Incident recovery - a risky business.
Risk management is more than documenting the hazards or identifying controls – it requires assessing the effectiveness of the controls selected. The attached video illustrates what can happen when risk management processes are not in place.
When assessing the effectiveness of the hazard controls, key questions to consider include:
Is the control the most effective solution to mitigate the hazard, or is it an easy stop gap to complete a task? Have you utilised the hierarchy controls for above the line solutions?
![](https://static.wixstatic.com/media/9b372d_6ce4d33a6ef245ea82c5c2dfa9d6e28a~mv2.png/v1/fill/w_980,h_671,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/9b372d_6ce4d33a6ef245ea82c5c2dfa9d6e28a~mv2.png)
Have personnel involved in the task (i.e. the subject matter experts) been included in the risk assessment process including the review of controls?
Does the control introduce other more serious hazards?
Is the control feasible from an operational, environmental and financial perspective?
What happens if the controls fail – do you have appropriate emergency management strategies in place?
Have you risk assessed the emergency response protocol prior to and during an incident recovery?
Remember assessing the effectiveness of hazard controls is ongoing process and should not be restricted to an annual desktop review.