Unit 1: Security Risk Management Framework
You have been employed as a Security Consultant for a large, UK based NGO that conducts projects worldwide, often in remote and hostile environments. You have been tasked with assessing the current Risk Management and Security Support Services, updating them, and implementing a strategy to adopt any changes.
For this Unit, further details, a description of the organisation, its activities and its current Security Risk Management framework can be seen at Annexes A and B
The assignment is broken down into three distinct tasks as follows.
Task 1: Understand Security Enterprise Risk Management Frameworks (SERM)
Task: Write a detailed analysis of the existing Security Risk Management (SRM) framework of the NGO (using Annex A for background and context), identify areas for improvement, and propose an enhanced strategy that integrates the principles of ISO 31000 and COSO for effective Security Enterprise Risk Management (SERM).
Task Description: Write a report that includes the following instructions:
Introduction
• Define Security Risk Management (SRM) using a source to reference as evidence
• Explain the use of ISO31000 and COSO as effective SERM models within the paper
• Provide a brief overview of the NGO for context
LO1.1 Explain the Importance of SRM Framework:
• Discuss the significance of having a structured SRM framework in place, especially for an NGO operating in remote and hostile environments.
• Highlight how a well-defined SRM framework can help in identifying, assessing, and mitigating security risks effectively.
LO1.2 Evaluate the contribution of Security Enterprise Risk Management (SERM) to effective security:
• Evaluate how SERM contributes to the overall security position of the organisation, using COSO (2017) as an example.
• Provide examples of how SERM practices have enhanced security measures in similar organisations
LO1.3 Demonstrate the use of ISO 31000 risk management principles in a Security Risk Management context within an organisation:
• Demonstrate the application of ISO 31000 risk management principles within the context of the NGO’s SRM.
• Analyse the current policy and process through the lens of ISO 31000, identifying gaps and suggesting improvements.
LO1.4 Explain how the generic approach of ISO 31000 and COSO can be combined to best fit a SERM strategy:
• Explain how the generic approaches of ISO 31000 and COSO can be amalgamated to develop a robust SERM strategy.
• Propose a model that integrates both frameworks, tailored to the unique needs and challenges faced by the NGO.