这是我下午自学一个课程时提高的"Classic" Risk Anallysis,给你参考下:
Identify relevant policies
- What existing risk tolerance policies are available?
Study the current environment
- Understand what strengths and weaknesses exist today
Perform requirements analysis
- Just how much availability is required?
- What is the acceptable likelihood of a long outage?
Hypothesize vulnerabilities
- What can possibly go wrong?
Identify and quantify risks
- The statistical probability of something going wrong over the life of the project 9 or the likely number of times something will go wrong over the life of the project0 multiplied by the cost of an occurrence
Evaluate countermeasures
- What will it take to reduce the risk (by reducing the likelihood or consequences of an occurrence) to an acceptable level
Make decisions, create a budget and a plan the environment
引用方法论:通过“计划-实施-检查-改进”"Plan-Do-Check-Act" (PDCA) model,去构架新的process
还有就是:
Due Care: involves carrying out the necessary steps to mitigate these risks,说的是,你应该去做的事情,像计划。
Due Diligence:is continual effort of making sure that the correct polices, procedures and standards are in place and being followed,说的是你要保证Due Care要做的那些事情一直在保持最新的状态,有点像审计,要保证Due Care在执行
Before the event
Good planning-list critical point
Risk analysis
Decide procedure
Communication
During the event
Keep tracking, double check in every step by using different method or different thinking style, ask third party to check
Communication
After the events
Learn the lessons,
Improve the procedure