Andrew Brown

Forum Replies Created

Viewing 6 posts - 1 through 6 (of 6 total)
  • Author
    Posts
  • in reply to: Risk Appetite Working Group #18401
    Andrew Brown
    Participant

    I’ve obtained permission from the original author (Lucas Everly-Commonwealth of PA) to modify this document. The original intent was to clarify/visualize the difference between appetite/tolerance and risk thresholds.

    Attachments:
    You must be logged in to view attached files.
    in reply to: Risk Appetite/Tolerance chart #18391
    Andrew Brown
    Participant

    I found the author and had a good conversation with him about the “Risk Landscape chart.pdf”. He – Lucas Everly, created it because execs in his organization were conflating risk appetite with risk threshold. He created the diagram to be an accurate visualization between: appetite, tolerance, and threshold.

    We can reference this work and should cite him. He also gave his blessing for modifying it for our needs, which I’ve begun based on the conversations yesterday and via email afterwards.

    in reply to: Risk Appetite Working Group #18334
    Andrew Brown
    Participant

    I’m listening to the CSF 2.0 briefing from NIST on the Cyber-ERM COI meeting today. Perhaps a “quick-start” guide for developing a Risk Appetite statement, a Risk tolerance statement and ultimately a Risk profile. We may be able to plagiarize… reuse the NIST quick start guide(s). Duplication of terminology, process only reinforces the documents

    in reply to: Cyber-ERM Playbook Chapter (FINAL DRAFT) #18319
    Andrew Brown
    Participant

    Update/Clarification
    I would add that Third-party risks and /or Supply-Chain risks would be grouped under either “Service” as orgs. hire 3rd parties to perform a service, OR under “Staff” as Orgs hire 3rd party staffing resources.

    in reply to: Risk Appetite Working Group #18305
    Andrew Brown
    Participant

    This is somewhat duplicative of the NISTIR 8286. There’s a few points of clarity that the NISTIR doesn’t address. It is very much in a draft state.

    Attachments:
    You must be logged in to view attached files.
    in reply to: Cyber-ERM Playbook Chapter (FINAL DRAFT) #18296
    Andrew Brown
    Participant

    Attached is an excerpt from a risk management document I was working on in a previous organization. Specifically, the risk impact category taxonomy and explanation of use.

    Attachments:
    You must be logged in to view attached files.
Viewing 6 posts - 1 through 6 (of 6 total)