<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itskeptic.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The IT Skeptic - Comments for &quot;Risk Management - the lost process of ITIL V3&quot;</title>
 <link>http://www.itskeptic.org/node/640</link>
 <description>Comments for &quot;Risk Management - the lost process of ITIL V3&quot;</description>
 <language>en</language>
<item>
 <title>Risk Management Discipline</title>
 <link>http://www.itskeptic.org/node/640#comment-2988</link>
 <description>&lt;p&gt;Microsoft has created the Risk Management Discipline in their Microsoft Operations Framework. At first it was set apart from the other functions and in their recent released version 4 it is part of the function Governance, Risk and Compliance. When you zoom in on Risk Management you&#039;ll find overlap with other functions/processes (pfff... it is difficult to stay political correct), specific problem management. When you talk about pro active problem management, you&#039;ll come into the realm of risk management. Specific when discussing possible scenario&#039;s (what can go wrong and how can we prevent this from happening?)&lt;br /&gt;
It the Operations Management course I&#039;ve given last week, I&#039;ve spend a good couple of hours on risk management. Every time I&#039;m surprised to find that most system administrators (the course is meant for operations managers, team leaders and technical supervisors) have difficulty identifying risks in production. They can easily identify project management risks (or risks for change management), but not risks in the day-to-day running of IT services. And according to Forrester and others (I do not have the survey reports ready, so I&#039;m now prime target for the craptoid facts) about 80% of downtime is caused by changes that are implemented hastily and untested and by administrators not following procedures or just being sloppy. I feel that spending some time on identifying risks and coming with ways to mitigate will be very useful. Also, are workarounds for incidents not some kind of contingency plans in the Risk management sense?&lt;/p&gt;
&lt;p&gt;Paul&lt;/p&gt;
</description>
 <pubDate>Mon, 16 Jun 2008 07:35:36 +0000</pubDate>
 <dc:creator>ITMaturity</dc:creator>
 <guid isPermaLink="false">comment 2988 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Oh yeah!</title>
 <link>http://www.itskeptic.org/node/640#comment-2983</link>
 <description>&lt;p&gt;Cary,&lt;/p&gt;
&lt;p&gt;Now you&#039;re talking. I&#039;ve been teaching ORM for years. Thanks for introducing this into the conversation!&lt;/p&gt;
&lt;p&gt;kengon&lt;/p&gt;
</description>
 <pubDate>Sun, 15 Jun 2008 03:58:51 +0000</pubDate>
 <dc:creator>kengon</dc:creator>
 <guid isPermaLink="false">comment 2983 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>ORM</title>
 <link>http://www.itskeptic.org/node/640#comment-2982</link>
 <description>&lt;p&gt;Here&#039;s ORM guidance I recommend.  It&#039;s the way I learned it.  It works for people in the toughest of circumstances.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.au.af.mil/au/awc/awcgate/usmc/orm.pdf&quot; title=&quot;http://www.au.af.mil/au/awc/awcgate/usmc/orm.pdf&quot; rel=&quot;nofollow&quot;&gt;http://www.au.af.mil/au/awc/awcgate/usmc/orm.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Cary King&lt;br /&gt;
Minerva Enterprises&lt;br /&gt;
Managing Partner&lt;br /&gt;
&lt;a href=&quot;http://www.MinervaE.com&quot; title=&quot;www.MinervaE.com&quot; rel=&quot;nofollow&quot;&gt;www.MinervaE.com&lt;/a&gt;&lt;/p&gt;
</description>
 <pubDate>Sat, 14 Jun 2008 23:48:00 +0000</pubDate>
 <dc:creator>Cary King</dc:creator>
 <guid isPermaLink="false">comment 2982 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>plenty of Risk Mgt in ITIL - you just have to see it</title>
 <link>http://www.itskeptic.org/node/640#comment-2979</link>
 <description>&lt;p&gt;It may not be ONE of these 27 &#039;things&#039;, but it&#039;s definitely there: there&#039;s plenty of Risk Mgt in ITIL, you just have to recognize it.&lt;br /&gt;
In my definition, Risk Mgt is concerned with a few major activities:&lt;br /&gt;
- determine vulnerabilities&lt;br /&gt;
- identify risks&lt;br /&gt;
- analyze cause&lt;br /&gt;
- determine countermeasure&lt;br /&gt;
- take action&lt;br /&gt;
- evaluate. &lt;/p&gt;
&lt;p&gt;If you now look at ITIL&#039;s Information Security Mgt, you&#039;ll recognize Risk Mgt. If you look at Capacity Mgt, you&#039;ll recognize it as well. Same for Availability Mgt, Continuity Mgt, &lt;strong&gt;or any other management function of a service quality parameter you&#039;ve agreed upon in the SLA....&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Of course, the &lt;strong&gt;functions&lt;/strong&gt; Availability Mgt, Security Mgt, etcetera, cover more than just Risk Mgt: they also cover their Incident Mgt, Change Mgt, and the other three elementary processes of an IT organization.&lt;/p&gt;
</description>
 <pubDate>Sat, 14 Jun 2008 10:17:34 +0000</pubDate>
 <dc:creator>jvbon</dc:creator>
 <guid isPermaLink="false">comment 2979 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>you mean &quot;itSMF-UK&quot;</title>
 <link>http://www.itskeptic.org/node/640#comment-2978</link>
 <description>&lt;p&gt;Skep - you&#039;re generalizing too much. That booklet was the product of itSMF-UK, and they obviously follow ITIL by the book, as usual. They may still own the brand name &#039;itSMF&#039; but they do not represent &#039;the ítSMF&#039;. There are many others out there that now understand that there are only a few processes and many organizational functions described in ITIL - according to ITIL&#039;s own definition of &#039;process&#039;. We have seen quite a few postings in your blog on that topic.&lt;br /&gt;
The latest itSMF publication analyses that very clearly in chapter 6.3 Functions and processes in IT management - Migrating from an ITIL reference model to a universal implementation model (see &lt;a href=&quot;http://www.itsmbookshop.com/Media/SampleFiles/9789087531003smpl.pdf&quot; title=&quot;http://www.itsmbookshop.com/Media/SampleFiles/9789087531003smpl.pdf&quot; rel=&quot;nofollow&quot;&gt;http://www.itsmbookshop.com/Media/SampleFiles/9789087531003smpl.pdf&lt;/a&gt;).&lt;br /&gt;
A must read for anyone not already infected by the belief that ITIL is a holy book.&lt;/p&gt;
</description>
 <pubDate>Sat, 14 Jun 2008 09:12:22 +0000</pubDate>
 <dc:creator>jvbon</dc:creator>
 <guid isPermaLink="false">comment 2978 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>itSMF map ITIL V3 processes</title>
 <link>http://www.itskeptic.org/node/640#comment-2977</link>
 <description>&lt;p&gt;itSMF systematically list the processes in ITIL.  See page 41 of &lt;a href=&quot;http://www.itsmf.com/upload/bookstore/itSMF_ITILV3_Intro_Overview.pdf&quot; target=&quot;_blank&quot;&gt;this booklet&lt;/a&gt; &lt;/p&gt;
</description>
 <pubDate>Sat, 14 Jun 2008 05:00:33 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 2977 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Along with Prince2, COBIT, ASL, ISO2700n ...  MoR is yet another</title>
 <link>http://www.itskeptic.org/node/640#comment-2976</link>
 <description>&lt;p&gt;They sure do.   Along with Prince2, COBIT, ASL, ISO2700n ...  MoR is yet another body or knowledge neither integrated nor referenced by ITIL.   Great, innit?&lt;/p&gt;
&lt;p&gt;P.S. dropping the name once in the intro of a book does not constitute referencing a BOK&lt;/p&gt;
</description>
 <pubDate>Sat, 14 Jun 2008 04:55:39 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 2976 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Competing Frameworks?</title>
 <link>http://www.itskeptic.org/node/640#comment-2974</link>
 <description>&lt;p&gt;Skep,&lt;/p&gt;
&lt;p&gt;Are the itSMFs 27 processes a competing framework? Last I knew they didn&#039;t have one! :-0&lt;/p&gt;
&lt;p&gt;kengon&lt;/p&gt;
</description>
 <pubDate>Fri, 13 Jun 2008 14:10:03 +0000</pubDate>
 <dc:creator>kengon</dc:creator>
 <guid isPermaLink="false">comment 2974 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>OGC has some guidance</title>
 <link>http://www.itskeptic.org/node/640#comment-2973</link>
 <description>&lt;p&gt;Surprise!  Outside of ITIL, OGC does offer guidance for Managment of Risk.&lt;/p&gt;
&lt;p&gt;You can find further information here:  http://www.best-management-practice.com/Risk-Management-MoR/&lt;/p&gt;
</description>
 <pubDate>Fri, 13 Jun 2008 12:53:14 +0000</pubDate>
 <dc:creator>ITIL citizen</dc:creator>
 <guid isPermaLink="false">comment 2973 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>InfoSec?</title>
 <link>http://www.itskeptic.org/node/640#comment-2972</link>
 <description>&lt;p&gt;Maybe InfoSec should be depreciated and made a subsection of Risk management?  As a process is Infosec more important than risk management?&lt;/p&gt;
</description>
 <pubDate>Fri, 13 Jun 2008 12:02:32 +0000</pubDate>
 <dc:creator>Red Pineapple</dc:creator>
 <guid isPermaLink="false">comment 2972 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Agree, I would&#039;t create a function in IT</title>
 <link>http://www.itskeptic.org/node/640#comment-2970</link>
 <description>&lt;p&gt;I see it a bit like Continual Service Improvement. When you look at CSI, it is very heavily dependent on the role of CSI Manager. He is the sort of torch bearer, evangelist or visionary person driving the CSI initiatives.&lt;/p&gt;
&lt;p&gt;In same manner security and risk should be driven or promoted by someone and executed by processes and functions in various parts of the lifecycle.&lt;/p&gt;
&lt;p&gt;Not a function in IT, in larger organizations such group or function could exist with larger scope than just IT? After all these are not just IT issues only.&lt;/p&gt;
&lt;p&gt;--- &lt;/p&gt;
&lt;p&gt;Good point though within ITIL world: it is a requirement in the syllabus. So the students should have some understanding on the various points in the lifecycle where you should spend some effort in managing risk. Cobit would give you some additional handle on what particular actions and artifacts should result...&lt;/p&gt;
</description>
 <pubDate>Fri, 13 Jun 2008 09:32:10 +0000</pubDate>
 <dc:creator>Seppo Tapola</dc:creator>
 <guid isPermaLink="false">comment 2970 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>no centralised Risk Management function in IT</title>
 <link>http://www.itskeptic.org/node/640#comment-2969</link>
 <description>&lt;p&gt;Welcome Seppo&lt;/p&gt;
&lt;p&gt;it&#039;s a study topic so one hopes there is some collated guidance somewhere.&lt;/p&gt;
&lt;p&gt;I guess I agree with your points - It is not one of the itSMF&#039;s 27 processes - so long as we accept there is no centralised Risk Management function in IT.  do we?&lt;/p&gt;
</description>
 <pubDate>Fri, 13 Jun 2008 08:25:49 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 2969 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Maybe the pieces should be collected to a process...</title>
 <link>http://www.itskeptic.org/node/640#comment-2968</link>
 <description>&lt;p&gt;...or maybe not.&lt;/p&gt;
&lt;p&gt;There are many viewpoints to risks.&lt;/p&gt;
&lt;p&gt;There are the risks that you need to think when you are doing Service Design, there it is embedded somewhere around Availability and IT Service Continuity, as one would expect.&lt;/p&gt;
&lt;p&gt;One should not forget the risks for the business, which I find are described in quite interesting way in Service Strategy. We IT people certainly understand that whenever you start contemplate the possibility of using IT in someway you are in big danger anyways ;-). Some good viewpoints in the green book though, written in a bit novel way. But I guess that Service Strategy really represents the point in ITIL V3, where the new IT really needs to stretch the envelope, move out from the traditional comfort zone and learn the true reasons why organizations are hiring them to play with expensive toys.&lt;/p&gt;
&lt;p&gt;Then we have the risk in Service Operation, pretty familiar to IT people.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;Maybe not a new process, please. In that way there would be the same danger that we have with security or quality.  &quot;It&#039;s not MY task to think of them, it&#039;s the ________ people who are managing that&quot;. So in same way that everybody is responsible for security or improving the quality, everybody should be thinking of the risks. &lt;/p&gt;
&lt;p&gt;But it wouldn&#039;t be a bad idea to have some condensed guidance for that...&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Seppo&lt;/p&gt;
</description>
 <pubDate>Fri, 13 Jun 2008 07:38:33 +0000</pubDate>
 <dc:creator>Seppo Tapola</dc:creator>
 <guid isPermaLink="false">comment 2968 at http://www.itskeptic.org</guid>
</item>
</channel>
</rss>
