Toward a Risk Management Framework for the DNS April 2013 Beijing - - PowerPoint PPT Presentation

toward a risk management framework for the dns
SMART_READER_LITE
LIVE PREVIEW

Toward a Risk Management Framework for the DNS April 2013 Beijing - - PowerPoint PPT Presentation

Toward a Risk Management Framework for the DNS April 2013 Beijing ! 1 Who we are VAUGHAN RENNER RICHARD WESTLAKE COLIN JACKSON 2 A risk management framework is not a risk or threat assessment but what you put the assessment into that


slide-1
SLIDE 1

Toward a Risk Management Framework for the DNS

!

April 2013 Beijing

1

slide-2
SLIDE 2

Who we are

RICHARD WESTLAKE COLIN JACKSON VAUGHAN RENNER

2

slide-3
SLIDE 3

not a risk or threat assessment but what you put the assessment into that helps you manage risks and prioritise actions and investments to mitigate the risks

A risk management framework is

3

slide-4
SLIDE 4

Risk frameworks in the wild

4

slide-5
SLIDE 5

How we will build it

Come to Toronto to gather information Develop principles to cover DNS Risk Management Analyse candidate frameworks against principles Tailor it to fit multistakeholder environment Test it using example risks from DSSA WG Present it at Beijing

5

slide-6
SLIDE 6

RMF Principles

  • ICANN is a unique identity, embedded in a community
  • f interest
  • The DNS is a technically unique and important system
  • Provide a means to fostering an enduring risk culture

within ICANN

  • Avoid a monoculture
  • Adapt not reinvent
  • Process is not a substitute for thought
  • Cover risks that are within ICANN’s sphere of

concern, but not necessarily under its control

6

slide-7
SLIDE 7

Westlake Governance Principles

  • For practitioners, by practitioners
  • Outputs must be actionable
  • Actions must be measurable

7

slide-8
SLIDE 8

One Size Does Not Fit All

Controllable Risks

8

slide-9
SLIDE 9

One Size Does Not Fit All

Controllable Risks External Events

9

slide-10
SLIDE 10

One Size Does Not Fit All

Controllable Risks External Events Strategic Risks

Acknowledgment: R Kaplan & A Mikes, Managing Risks: A New Framework, Harvard Business Review, June 2012

10

slide-11
SLIDE 11

Risk framework - controllable risks

11

slide-12
SLIDE 12

Risk framework - external events

12

slide-13
SLIDE 13

Risk framework - strategic risks

13

slide-14
SLIDE 14

Risk framework - all risk types

14

slide-15
SLIDE 15

Taxonomy of Risk

15

slide-16
SLIDE 16

Taxonomy of Risk

(ICANN ¡communicates) (ICANN ¡seeks ¡consensus) (Board ¡has ¡direct ¡influence)

16

slide-17
SLIDE 17

Who does what: controllable risks

17

slide-18
SLIDE 18

Who does what: external events

18

slide-19
SLIDE 19

Who does what: strategic risks

(Consequences of a business decision)

19

slide-20
SLIDE 20

Taxonomy of Risk - Examples

(Board ¡has ¡direct ¡influence) (ICANN ¡seeks ¡consensus) (ICANN ¡communicates)

20

slide-21
SLIDE 21

Next steps

Present proposed RMF at Beijing Seek community and staff feedback on the proposed RMF Further testing of RMF using example risks from DSSA WG Agree with ICANN staff Principles for developing:

  • Risk Triggers
  • Escalation processes
  • Mitigation or response actions

Revise RMF as appropriate Assess preparedness of staff Present final RMF at Durban

21

slide-22
SLIDE 22

Let’s talk

{richard,colin,vaughan}@westlakegovernance.com www.westlakegovernance.com

!

22