---
title: "Risk Assessment - Methodology?"
canonical: "https://kb.myframeworks.com.au/space/FRAM/28378722/Risk%20Assessment%20-%20Methodology%3F"
format: markdown
---
# Overview

The foundation of any risk assessment methodology is the definition of a critical outage. Critical manufacturing processes can often be interrupted for as long as 24 hours without serious implications. The definition of critical outage establishes the basis for the identification and assessment of downtime events.   
Operating your business in a redundant system mode or even manually is usually sufficient to keep the majority of your customers satisfied. What your business cannot afford is the loss of income-producing data that occurs between your last data backup (usually the previous night, if it has worked) and the disaster occurrence. What quotes and sales orders have been entered? What account sales have been made, and do I have a manual record (Delivery Docket, invoice copy, or picking slip)? At least with your POS transactions, you have the cash in the till, but what about CODs, Lay Buys, and Special Orders?


Two areas are of primary concern: **outage duration** and the **expected frequency of occurrence.** Considering the allocation of resources, there is little need to control events with very low frequencies of occurrence.

# Questions that need to be asked: 

- Have potential disasters that could result in an interruption to the business operations been systematically identified? Do my contingency plans focus limited resources on relatively high probability and more severe consequence events?
- What will occur if critical systems are absent over specific periods of time?
- What foreseeable impact exists if accounting functionality is down, for example, or the inventory file, access to outstanding quotes and sales orders, and customer balances? Determine the maximum amount of downtime for these critical items before there will be a significant impact on the business.
- Have the probabilities—and the consequences—of these events been assessed and quantified?
- Are cost-beneficial mitigation measures being taken to reduce the risk of an interruption of a facility's operations?
- How effective is the preventive maintenance program? Do my backups really work? Can I restore my backup files with a minimum of disruption, and do I have confidence in the ability of my staff to do this?
- Have I identified disaster recovery alternatives for critical functions? You might decide that a 'hot site' is a reasonable alternative. A hot site is a computer and data processing centre with computers in place and waiting to be used by a company experiencing a disaster. Most hot sites are permanent facilities where the company can recreate its computing environment. Is 'warm standby' sufficient and cost-effective?
- What are the benefits of one form of disaster recovery option over another, and what are their limitations? Each alternative should have a specified recovery period, so estimate the amount of time until the critical systems become available, and is this acceptable? Use the benefits of a faster recovery in the event of a disaster as a competitive advantage.
- Identify what is needed for the disaster recovery alternative to be implemented. Minimum requirements may involve telecommunications with certain bandwidths or dial-up lines. A specified level of power redundancy may be required for servers. Agreements with hardware vendors or vendors who provide disaster recovery sites may also be an option.
- What are the costs? Gain an understanding of the total cost for disaster recovery alternatives. Examples of common costs include arranging hardware agreements with vendors or the cost of having a disaster recovery site available for use. Installation fees, the purchase of redundant telecommunications, and the purchase of upgrading telecommunications (that is, increasing bandwidth) are other common costs.