Original posted on 28 May 2010 13:41 by sripattra
Today IT Risk is not only concerned with IT equipment but involves the whole business operation. The IT system administrator should explore the whole organization to determine what the real IT Asset of the organization is.
The continuity of business operation should be considered for risk assessment and the IT administrator should analyze which systems require recovery within 15 minutes, 4 hours or 2 weeks for low impact systems.
The payroll system in a medical research institute is not an important part of the
business risk but it is a very critical system for a HR professional outsource company.
In a 200 seat restaurant the computer system which automatically sends the order from the waiter at the table to the kitchen can wait a few days for recovery, because the waiter can send the order manually. But in a food court that uses a cash card system, if the system breaks during the daily operation recovery must be within one hour because the cash card must be refunded to the customer.
Therefore, the first step of IT Risk assessment is identifying the IT asset to be able to appropriately manage the risk.
-------------------------------------------------------------------------------
Reference:
George Westerman & Richard Hunter , “IT Risk” , Harvard business school press, 2007.
TIS 22300 , TIS 18000, www. tisi. go. th
--------------------------------------------------------------------------------
Thank you Aj. John for review and advise
The continuity of business operation should be considered for risk assessment and the IT administrator should analyze which systems require recovery within 15 minutes, 4 hours or 2 weeks for low impact systems.
The payroll system in a medical research institute is not an important part of the
business risk but it is a very critical system for a HR professional outsource company.
In a 200 seat restaurant the computer system which automatically sends the order from the waiter at the table to the kitchen can wait a few days for recovery, because the waiter can send the order manually. But in a food court that uses a cash card system, if the system breaks during the daily operation recovery must be within one hour because the cash card must be refunded to the customer.
Therefore, the first step of IT Risk assessment is identifying the IT asset to be able to appropriately manage the risk.
-------------------------------------------------------------------------------
Reference:
George Westerman & Richard Hunter , “IT Risk” , Harvard business school press, 2007.
TIS 22300 , TIS 18000, www. tisi. go. th
--------------------------------------------------------------------------------
Thank you Aj. John for review and advise
