15.08.2018 Views

become-itil-foundation-certified-abhinav-kaiser(www.ebook-dl.com)

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4.6.1.2 Risk Analysis<br />

Chapter 4 ■ Service Strategy<br />

After you think you have identified all the risks (which is impossible), add another<br />

column next to the risk to identify the probability that the risk could materialize:<br />

• Datacenter losing power during janitorial activities: Low<br />

• End users losing connectivity to business applications: Medium<br />

• Employees taking sick leave in December: High<br />

Also, you would expound on the potential impact that you identified in the previous<br />

activity—risk identification. There are two ways to analyze an impact: quantitative and<br />

qualitative. In one column, you could quantify the impact by providing numbers for the<br />

impact, such as 100 users impacted and losses amount to $10,000. In the next column,<br />

you can describe the impact in words, the things that cannot be quantified. Such as the<br />

<strong>com</strong>pany losing the brand image and facing legal action from customers.<br />

The next item on the agenda to analyze is the mitigation actions. For every identified<br />

risk, you need to <strong>com</strong>e up with a plan to mitigate it. Remember that you cannot avoid all<br />

risks, so you need a concrete plan to han<strong>dl</strong>e them when risk events are realized.<br />

4.6.2 Risk Management<br />

Risk management is twofold: pro-active and reactive, with the emphasis being on being<br />

pro-active.<br />

Reactive risk management is straightforward. You have a risk register that lists all the<br />

risks against the mitigation actions. When it happens, whoever is in charge needs to take<br />

mitigation action and see it through the day. Nothing fancy about it, but it’s a necessity.<br />

Pro-active risks can be managed by reviewing the risk register regularly. Basically<br />

in this activity, smart people in the room look at every risk and the probability of it<br />

happening and review if it is still the case. If the probability has changed, the risk register<br />

is updated. It is possible that the janitor tripping over the power line is no longer a risk<br />

one year after it was recorded, as janitors are no longer allowed to enter datacenters.<br />

Perhaps air quality issues where resolved because there is a new technology in place that<br />

automatically sucks all the dust through its ducts, and the air conditioning <strong>com</strong>es with<br />

improved air purifying filters that ensure 99.99% dust-free air.<br />

Risk management overall is an interesting activity. Although you play the devil’s<br />

advocate, it helps you understand the stability of the service and keeps you better<br />

prepared for the worst to <strong>com</strong>e. As the adage goes, expect the best and plan for the worst.<br />

4.7 Governance<br />

Governance is a way of organizing, amplifying, and constraining power.<br />

—Rebecca MacKinnon<br />

53

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!