top of page

Operational Resilience

Writer's picture: Anthony PecciaAnthony Peccia

Operational Resilience is the focus, capability, and capacity to rapidly recover from (op) risk events by having ready the necessary resources and well-prepared recovery plans.


See lesson 5 Operational Resilience readings for additional information



 
 
 

49 commentaires


Ansh Arora
Ansh Arora
07 nov. 2024

Under critical activities, there is 'Third Party,' and under recovery plans, there is 'Communication.' I have a question about this. Where would communication with third parties fall within this MECE framework? Does 'communication' here refer specifically to internal communication? Also, I wanted to confirm that 'third parties' refer to companies that assist in resolving issues and keeping the business operational—for example, a database company in case files go missing or a hardware company if computers go down.

J'aime

I have a question after finishing the cases related to each component of the RMF: Is a gap analysis mandatory for each of the ECRG? In addition, when I was discussing the class content with my groupmates, we still feel a bit confused about the timeline for each component. For example, is exposure considered the risk that the company should be careful with and try to avoid, while control refers to the process of managing the exposure to prevent the risk from occurring? Resilience, as mentioned above, is the recovery process from a risk event to mitigate the negative effects, while governance is more of a macro-level oversight to identify potential improvements in the overall regulatory activities. I want to…

J'aime
Anthony Peccia
Anthony Peccia
24 oct. 2024
En réponse à

Exposure is identifying and assessing the risk (i.e. the potential to experience a financial or reputational loss in the future), C is the controls you put in place to keep the residual risk within your risk appetite, R is the capability to quickly recover from loss events, and G is the structure that enables the organization to effectively and efficiently carry out the E, C and R and meeting reg requirements .

J'aime

Hangzhen Jin
Hangzhen Jin
17 oct. 2024

How can the MECE framework be applied to categorize recovery objectives, recovery plans, and critical activities to ensure no overlap and full coverage of potential operational disruptions? since a MECE structure approach supports continuous improvements, enabling the integration of evolving internal and third-party risks into resilience planning.

J'aime

Wenjun Zhang
17 oct. 2024

In the resilience section, we first identify critical activities, which are divided into internal and third-party categories. If the critical activities are third-party-dependent, what should be done in this case? Does the company still have any say or control over this?

J'aime

Chenyao.Wang
17 oct. 2024

After the Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) have been identified and aligned with business objectives and regulatory requirements, how frequently should the organization conduct simulations or stress tests to evaluate the effectiveness of the recovery plan and these objectives?

J'aime

Operational Risk Management That Works

brought to you by

MLX logo 2018.png

©2022 by Operational Risk Management That Works. Proudly created with Wix.com

bottom of page