- Has a risk analysis or business impact analysis been done and has management endorsed the priorities and criticality which that process has defined?
- Do you have sufficient data to make a risk management decision?
- Does your risk analysis solution readily and visibly highlight security control deficiencies and risk ratings by media and information asset for management reporting?
- Which techniques will you use to create the risk management plan?
- Does your business continuity plan have senior management approval and sponsorship?
- Do you have a process to perform a risk analysis or new or changing business processes?
- Does your organization use a standard set of tools and/or methods to detect malicious code in information systems entry and exit points to detect and eradicate malicious code?
- Is management aware of the specific technology systems that support business activities?
- Does your organization have a comprehensive risk management program for third parties?
- How has your organization supported improved research and/or risk analysis on the impacts of climate change?
- Which quantitative risk analysis techniques relies on experience and past data to compute the probability and impact of risks on project objectives?
- Has the business undertaken a data security and IT risk analysis?
- Who has access to applications and business processes via remote access?
- Does your organization have a plan to deal with the risk of business interruption?
- Do your data management policies and procedures address tenant and service level conflicts of interests?
- Who has to address the risk management issues?
- Does any tool assist with the analysis of data that has been gathered and processed?
- What data are required to meet regulatory reporting requirements and risk management functions?
- Are the sources of the research reliable and has the data been verified?
- Does your organization have a risk management department?
- What risk management process do you have in general?
- What is agile risk management and when does it make sense to use it?
- What impact will the control approach have on the technical performance of the system?
- Does your organization have an effective process to prioritize business functions?
- Does your program office or risk management ipt have a risk mitigation plan?
- Is risk analysis performed prior to decision on outsourcing information management or information systems?
- What data are required to meet regulatory reporting and risk management functions?
- How conservatively has management positioned its accounting practices within the range of acceptable GAAP guidelines?
- Is your organization using risk analysis to support programming and project delivery decisions, as public private partnerships and long term maintenance agreements?
- Does the business case mention consultation that has taken place with stakeholders?
- Did the business process owners document their own data restore procedures?
- Do the public have access to data either through web or any other means?
- Does your organization have a written policy for business continuity and disaster recovery?
- What risk analysis measures are you using to support risk management decisions?
- Does your program have a risk management ipt?
- Is goal driven approach for risk management useful in software development project?
- What data elements are needed in the risk management system?
- Are adequate and appropriate data and information input into the risk analysis process?
- How does the information system categorization affect the use of common security controls?
- Which is the best approach for improving information security management processes?
- Has management carried out risk analysis for all information assets?
- What actions are taken by the project teams to help encourage risk management activities?
- Does management have the skills required to understand the complexities associated with cloud computing?
- Does your organization have policies on protecting and handling data containing personal information?
- What impact will the mitigation approach have on the technical performance of the system?
- How will risk management and improvement activities relate to the strategic goals?
- Have you ensured that the information users have the right tools and capacity to manage uncertainty?
- How will the risk management plan be monitored, enforced, and communicated to the public?
- How does a project organization conduct its project risk management process?
- Do you have a data quality team in your department?
- Do you have enough information to make risk analysis?
- Why do other organizations have an information security policy?
- How do you correlate business value with source data quality?
- Are continuous risk analysis and risk management an integrated part of the project design?
- When implementing ITIL processes, what is the best timing for establishing service level agreements with the business, especially if you are also upgrading your help desk and change management tool?
- Do you have your key suppliers and customers business continuity plans?
- Does your organization have an effective inventory management system?
- How will the selected risk management options be implemented?
- Have the control objectives, expected performance and management information been defined?
- Does your organization have a formal governance body for business continuity?
- Which tools are currently in place for information security risk analysis and management?
- Does the planning process include risk analysis of critical business processes?
- When will the quantitative risk analysis process need to be repeated?
- Do people feel that the have enough information about a risk to manage it?
- How has your organizations risk assessment process accounted for manifested risks?
- Can risk management be integrated in the early phase of software development projects?
- How much data has to be handled by the system?
- Do you collect capacity and use data for all relevant components of your cloud service offering?
- What additional information is required to ensure the group has the full picture?
- What elements of project risk management are necessities for your organization to implement?
- Does the management team individually and collectively have a good reputation inside and outside your organization?
- How does the team know that the risk management approach works?
- Does management periodically reassess risk analysis to ensure that critical systems are properly identified and prioritized?
- How would your organization know if its new information security program is accomplishing its goals?
- What do you need to put the right security practices into your organizations business operations?
- Are there any personnel issues or personal issues that could have major financial implications for the business going forward?
- Are the sources of data and information used in risk assessment identified and documented?
- Do you have separate key management and key usage duties?
- What is the management style that blends the technical knowledge and your business structure and delivers the product or service to the market place?
- Has a risk analysis regarding data security been carried out?
- Can management predict whether the prices of cloud solutions will rise or fall in the future?
- Do senior managers have the experience and skills to appreciate the impact of the other people in your organization who deliver the other core competencies?
- How does a risk impact your organizations ability to achieve its strategy and business objectives?
- Which data and information assets should really be included in the information risk analysis?
- What impact will the market changes have on your business?
- Do you have a process for ensuring that security patches are applied to systems on a timely basis?
- Are the limitations of data and information used in risk assessment identified and documented?
- Does the board have access to the information needed to evaluate risks emerging from ESG trends?
- Is there someone in your organization who will have responsibility for maintaining and updating your plan?
- Does your organization have a risk analysis to understand threats, vulnerabilities and countermeasures?
- What changes to the risk model has public cloud introduced?
- Do the people who need to use it understand and have the required skills to use it?
- Did management involve a variety of business unit staff in the testing of the BCP?
- Who has the responsibility for review and risk analysis of all supplies and contracts on a regular basis?
- What impact will change have on objectives?
- Do organization personnel have the requisite knowledge and skills to adequately perform the risk analysis?
- How do you report to your organization that a risk event has occurred on the project?
- Do you have personnel with information security competence?
- Have you reviewed your risk analysis or risk management measures during the project implementation?
- Which process will perform risk analysis and review of all suppliers and contracts on a regular basis?