Example: bachelor of science

United Nations Security Management System Security Risk ...

United Nations Security Management System Security Risk Management (SRM) manual Issued 11 December 2015 SRM manual Table of Contents 1 TABLE OF CONTENTS Introduction .. 1 Conceptual Overview .. 3 PART I: Introduction to Security as Risk Management .. 3 PART II: The Structured Approach to SRM .. 9 Step 1: Geographical Scope and Timeframe .. 11 Geographical Scope .. 11 Timeframe .. 11 Step 2: Situational Analysis .. 13 Step 3: Programme Assessment .. 17 Step 4: Threat Assessment .. 21 PART I: General Threat Assessment .. 21 PART II: Specific threats and event descriptions .. 26 Step 5: Security Risk Assessment .. 35 The Concept of Likelihood in the unsms .. 35 Prevention Vulnerability Assessment .. 36 Impact .. 38 Mitigation Vulnerability Assessment .. 39 Risk Levels .. 40 Step 6: Security Risk Management Measures .. 44 Projecting Required SRM Measures .. 44 Selecting SRM measures .. 44 The effects of SRM Measures - reducing Likelihood and Impact.

2 Who is covered by the UNSMS is found in Security Policy Manual, Chapter III, “Applicability of the United Nations Security Management System”. 3 Many United Nations organizations have a dedicated risk management approach that deals with risks beyond those categorized

Tags:

  Policy, Manual, Security, System, Management, Nations, Unsms, Security policy manual, Nations security management system security

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of United Nations Security Management System Security Risk ...

1 United Nations Security Management System Security Risk Management (SRM) manual Issued 11 December 2015 SRM manual Table of Contents 1 TABLE OF CONTENTS Introduction .. 1 Conceptual Overview .. 3 PART I: Introduction to Security as Risk Management .. 3 PART II: The Structured Approach to SRM .. 9 Step 1: Geographical Scope and Timeframe .. 11 Geographical Scope .. 11 Timeframe .. 11 Step 2: Situational Analysis .. 13 Step 3: Programme Assessment .. 17 Step 4: Threat Assessment .. 21 PART I: General Threat Assessment .. 21 PART II: Specific threats and event descriptions .. 26 Step 5: Security Risk Assessment .. 35 The Concept of Likelihood in the unsms .. 35 Prevention Vulnerability Assessment .. 36 Impact .. 38 Mitigation Vulnerability Assessment .. 39 Risk Levels .. 40 Step 6: Security Risk Management Measures .. 44 Projecting Required SRM Measures .. 44 Selecting SRM measures .. 44 The effects of SRM Measures - reducing Likelihood and Impact.

2 46 Integrated Systems Approach .. 47 Decision-making and Implementation .. 48 Step 7: Security Risk Management Implementation .. 52 Step 8: Acceptable Risk .. 56 Acceptable Risk Model .. 56 Programme Criticality Tool .. 58 Step 9: Review and Monitoring .. 59 Security Risk Management Areas Monitoring and Review .. 60 Support: DSS Guidance on SRM Process Management , Support and Oversight .. 65 SRM Flow Process .. 65 SRM Support and Error! Bookmark not defined. SRM 68 SRM manual Table of Contents 2 Annex A: Glossary .. 69 Annex B: Programme Planning Cycle .. 71 Annex C: Programme Criticality Tool .. 73 Annex D: General Threat Assessment Definitions and Security Levels .. 89 Part I: Definitions of Descriptors in the General Threat Assessment.. 89 Part II: The General Threat Assessment and Security Levels .. 95 SRM manual Introduction 1 Introduction Introduction Security Risk Management (SRM) is a United Nations Security Management System ( unsms ) analytical process for assessing the operational context of the UN in order to identify the risk level of threats that may affect UN personnel, assets, premises and operations on the basis of which, Security Management decisions are made.

3 The SRM process was first launched by the unsms in 2004. Since then, it has been updated in a new unsms policy in 2009 and there have been multiple additional related guidelines, training tools and templates intended to improve the process. In July 2010, the Inter-Agency Security Management Network (IASMN) formed a working group with the original purpose of examining ways to improve likelihood assessments within the Security Risk Management (SRM) model. The working group included senior Security professionals from DSS and several UN organizations, from the field and headquarters. In January 2011, the IASMN, cognizant of the need for broader enhancements of the SRM process, expanded the remit of the working group beyond the area of likelihood assessments to include the entire SRM process. Reviews of Security Risk Assessments (SRA) and the resulting recommendations and decisions indicated that the following areas could be further enhanced: The reliability and validity of Security risk assessment; The context-specific Security risk Management strategies; Structured decisions for acceptance of risks; Dynamic, responsive and flexible application of the SRM process, to changes in the situation and programming.

4 These improvements, among others, will result in increased trust in the SRM process and as a tool to better enable Security advisors and decision-makers to effectively manage risk. This manual combines policy , guidelines and technical instruction on SRM that any user should be able to use to expand their knowledge of the theory and practice of SRM in the unsms . The manual contains new concepts and definitions and will guide users in applying the SRM process. Even though the SRM is a component of all unsms policies, guidelines and procedures, this manual does not address all aspects of Security Management in the unsms . Reference is, therefore, made to the Security policy manual and the Security Management Operations The manual is structured to follow the sequence of the SRM process. After the introduction and conceptual overview, each chapter of the manual deals with a distinct step in the SRM process discussing the theory behind it, a 1 See SRM manual Introduction 2 clear explanation of the components of each step and ends with a snapshot of the unsms SRM tool.

5 Once readers have familiarized themselves with the details of this manual , they will have the knowledge and tools to apply the SRM process to their work environment covering a broad spectrum of the work of the UN. Outputs of the SRM process are: 1. A Security Risk Management Area or Ad-hoc SRM document; 2. An overview Designated Area Security Risk Management document (previously referred to as the Country SRA ); 3. A change summary document and; 4. An SRM document in support of decisions regarding specific programme, premises or activities associated with unique threats. SRM manual Conceptual Overview 3 Conceptual Overview Conceptual Overview PART I: Introduction to Security as Risk Management The purpose of this chapter is to introduce readers to the main concepts involved in risk Management and how risk Management is applied to Security in the United Nations Security Management System ( unsms ).

6 2 The terms risk and risk Management have been commonly used to apply to other components of the United Nations System , including business continuity, emergency preparedness, and audit. Despite their increased use, or perhaps because of it, the terms and the processes they encompass are not clearly or commonly understood. That is why it is necessary to explain what Security Risk Management means, why it is important to the unsms , and how it uses a simple but structured decision-making model to help the United Nations System better achieve its goals. What is Security Risk Management ? Security Risk Management is our System of identifying future harmful events that may affect the achievement of objectives: assessing them for likelihood and impact; and determining an appropriate response. Any United Nations objective, from global strategic goals to local programme plans, may fail because of various obstacles.

7 In the Security context, obstacles are called threats. All managers must identify threats and evaluate how these threats may affect their objectives. In many of the places where we work, the effect of threats, if not managed, can be fatal to personnel and programmes. Risk, on the other hand, is the combination of the likelihood of a threat being carried out and the subsequent impact for an organization. The process whereby a manager identifies, evaluates and systematically deals with obstacles to success is risk Management . Security measures can either be used to prevent a vulnerability from being exploited or mitigate the impact of an exploitation, or both. One way to think of risk Management is that it is the systematic determination and implementation of timely and effective approaches for managing the effects of threats to the organization. Security Risk Management is merely the Management of Security -related risks3.

8 Why is it Important? Security Risk Management is an essential Management tool. It increases our chances of achieving our goals by decreasing the effect of threats. Security Risk Management offers a structured approach to help make good decisions and allows for clear accountability. It allows managers to maximize 2 Who is covered by the unsms is found in Security policy manual , Chapter III, Applicability of the United Nations Security Management System . 3 Many United Nations organizations have a dedicated risk Management approach that deals with risks beyond those categorized as Security risks . Often that System is called Enterprise Risk Management . Key Definition Risk Management : The systematic determination and implementation of timely and effective approaches for managing the effects of threats to the organization. SRM manual Conceptual Overview 4 programme opportunities and to allocate Security -related resources in ways that enable programme delivery within acceptable levels of risk.

9 It is vital to achieving the planned and envisioned programme results for the organizations, especially in complex and dangerous environments. Definition of Risk Although the steps of Security Risk Management are clear and simple, it is important to understand what risk is. The unsms has adopted the concepts of Likelihood and Impact to define Risk; the assessment of Risk, therefore, is an assessment of how vulnerable the Organization is to an undesirable event (a Threat), expressed in terms of Likelihood (the prospect of the event occurring) and Impact (the effect of the event if it does occur). To illustrate, risk is intuitively composed of two components (Likelihood and Impact), take the example of a tightrope walker - most people have little hesitation walking along the top of a table or bench. If you raise the table or bench 100 feet/30 meters in the air, most people would feel very uncomfortable doing the same thing.

10 This is because they intuitively know that the risk has changed. Even though the likelihood of falling off the table is the same in both situations, the impact (if they were to fall) in the second situation is significantly higher. If the table is shrunk to the size of a rope, as it is for a tightrope walker, then the likelihood of falling also increases. Thus, the risk from falling is a combination of both the likelihood of falling and the impact of the Understanding that risk is a combination of likelihood and impact, it is clear that managing risk is a question of managing likelihood and impact. A tightrope walker may use a large pole to increase his balance and lower the likelihood of falling. He may also install a net below the tightrope so that if he does fall, the impact will be less serious. In this way, he has managed his risk by managing both likelihood and impact. When discussing the Management of risks, the unsms has adopted the terms Prevention and Mitigation ; taking measures to reduce Likelihood is called Prevention 5 while taking measures to reduce Impact is called Mitigation.


Related search queries