risk assessment: riskit analysis graph
DESCRIPTION
Objectives of Session Coverage To gain the ability to build a Riskit Analysis GraphTRANSCRIPT
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Risk Assessment: Riskit Risk Assessment: Riskit Analysis GraphAnalysis Graph
COMM80: Risk Assessment of Systems Change
Unit 7
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Objectives of Objectives of Session CoverageSession Coverage
• To gain the ability to build a Riskit Analysis Graph
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Riskit Analysis Riskit Analysis Graph Perspective Graph Perspective
• This technique belongs to the Riskit method• Riskit was designed to manage risk during
systems development.– However, there is nothing in it that restricts its use
to such a perspective.
Risk Perspective Risk Lifecycle
(D) Infrastructure
Analyse Characteristics Examples for feasibility of system being based on
the existing infrastructure: network, o/s etc
Techniques RAG, Goal/stakeholders, GQM, … Methods RISKIT
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
FeaturesTechniques
strategic detailed Riskitdefined
generic
Goal-Question-Metric (GQM) Brainstorming techniques Goal and stakeholder driven identification Meeting aids * * Interviews Riskit analysis graph Multiple criteria decision making tools * * (e.g. AHP)
Riskit Pareto ranking technique Riskit element review Riskit controlling action taxonomy Organisation measurement program orDatabase
Summary of Summary of TechniquesTechniques
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Risk Analysis GraphRisk Analysis Graph(example from the Riskit Manual)
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Riskit Analysis Riskit Analysis Graph ComponentsGraph Components
The overall risk being evaluated
An event that may occur as a result of the risk happening
A possible action that can be taken in response to the event happening
The resultant costs to the organisation on taking a specific action
Consequences can be either deterministic (known): full arrow. Or stochastic (probabilistic) : dashed arrow
An outcome (can be omitted) shows the situation in a project after the risk event has occurred but before any corrective action is taken.
Outcome
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
General Example of General Example of Riskit Analysis Graph Riskit Analysis Graph
ComponentsComponents• Risk Factor: a high cholesterol diet • Risk Event: a doctor's diagnosis of a patient’s
heart problem • Risk Outcome: a diagnosed heart disease exists • Risk Reaction: treatment of heart problem • Risk Effect: hospital stay • Utility Loss: net effect of pain, loss of time,
expenses felt by individuals: in this case emotional upset and disruption to normal life.
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
General Example of General Example of Riskit Analysis Graph Riskit Analysis Graph
ComponentsComponents• Risk Factor: living near a fault line of earth's plates• Risk Event: an earthquake• Risk Outcome: some buildings/roads destroyed• Risk Reaction: reconstruction of infrastructure• Risk Effect: cost of reconstruction• Utility Loss: net effect of pain, loss of time,
expenses felt by individuals: for one individual minimal since personal losses low and covered by insurance, for another catastrophic since home destroyed and without insurance.
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Software Systems Software Systems ExampleExample
• Risk Factor: inexperience of personnel• Risk Event: a system crashes• Risk Outcome: system out of operation for up to 8
hours• Risk Reaction: systems operational after delay,
back up data restored • Risk Effect: added cost • Utility Loss: perceived harm experienced by
stakeholders: in this case minimal since only small data entry per day and data backed up daily
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Software Systems Software Systems ExampleExample
• Risk Factor: use of new development methods
• Risk Event: key personnel leave• Risk Outcome: personnel and competence
shortage• Risk Reaction: recruiting initiated, staff
reassigned• Risk Effect: two month delay• Utility Loss: perceived harm experienced by
stakeholders: in this case catastrophic since software delay results in client imposing financial penalty.
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
A Riskit Analysis Graph for A Riskit Analysis Graph for a Systems Change Case a Systems Change Case
Study (part 1)Study (part 1)
Factor
Lack of IT specialist
FactorLack of staff training
Event Project costs underestimated.
OutcomeProject behind schedule, exceeding budgets
Factor
Lack of IT specialist
Reaction
Reaction
Do nothing
Allocate more resource
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
Effect SetProject behind schedule:10 months budget overrun by £10,000
Reaction
Reaction
Do nothing
Allocate more resource
Utility LossDelaying other projects (significant problem)Unable to process all potential orders - lost business (catastrophic)
Effect SetProject behind schedule: 2 weeks budget overrun £25,000
Utility LossReduced budget available for planned projects resulting in delay to some non-critical projects (minor problem)
A Riskit Analysis Graph for A Riskit Analysis Graph for a Systems Change Case a Systems Change Case
Study (part 2)Study (part 2)
Unit 7University of Sunderland COMM80 Risk Assessment of Systems Change
A student A student generated graphgenerated graph