1
00:00:00,480 --> 00:00:01,313
In this lesson,

2
00:00:01,313 --> 00:00:03,960
we will cover risk assessment frequency.

3
00:00:03,960 --> 00:00:06,600
Risk assessment frequency refers the regularity

4
00:00:06,600 --> 00:00:08,250
with which risk assessments are conducted

5
00:00:08,250 --> 00:00:09,660
within an organization.

6
00:00:09,660 --> 00:00:12,180
The frequency can vary greatly depending on the nature

7
00:00:12,180 --> 00:00:14,340
of the organization, the type of risk involved,

8
00:00:14,340 --> 00:00:17,700
and changes in the internal or external environment.

9
00:00:17,700 --> 00:00:20,670
There are four main types of risk assessment frequencies

10
00:00:20,670 --> 00:00:24,360
ad-hoc, recurring, one-time, and continuous.

11
00:00:24,360 --> 00:00:27,390
First, we have ad-hoc risk assessments.

12
00:00:27,390 --> 00:00:30,480
Ad-hoc risk assessments are conducted as and when needed,

13
00:00:30,480 --> 00:00:32,759
often in response to a specific event

14
00:00:32,759 --> 00:00:36,060
or situation that has the potential to introduce new risk

15
00:00:36,060 --> 00:00:38,400
or change the nature of existing risk.

16
00:00:38,400 --> 00:00:40,350
For instance, an organization might conduct

17
00:00:40,350 --> 00:00:42,330
an ad-hoc risk assessment when launching

18
00:00:42,330 --> 00:00:44,460
a new product, entering a new market,

19
00:00:44,460 --> 00:00:46,560
or in response to a significant event,

20
00:00:46,560 --> 00:00:50,490
such as a natural disaster or major change in regulations.

21
00:00:50,490 --> 00:00:53,370
Second, we have recurring risk assessments.

22
00:00:53,370 --> 00:00:55,470
Recurring risk assessments are conducted

23
00:00:55,470 --> 00:00:57,900
at regular intervals such as annually,

24
00:00:57,900 --> 00:00:59,670
quarterly, or monthly.

25
00:00:59,670 --> 00:01:01,650
These assessments are typically part

26
00:01:01,650 --> 00:01:04,260
of an organization's standard operating procedures

27
00:01:04,260 --> 00:01:05,430
and are designed to ensure

28
00:01:05,430 --> 00:01:07,800
that risks are continually identified,

29
00:01:07,800 --> 00:01:10,140
analyzed, and managed effectively.

30
00:01:10,140 --> 00:01:12,180
For example, a financial institution

31
00:01:12,180 --> 00:01:14,280
might conduct recurring risk assessments

32
00:01:14,280 --> 00:01:18,450
to monitor credit risk, market risk, and operational risk.

33
00:01:18,450 --> 00:01:20,550
Another example of recurring risk assessments

34
00:01:20,550 --> 00:01:21,960
would be a tech company

35
00:01:21,960 --> 00:01:24,210
might conduct recurring penetration testing

36
00:01:24,210 --> 00:01:27,300
where ethical hackers attempt to breach their systems

37
00:01:27,300 --> 00:01:29,070
to identify vulnerabilities.

38
00:01:29,070 --> 00:01:32,070
These assessments are scheduled regularly to ensure

39
00:01:32,070 --> 00:01:34,530
that any new vulnerabilities that might have emerged

40
00:01:34,530 --> 00:01:37,950
since the last assessment are identified and addressed.

41
00:01:37,950 --> 00:01:40,470
Third, we have one-time assessments.

42
00:01:40,470 --> 00:01:42,870
One-time risk assessments are conducted

43
00:01:42,870 --> 00:01:46,260
for a specific purpose and are not repeated.

44
00:01:46,260 --> 00:01:48,870
These assessments are often associated

45
00:01:48,870 --> 00:01:50,910
with a particular project or initiative.

46
00:01:50,910 --> 00:01:53,100
For instance, an organization might conduct

47
00:01:53,100 --> 00:01:54,600
a one-time risk assessment

48
00:01:54,600 --> 00:01:57,120
when implementing a new IT system,

49
00:01:57,120 --> 00:01:59,520
undertaking a major construction project,

50
00:01:59,520 --> 00:02:02,490
or planning significant organizational changes.

51
00:02:02,490 --> 00:02:05,520
Now, before we move on to the final type of risk assessment

52
00:02:05,520 --> 00:02:07,080
you need to understand the difference

53
00:02:07,080 --> 00:02:08,669
between ad-hoc risk assessment

54
00:02:08,669 --> 00:02:10,410
and one-time risk assessments.

55
00:02:10,410 --> 00:02:12,240
One-time assessments are associated

56
00:02:12,240 --> 00:02:15,630
with a specific project or initiative and are not repeated.

57
00:02:15,630 --> 00:02:18,660
While ad-hoc risk assessments are conducted in response

58
00:02:18,660 --> 00:02:22,260
to a specific event or situation and may be repeated

59
00:02:22,260 --> 00:02:25,230
if similar circumstances arise in the future.

60
00:02:25,230 --> 00:02:28,530
Fourth and finally, we have continuous risk assessments.

61
00:02:28,530 --> 00:02:31,170
Continuous risk assessments involve ongoing monitoring

62
00:02:31,170 --> 00:02:32,730
and evaluation of risk.

63
00:02:32,730 --> 00:02:35,190
This approach is often enabled by technology

64
00:02:35,190 --> 00:02:37,950
and involves real-time data collection and analysis.

65
00:02:37,950 --> 00:02:40,170
For example, a cybersecurity team

66
00:02:40,170 --> 00:02:41,940
might use continuous risk assessments

67
00:02:41,940 --> 00:02:43,800
to monitor threats and vulnerabilities,

68
00:02:43,800 --> 00:02:47,253
enabling them to respond quickly to any potential issue.

69
00:02:48,090 --> 00:02:51,360
So remember, the frequency of risk assessments

70
00:02:51,360 --> 00:02:54,480
can vary greatly depending on the needs of the organization

71
00:02:54,480 --> 00:02:56,460
and the nature of the risk involved.

72
00:02:56,460 --> 00:02:58,860
Ad-hoc assessments are conducted as needed,

73
00:02:58,860 --> 00:03:01,560
often in response to specific events or situations.

74
00:03:01,560 --> 00:03:04,290
Recurrent assessments are conducted at regular intervals

75
00:03:04,290 --> 00:03:07,230
as part of an organization's standard operating procedures.

76
00:03:07,230 --> 00:03:08,850
One-time assessments are conducted

77
00:03:08,850 --> 00:03:11,400
for a specific purpose and are not repeated.

78
00:03:11,400 --> 00:03:14,580
Continuous assessments involve ongoing monitoring

79
00:03:14,580 --> 00:03:16,320
and evaluation of risk.

80
00:03:16,320 --> 00:03:19,410
Each type of risk assessment frequency has its place

81
00:03:19,410 --> 00:03:20,970
and can contribute to a robust

82
00:03:20,970 --> 00:03:23,133
and effective risk management process.

