<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Quora on Andrew Sheves</title><link>https://andrewsheves.com/tags/quora/</link><description>Recent content in Quora on Andrew Sheves</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 13 Jul 2018 00:00:00 +0000</lastBuildDate><atom:link href="https://andrewsheves.com/tags/quora/index.xml" rel="self" type="application/rss+xml"/><item><title>What is a risk mitigation plan?</title><link>https://andrewsheves.com/2018/07/13/what-is-a-risk-mitigation-plan/</link><pubDate>Fri, 13 Jul 2018 00:00:00 +0000</pubDate><guid>https://andrewsheves.com/2018/07/13/what-is-a-risk-mitigation-plan/</guid><description>&lt;p&gt;&lt;em&gt;This post originally appeared on Quora in response to the question ‘What is a risk mitigation plan?’ &lt;a href="https://www.quora.com/What-is-a-risk-mitigation-plan"&gt;Link&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;h1 id="what-is-a-risk-mitigation-plan"&gt;What is a risk mitigation plan&lt;/h1&gt;
&lt;p&gt;The risk mitigation plan is a series of specific actions or steps you will take in response to a risk once you have &lt;a href="https://dcdr.io/2017/03/18/risk-assessment-process-how-to-conduct-a-risk-assessment/"&gt;completed your risk assessment&lt;/a&gt;.  However, before you start to develop the mitigation plan in detail, you need to determine a general course of action based on one of five main options: &lt;strong&gt;avoid, tolerate, treat, transfer &lt;strong&gt;and&lt;/strong&gt; terminate (A4T)&lt;/strong&gt;. Which of these is most applicable will depend on your risk tolerance (short term), risk appetite (longer term) and what you can reasonably achieve with the resources available (ALARP).&lt;/p&gt;</description></item><item><title>Convincing people to take risks</title><link>https://andrewsheves.com/2018/07/06/convincing-people-to-take-risks/</link><pubDate>Fri, 06 Jul 2018 00:00:00 +0000</pubDate><guid>https://andrewsheves.com/2018/07/06/convincing-people-to-take-risks/</guid><description>&lt;p&gt;&lt;em&gt;This post first appeared on Quora in response to the question ‘How do you convince people to take a risk in a company?’ &lt;a href="https://www.quora.com/How-do-you-convince-people-to-take-a-risk-in-a-company"&gt;Link&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;h1 id="how-do-you-convince-people-to-take-a-risk-in-a-company"&gt;How do you convince people to take a risk in a company?&lt;/h1&gt;
&lt;p&gt;Firstly, I don’t think we should ever push people to take risks that 1) they are uncomfortable with and 2) that don’t serve the company’s objectives.&lt;/p&gt;
&lt;p&gt;However, I also know that sometimes people might overestimate and subsequently avoid a risk that might actually benefit them and the company. That is something we can help with.&lt;/p&gt;</description></item><item><title>Risk management and the security manager – a quick note</title><link>https://andrewsheves.com/2018/06/30/risk-management-and-the-security-manager-a-quick-note/</link><pubDate>Sat, 30 Jun 2018 00:00:00 +0000</pubDate><guid>https://andrewsheves.com/2018/06/30/risk-management-and-the-security-manager-a-quick-note/</guid><description>&lt;p&gt;&lt;em&gt;This post originally appeared on Quora in answer to the question “How does risk management fit in security risk management profession?” &lt;a href="https://www.quora.com/How-does-risk-management-fit-in-security-risk-management-profession/answer/Andrew-Sheves-2"&gt;Link&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="how-does-risk-management-fit-in-security-risk-management-profession"&gt;How does risk management fit in security risk management profession?&lt;/h2&gt;
&lt;p&gt;Ideally, a security manager will use a risk management foundation for their security management system.  This will help integrate security risks into the organization’s understanding of its overall risk environment.  This focus also ensures that the security program is focussed on protecting the organization’s objectives which aligns with the ISO definition of risk:&lt;/p&gt;</description></item></channel></rss>