1
00:00:00,480 --> 00:00:01,313
In this lesson,

2
00:00:01,313 --> 00:00:03,600
we will discuss risk identification.

3
00:00:03,600 --> 00:00:06,240
Risk identification is a crucial first step

4
00:00:06,240 --> 00:00:07,770
in a risk management process.

5
00:00:07,770 --> 00:00:09,750
It involves recognizing potential risks

6
00:00:09,750 --> 00:00:12,720
that could negatively impact an organization's ability

7
00:00:12,720 --> 00:00:15,120
to operate or achieve its objectives.

8
00:00:15,120 --> 00:00:18,210
Regardless of how likely or unlikely these risks may be,

9
00:00:18,210 --> 00:00:20,580
identifying them is essential for the organization

10
00:00:20,580 --> 00:00:24,060
to prepare and plan for potential disruption.

11
00:00:24,060 --> 00:00:26,100
Once risk identification is conducted,

12
00:00:26,100 --> 00:00:27,540
we will often follow this up

13
00:00:27,540 --> 00:00:29,880
by conducting a business impact analysis

14
00:00:29,880 --> 00:00:31,500
and determining some key metrics

15
00:00:31,500 --> 00:00:35,280
like recovery time objectives, recovery point objective,

16
00:00:35,280 --> 00:00:38,460
mean time to repair, and mean time between failures.

17
00:00:38,460 --> 00:00:42,390
So we will cover each of these terms in this lesson as well.

18
00:00:42,390 --> 00:00:45,150
Now, risk identification is a proactive process

19
00:00:45,150 --> 00:00:47,100
that involves identifying potential threats

20
00:00:47,100 --> 00:00:48,660
and vulnerabilities that could affect

21
00:00:48,660 --> 00:00:51,390
an organization's operations or objective.

22
00:00:51,390 --> 00:00:54,360
This can involve a wide range of potential risks,

23
00:00:54,360 --> 00:00:56,460
from financial and operational risks

24
00:00:56,460 --> 00:00:58,830
to strategic and reputational risk.

25
00:00:58,830 --> 00:01:00,660
Techniques used in risk identification

26
00:01:00,660 --> 00:01:03,600
can include brainstorming, checklists, interviews,

27
00:01:03,600 --> 00:01:05,640
or scenario analysis.

28
00:01:05,640 --> 00:01:08,850
The goal is to create a comprehensive list of risks

29
00:01:08,850 --> 00:01:11,640
based on those events that might prevent the organization

30
00:01:11,640 --> 00:01:14,100
from achieving its objectives.

31
00:01:14,100 --> 00:01:17,640
Now, the organization should consider a wide range of risks,

32
00:01:17,640 --> 00:01:19,470
including operational, financial,

33
00:01:19,470 --> 00:01:21,570
strategic, and reputational.

34
00:01:21,570 --> 00:01:25,020
Even risks that seem unlikely should be included,

35
00:01:25,020 --> 00:01:27,810
as these could still have a significant impact

36
00:01:27,810 --> 00:01:29,310
if they were to occur.

37
00:01:29,310 --> 00:01:31,740
Once all potential risks have been identified,

38
00:01:31,740 --> 00:01:33,870
they should be documented and analyzed

39
00:01:33,870 --> 00:01:36,750
in terms of their potential impact and likelihood.

40
00:01:36,750 --> 00:01:38,520
This will help the company prioritize

41
00:01:38,520 --> 00:01:39,720
its risk management efforts

42
00:01:39,720 --> 00:01:42,900
and develop effective strategies to address these risks.

43
00:01:42,900 --> 00:01:46,440
Next, we'll conduct our business impact analysis.

44
00:01:46,440 --> 00:01:49,860
The business impact analysis, or BIA, is a process

45
00:01:49,860 --> 00:01:52,980
that involves evaluating the potential effects of disruption

46
00:01:52,980 --> 00:01:56,070
to an organization's business functions and processes.

47
00:01:56,070 --> 00:01:58,770
A business impact analysis helps to identify

48
00:01:58,770 --> 00:02:02,070
and prioritize critical business functions and processes,

49
00:02:02,070 --> 00:02:04,200
assess the potential impact or risk

50
00:02:04,200 --> 00:02:06,150
on these functions and processes,

51
00:02:06,150 --> 00:02:09,539
and determines how quickly these functions and processes

52
00:02:09,539 --> 00:02:12,600
need to be recovered after a disruption.

53
00:02:12,600 --> 00:02:14,700
Now, in order to understand the concept

54
00:02:14,700 --> 00:02:16,140
of business impact analysis,

55
00:02:16,140 --> 00:02:18,450
there are a few terms that you should be familiar with,

56
00:02:18,450 --> 00:02:19,950
and these are, again:

57
00:02:19,950 --> 00:02:22,560
recovery time objective, or RTO;

58
00:02:22,560 --> 00:02:25,470
recovery point objective, or RPO;

59
00:02:25,470 --> 00:02:28,827
mean time to repair, or MTTR;

60
00:02:28,827 --> 00:02:32,583
and mean time between failures, also known as MTBF.

61
00:02:34,020 --> 00:02:38,160
First, we have recovery time objective, or RTO.

62
00:02:38,160 --> 00:02:41,070
The recovery time objective is a critical metric

63
00:02:41,070 --> 00:02:43,590
in disaster recovery and business continuity planning.

64
00:02:43,590 --> 00:02:46,620
It represents the maximum acceptable length of time

65
00:02:46,620 --> 00:02:49,830
that can elapse before the lack of business function

66
00:02:49,830 --> 00:02:51,990
severely impacts the organization.

67
00:02:51,990 --> 00:02:54,180
In other words, it's the target time

68
00:02:54,180 --> 00:02:57,600
within which a business process must be restored

69
00:02:57,600 --> 00:03:01,380
after a disruption to avoid unacceptable consequences.

70
00:03:01,380 --> 00:03:04,710
Suppose a company operates an e-commerce website.

71
00:03:04,710 --> 00:03:07,020
If the website goes down due to a server failure,

72
00:03:07,020 --> 00:03:08,340
the company determines

73
00:03:08,340 --> 00:03:11,640
that it can tolerate a maximum of two hours of downtime

74
00:03:11,640 --> 00:03:13,200
before the impact on sales

75
00:03:13,200 --> 00:03:15,720
and customer satisfaction becomes severe.

76
00:03:15,720 --> 00:03:16,680
In this case,

77
00:03:16,680 --> 00:03:20,670
the recovery time objective for the website is two hours.

78
00:03:20,670 --> 00:03:25,200
Secondly, we have recovery point objective, or RPO.

79
00:03:25,200 --> 00:03:28,050
The recovery point objective is another crucial metric

80
00:03:28,050 --> 00:03:29,280
in disaster recovery.

81
00:03:29,280 --> 00:03:31,680
It represents the maximum acceptable amount

82
00:03:31,680 --> 00:03:34,170
of data loss measured in time.

83
00:03:34,170 --> 00:03:35,520
It's the point in time

84
00:03:35,520 --> 00:03:39,060
which data must be restored to resume business operations.

85
00:03:39,060 --> 00:03:40,380
Another example,

86
00:03:40,380 --> 00:03:43,410
if an organization has an RPO of four hours

87
00:03:43,410 --> 00:03:45,630
this means the business can tolerate data loss

88
00:03:45,630 --> 00:03:47,190
of up to four hours.

89
00:03:47,190 --> 00:03:49,290
For instance, if a financial institution

90
00:03:49,290 --> 00:03:52,020
that performs transactions continuously

91
00:03:52,020 --> 00:03:54,090
determined that they can afford to lose a maximum

92
00:03:54,090 --> 00:03:55,980
of 15 minutes of transactional data

93
00:03:55,980 --> 00:03:57,780
in the event of a system failure.

94
00:03:57,780 --> 00:04:00,150
Now, this means that the recovery point objective

95
00:04:00,150 --> 00:04:03,210
is 15 minutes and their systems need to be backed up

96
00:04:03,210 --> 00:04:06,840
at least every 15 minutes to meet this objective.

97
00:04:06,840 --> 00:04:11,400
Third, we have mean time to repair, or MTTR.

98
00:04:11,400 --> 00:04:13,830
The mean time to repair is a basic measure

99
00:04:13,830 --> 00:04:16,980
of the maintainability of repairable items.

100
00:04:16,980 --> 00:04:18,750
It represents the average time required

101
00:04:18,750 --> 00:04:21,480
to repair a failed component or system.

102
00:04:21,480 --> 00:04:24,900
A lower mean time to repair is an indicator of a system

103
00:04:24,900 --> 00:04:26,490
that can be repaired quickly,

104
00:04:26,490 --> 00:04:28,920
minimizing downtime and disruption.

105
00:04:28,920 --> 00:04:31,890
For example, let's use a manufacturing company

106
00:04:31,890 --> 00:04:34,080
that has a critical piece of machinery.

107
00:04:34,080 --> 00:04:35,850
Now, over the past year,

108
00:04:35,850 --> 00:04:38,040
the machine has broken down five times,

109
00:04:38,040 --> 00:04:41,550
and each time it took an average of four hours to repair.

110
00:04:41,550 --> 00:04:42,383
In this case,

111
00:04:42,383 --> 00:04:46,080
the mean time to repair for the machine is four hours.

112
00:04:46,080 --> 00:04:49,860
Fourth, we have mean time between failures, or MTBF.

113
00:04:49,860 --> 00:04:52,230
The mean time between failures is a measure

114
00:04:52,230 --> 00:04:54,990
of the reliability of a system or component.

115
00:04:54,990 --> 00:04:57,810
It represents the average time between failures.

116
00:04:57,810 --> 00:04:59,940
A higher mean time between failures

117
00:04:59,940 --> 00:05:02,760
indicates a system that fails less frequently,

118
00:05:02,760 --> 00:05:04,470
which can be a sign of a reliable

119
00:05:04,470 --> 00:05:06,240
and well-maintained system.

120
00:05:06,240 --> 00:05:09,510
Now, going back to the manufacturing company example,

121
00:05:09,510 --> 00:05:13,020
over the past year, the machine has broken down five times.

122
00:05:13,020 --> 00:05:16,380
Considering it broke down over a consistent period of time,

123
00:05:16,380 --> 00:05:18,240
so, five times a year,

124
00:05:18,240 --> 00:05:20,340
means that it has a mean time between failures

125
00:05:20,340 --> 00:05:24,870
of 2.4 months, or roughly every 72 days.

126
00:05:24,870 --> 00:05:29,430
Now remember, risk identification is a critical first step

127
00:05:29,430 --> 00:05:31,320
in the risk management process.

128
00:05:31,320 --> 00:05:33,120
It involves identifying potential risk,

129
00:05:33,120 --> 00:05:35,400
and conducting a business impact analysis

130
00:05:35,400 --> 00:05:38,430
to assess the potential effects of these risks.

131
00:05:38,430 --> 00:05:41,880
Key metrics such as RTO, RPO,

132
00:05:41,880 --> 00:05:45,900
MTTR, and MTBF are then determined

133
00:05:45,900 --> 00:05:48,030
to guide the organization's disaster recovery

134
00:05:48,030 --> 00:05:49,740
and business continuity planning.

135
00:05:49,740 --> 00:05:52,260
By understanding and implementing these processes

136
00:05:52,260 --> 00:05:55,020
and metrics, organizations can better prepare for

137
00:05:55,020 --> 00:05:57,003
and manage potential disruptions.

