12 October 2012

Risk Management ISO/IEC 31000 Standard

ISO Standard for Effective Management of Risk - ISO/IEC 31000, provides principles, framework and a process for managing any form of risk in a transparent, systematic and credible manner within any scope or context. The standard recommends that organizations develop, implement and continuously improve a risk management framework as an integral component of their management system. ISO/IEC 31000 purpose is to help organizations:
  • Increase the likelihood of achieving objectives
  • Encourage proactive management
  • Be aware of the need to identify and treat risk throughout the organization
  • Improve the identification of opportunities and threats
  • Comply with relevant legal and regulatory requirements and international norms
  • Improve financial reporting
  • Improve governance
  • Improve stakeholder confidence and trust
  • Establish a reliable basis for decision making and planning
  • Improve controls
  • Effectively allocate and use resources for risk treatment
  • Improve operational effectiveness and efficiency
  • Enhance health and safety performance, as well as environmental protection
  • Improve loss prevention and incident management
  • Minimize losses
  • Improve organizational learning
  • Improve organizational resilience
ISO 31000 can be applied to any public, private or community enterprise, association, group or individual.

Based on original Visionary template by Justin Tadlock
Customized by Panos Kalantzis aka pck

© 2012 Greek Information Security Professionals