Risk Management Policy
Kwanso LLC
01 Jan 2022
To define the methodology for assessing and managing Kwanso’s information security risks in order to achieve the company’s business and information security objectives.
The risk assessment process may be applied to all business processes, information, information systems, networks, devices, and information processing facilities that are owned or used by Kwanso applicants, employees, contractors, consultants, vendors, partners, and other users affiliated with Kwanso, or others using or accessing Kwanso networks and/or information systems.
Kwanso will ensure that risk management plays an integral part in the governance and management of the organization at a strategic and operational level. The purpose of a risk management policy is designed to ensure that the company achieves its stated business and security goals and objectives.
Kwanso has developed processes to identify those risks that would hinder the achievement of its strategic and operational objectives. Kwanso will therefore ensure that it has in place the means to identify, analyze, control, and monitor the strategic and operational risks it faces using this risk management policy based on best practices.
The IT Manager will ensure the risk management strategy and policy are reviewed regularly and that:
- The risk management policy is applied to relevant areas at Kwanso
- The risk management policy and its operational application are annually reviewed
- Non-compliance is reported to appropriate company officers and authorities
Kwanso may use a variety of risk reporting formats for the identification of risks, their classification, and evaluation based on factors such as vendors utilized, methodology employed, and the scope of the assessment. In general, and where possible, risks shall be assessed and ranked according to their impact and their likelihood of occurrence. A formal IT risk assessment, network penetration tests, and Kwanso production application penetration test will be performed at least annually.
In addition, an internal audit of the information security management system (ISMS) (i.e., information security controls and management processes) shall be performed at least annually.
Security risks shall be evaluated at various stages of the software design and development lifecycle as needed.
Some risks are within the control of Kwanso while others may be only to a lesser degree. Kwanso will consider the risks within each of the following categories:
- Technical
- Reputational
- Contractual
- Economic/Financial
- Regulatory/Compliance
- Fraud
Each identified risk will be assessed as to its likelihood and impact. Likelihood can be assessed as not likely, somewhat likely, or very likely. Impact can be assessed as not impactful, somewhat impactful, and very impactful. The likelihood and impact will be considered together to formulate an overall risk ranking.
The criteria for determining risk is the combined likelihood and impact of an event adversely affecting the confidentiality, availability, integrity, or privacy of customer data, personally identifiable information (PII), or business critical systems.
For all risk inputs such as risk assessments, penetration tests, vulnerability scans, etc., Kwanso management shall reserve the right to modify automated or third-party provided risk rankings based on its assessment of the nature and criticality of the system processing, as well as the nature, criticality and exploitability (or other relevant factors and considerations) of the identified vulnerability.
Risks will be prioritized and mapped using the approach contained in this policy. The following responses to risk should be employed. Where Kwanso chooses a risk response other than “Accept,” it shall develop a Risk Treatment Plan.
- Mitigate: Kwanso may take actions or employ strategies to reduce the risk.
- Accept: Kwanso may decide to accept and monitor the risk at the present time. This may be necessary for some risks that arise from external events.
- Transfer: Kwanso may decide to pass the risk on to another party. For example, contractual terms may be agreed to ensure that the risk is not borne by Kwanso, or insurance may be appropriate for protection against financial loss.
- Eliminate: The risk may be such that Kwanso could decide to cease the activity or to change it in such a way as to end the risk.
The procedure for managing risk will meet the following criteria:
- Kwanso will maintain a Risk Register and Treatment Plan.
- Risks shall be ranked by ‘likelihood’ and ‘severity/impact’ as critical, high, medium, low, or negligible.
- Overall risk shall be determined through a combination of likelihood and impact.
- Risks may be valuated to estimate potential monetary loss where practical, or may be considered relative to a control objective
- Kwanso will respond to risks in a prioritized fashion. Remediation priority will consider the risk likelihood and impact, cost, work effort, and availability of resources. Multiple remediations may be undertaken simultaneously.
- Periodic reports will be made to the senior leadership of Kwanso to ensure risks are being mitigated appropriately, and in accordance with business priorities and objectives.
Ultimately responsible party for the acceptance and/or treatment of any risks to the organization.
Can approve the avoidance, remediation, transference, or acceptance of any risk cited in the Risk Register. This person shall be responsible for communicating risks to top management and the board and adopting risk treatments in accordance with executive direction.
Shall be responsible for adherence to this policy.
Kwanso reserves the right to modify, amend or terminate this policy at any time.
Requests for an exception to this Policy must be submitted to the IT Manager for approval.
Any known violations of this policy should be reported to the IT Manager. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.
A threat event could be expected to have a limited adverse effect on organizational operations, mission capabilities, assets, individuals, customers or other organizations.
A threat event could be expected to have a serious adverse effect on organizational operations, mission capabilities, assets, individuals, customers or other organizations
A threat event could be expected to have a severe adverse effect on organizational operations, mission capabilities, assets, individuals, customers or other organizations.
A threat event could be expected to have a limited adverse effect, meaning: degradation of mission capability yet primary functions can still be performed; minor damage; minor financial loss; or range of effects is limited to some cyber resources but no critical resources.
A threat event could be expected to have a serious adverse effect, meaning: significant degradation of mission capability yet primary functions can still be performed at a reduced capacity; minor damage; minor financial loss; or range of effects is significant to some cyber resources and some critical resources.
A threat event could be expected to have a severe or catastrophic adverse effect, meaning: severe degradation or loss of mission capability and one or more primary functions cannot be performed; major damage; major financial loss; or range of effects is extensive to most cyber resources and most critical resources.
Adversary is unlikely to initiate a threat event; non-adversarial threat event (e.g., nature, error, accident) is unlikely to occur; or threat is unlikely to have adverse impacts.
Adversary is somewhat unlikely to initiate a threat event; non-adversarial threat event (e.g., nature, error, accident) is somewhat unlikely to occur; or threat is somewhat unlikely to have adverse impacts.
Adversary is highly likely to initiate a threat event; non-adversarial threat event (e.g., nature, error, accident) is highly likely to occur; or threat is highly likely to have adverse impacts.