Attachment 4 - IT Risk Management Strategy and Process.pdf
PDF 439 KB Posted
- Attached to
- LEGACY PIMS ACTUARIAL and IT SUPPORT SERVICES Federal contract opportunity
- Solicitation number
- 16PBGC25R0056
- Issued by
- Pension Benefit Guaranty Corporation
About this file
This document is an IT Risk Management Strategy and Process document for the Pension Benefit Guaranty Corporation (PBGC), version 9.0, dated March 12, 2025. The document outlines a comprehensive framework for identifying, assessing, and managing information technology risks across three core functional areas: CIO Programs, IT Programs, and Cybersecurity. The strategy establishes a disciplined approach to risk management that aligns with Office of Management and Budget (OMB) guidance and Project Management Institute (PMI) best practices.
The document details a six-step IT Risk Management Process: 1) Identify IT Risks, 2) Assess and Document IT Risks, 3) Identify and Document IT Risk Response, 4) Execute IT Risk Response, 5) Risk Review, and 6) Review and Re-Evaluate IT Risks and Responses. The risk assessment methodology includes determining probability (on a scale of 1-5) and impact (also on a scale of 1-5), with risks rated by multiplying these values. The strategy emphasizes continuous risk monitoring, reporting to various levels of management, and maintaining a risk register. High-risk items (with ratings of 13-25) are reported annually to the PBGC Risk Management Officer and managed in a Centralized Risk Register.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 06 Amendment 2 - 16PBGC25R0056.pdf | ||
| 06 Clauses.pdf | ||
| 06 Combined Synopsis and Solicitation - 16PBGC25R0056_Revised 2.pdf | ||
| Combined Synopsis and Solicitation - 16PBGC25R0056_Revised 2.pdf | ||
| PBGC Responses to Contractor Questions.pdf | ||
| Combined Synopsis and Solicitation - 16PBGC25R0056_Revised.pdf | ||
| Attachment 7 - Pricing Schedule Table (Revised).xlsx | XLSX spreadsheet | |
| Attachment 3 - Team workflow and separation of Duties.pdf | ||
| Attachment 5 - ITSLCM Framework.pdf | ||
| Attachment 6 - Section 508 Requirments for LPIMS.pdf | ||
| Attachment 7 - Pricing Schedule Table.xlsx | XLSX spreadsheet | |
| Combined Synopsis and Solicitation - 16PBGC25R0056.pdf | ||
| Attachment 1 - Legacy PIMS Fact Sheet.pdf | ||
| Attachment 2 - Legacy PIMS Task Map and Labor Projections.pdf | ||
| Attachment 8 - Wage Determiniation.pdf |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Office of Information Technology Policy and Compliance Division
IT Risk Management Strategy And Process
Version 9.0
March 12, 2025 ii
REVISION HISTORY
Version Date Nature of Change Entered By
1.0 March 1 - April
13, 2017
Incorporated feedback from BISD Managers and staff, the PCD Manager, IT Risk Managers, support personnel and the PBGC Risk Management Officer
Ella McCutcheon
2.0 Feb 28, 2018 –
May 2, 2018
Incorporated feedback received from the PCD Manager, BISD, and the IT Risk Management Process Owner.
Ella McCutcheon
3.0 March 4, 2019 –
April 16, 2019
Incorporated feedback received.
Ella McCutcheon
4.0 April 23, 2019 –
March 9, 2020
Incorporated feedback received.
Ella McCutcheon
5.0 March 12, 2021 –
March 26, 2021
Incorporated feedback received.
Ella McCutcheon
6.0 March 1, 2022-
March 17, 2022
Incorporated feedback received.
Ella McCutcheon
7.0 February 7, 2023
– March 13, 2023
Incorporated feedback received.
Ella McCutcheon
8.0 February 6, 2024
– March 7, 2024
Incorporated feedback received.
Ella McCutcheon
9.0 February 13, 2025 – March 12, Incorporated feedback received.
Ella McCutcheon iii
Table Of Contents
1. INTRODUCTION
2. IT RISK MANAGEMENT FRAMEWORK
2.1 DEFINITIONS………………………………………………………………………...………………….6
2.1.1 IT RISK
2.1.2 IT RISK MANAGEMENT
2.1.3 IT RISK REGISTER
2.2 CONSISTENT APPROACH TO DETERMINING PROBABILITY AND IMPACT
2.3 IT RISK RATING AND TOLERANCE
2.4 IT RISK REPORTING
3. ROLES AND RESPONSIBILITIES
4. THE IT RISK MANAGEMENT PROCESS
4.1 IDENTIFY IT RISKS
4.2 ASSESS AND DOCUMENT IT RISKS
4.3 IDENTIFY AND DOCUMENT IT RISK RESPONSE
4.3.1 EVALUATE POTENTIAL IT RISK TREATMENT
4.3.2 DEVELOP THE APPROPRIATE IT RESPONSE
4.4 EXECUTE IT RISK RESPONSE
4.5 RISK REVIEW
4.6 REVIEW AND RE-EVALUATE IT RISKS AND RESPONSES
4.6.1 HAS THE IT RISK BEEN REALIZED?
4.6.2 DOES THE IT RISK STILL EXIST?
4.6.3 IS IT RISK RESPONSE EFFECTIVE?
5. IT RISK MANAGEMENT STRATEGY AND PROCESS MAINTENANCE………...…….……...17
APPENDIX A – OMB RISK CATEGORIES
APPENDIX B – ACRONYMS
APPROVAL
1. Introduction
Good risk management practices allow The Office of Information Technology (OIT), to reduce service interruptions, prevent data losses, increase the probability of delivering projects on time, within budget, and more. OIT practices risk management in many areas.
The purpose of this document is to formally establish a consistent and disciplined strategy for managing Information Technology (IT) Risks at the Pensions Benefit Guaranty Corporation (PBGC) with these expected outcomes:
• Ensure processes align with the current administration priorities to improve operational efficiencies
• The fulfillment of OMB Circular A-123 internal control requirements
• The fulfillment of NIST 800-53/PM-9 control requirements and an established risk management strategy for organizational and operational risks
• The ability to consistently leverage formal up-to-date risk management practices.
• An established standard approach to managing, tracking, and reporting IT related risks
• An established formal escalation path for IT-related risks
This IT Risk Management Strategy and Process Document covers the following topics:
• IT Risk Management Framework
• Roles and Responsibilities
• IT Risk Management Process
• IT Risk Management Strategy and Process Maintenance
2. IT Risk Management Framework
The CIO Leadership Team established the IT Risk Management Framework, shown below in Figure 1. This framework is in alignment with the Office of Management and Budget (OMB) guidance and the Project Management Institute (PMI) best practices. In addition, this framework serves as a foundation to the IT Risk Management Strategy and Process of which provides a disciplined approach to discovering and managing IT Risks in three (3) core IT Functional Areas (CIO Programs, IT Programs, and Cybersecurity).
CIO Programs: These are core CIO Programs that are essential to the CIO operations and contribute to OIT’s mission objectives. The programs are:
• Policy and Compliance
• Enterprise Architecture Program
• IT Portfolio Management Program
• Program Governance Division
• Enterprise Cybersecurity Department
• Information Technology Infrastructure Operations Department
UIT Programs: IT Programs in the PBGC IT Portfolio are Information Systems that enable PBGC to perform their operations in an automated manner, typically managed collectively by both IT and Business Program Managers. IT and Business Program Managers are supported by IT and Business Project Managers.
Cybersecurity Risks: All Cybersecurity risks related to the full security life cycle of Information Systems are managed using the Information System Risk Management Framework (RMF) Process which can be found in the OIT Process and Procedures Library (PPL).
Figure 1. IT Risk Management Framework
PBGC has established an Enterprise Risk Management (ERM) Program, coordinated via the PBGC Risk Management Council (RMC) and the PBGC Risk Management Officer. The purpose of the program is to assist agency leaders, management, and the Board of Directors to identify, assess, quantify, manage, and mitigate PBGC’s https://pbgcgov.sharepoint.com/EGD/PCD/Pages/PPL_Home.aspx risks. The IT Risk Management process has been optimized and well-integrated with the PBGC ERM since its inception.
A monthly IT Risk Management CIO IT Programs Report is provided and the OIT High Risk Register is provided annually to further enhance the ERM Program.
2.1 Definitions
2.1.1 IT Risk
A “risk” is an uncertain event or condition that, if it occurs, has a positive or negative effect on a program’s mission, purpose, objectives, financial stability, or reputation. An Information Technology Risk is a risk that could occur within the area of Information Technology. Risks may have one or more causes and one or more impacts.
2.1.2 IT Risk Management
IT Risk Management is the disciplined approach for proactively identifying, prioritizing, and measuring the impact of IT Risks, and developing, selecting, and managing options for handling those risks; not necessarily to eliminate them entirely, but to reduce the probability of the occurrence and/or minimize their impact if the risk is realized.
Essentially, risk management is anticipating and making plans for what will go wrong. Each program area will document how risks are managed in their respective program plan.
2.1.3 IT Risk Register
An IT Risk Register is the document where all the risks related to a program are captured and the risk response is documented.
An IT Risk Register Template is available via the OIT Process and Procedures Library (PPL). The use of this template is not mandatory.
However, using a standard template will help to a mature the organization.
An automated tool, (P3M), the Project, Program, Portfolio Management Solution, is available to manage IT CIO Program Risks.
CIO Programs Risks with an IT Risk Rating of 13 – 25 will be reported to the PBGC RMO (Risk Management Officer) annually and managed in a Centralized Risk Register maintained by the OIT Risk Management Council Representative.
2.2 Consistent Approach to Determining Probability and
Impact
To ensure that all IT Risks are assessed and managed in a consistent manner, a common approach has been established for assessing the probability and impact of a given risk:
Probability
The ”Probability” that the risk event will occur is assessed on a scale from 1 to 5, as follows:
1 = Rare: Probability of a ≤ 10% chance of the risk occurring
2 = Unlikely: Probability of a ≥ 10% to < 35% chance of the risk occurring
3 = Possible: Probability of a ≥ 35% and < 65% chance of the risk occurring
4 = Likely: Probability of a ≥ 65% and < 90% chance of the risk occurring
5 = Very High: Probability of a ≥ 90% chance of the risk occurring
Impact
The “Impact” of the risk event is assessed on a scale of 1 to 5, as follows:
1 = Low impact (e.g., impact to scope, cost, schedule, resources, and the agency to meet its strategic and mission goals are insignificant) https://pbgcgov.sharepoint.com/Sites/p-OMA/RMG/RiskRegister/Lists/Risk%20Register/OIT.aspx
2 = Minor impact (e.g., impact to scope, cost, schedule, and resources is material within an investment/work unit but stakeholders remain unaffected, impact the agency to meet its strategic and mission goals are marginal)
3 = Medium impact (e.g., impact to scope, cost, schedule, and resources is material for a Department and requires Steering Committee, Information Technology Investment Review Board (ITIRB) and/or Budget Planning Integration Team (BPIT) actions;
some participants or practitioners are impacted with minimal visibility to the Board and/or Congress, impact the agency to meet its strategic and mission goals is moderate)
4 = Major impact (e.g., impact to scope, cost, schedule and/or resources would require EMC involvement, a portion of participants/practitioners are impacted and PBGC’s Director should be briefed; impact the agency to meet its strategic and mission goals are significant)
5 = Catastrophic impact (e.g., level 4 but a substantial portion of participants/practitioners would be adversely impacted, and the Board and/or Congress should be briefed; impact the agency to meet its strategic and mission goals is extreme)
2.3 IT Risk Rating and Tolerance
The risk rating is determined by multiplying the “Probability” of the risk by the “Impact” of the risk; known as (PxI). The risk rating is then used to establish the risk tolerance, the level of risk or degree of uncertainty that is acceptable to the organization”. Both the risk rating and tolerance are depicted on the below heat map which provides risk visibility and a reporting scale.
Table 1. IT Risk Rating (PxI), Tolerance and Reporting Path
**Note: CIO Programs Risks with an IT Risk Rating of 13 – 25 will be reported to the PBGC RMO (Risk Management Officer) annually. OIT High Risk submitted to the PBGC RMO will be managed in a Centralized Risk Register maintained by the OIT Risk Management Council Representative.
2.4 IT Risk Reporting
IT Risks are reported at various levels depending upon the rating of the risk. An IT Risk Management Monthly CIO IT Programs Report is provided to the CIO and appropriate personnel. CIO Programs Risks with an IT Risk Rating of 13 – 25 are reported to the PBGC Risk Management Officer annually. OIT High Risk submitted to the PBGC RMO will be managed in a Centralized Risk Register maintained by the OIT Risk Management Council Representative. Program Managers are responsible for reporting program risks. Systems, cybersecurity and privacy risks are addressed in the Information System Risk Management Framework (RMF Process) that is available via the OIT Process and Procedures Library (PPL).
IT Risk Rating
(PxI)
IT Programs
Reporting Path
CIO Programs
Reporting Path
13 - 25
Severe - Extreme
Governance Boards/OMB EMC/OMB/RMO (see below note)
10 - 12
Moderately High
CIO/CXO CIO
5 - 9
Moderate
IT/Business Program Managers
CIO Program Director
1 - 4
Extremely Low - Minor
IT/Business Project
Managers
IT/Business Program Managers
CIO Program Manager https://pbgcgov.sharepoint.com/Sites/p-OMA/RMG/RiskRegister/Lists/Risk%20Register/OIT.aspx https://pbgcgov.sharepoint.com/Sites/p-OMA/RMG/RiskRegister/Lists/Risk%20Register/OIT.aspx
3. Roles and Responsibilities
The essential roles of PBGC’s IT Risk Management are defined in the table below.
Table 2. Roles and Responsibilities
Roles Responsibilities
All PBGC and IT Staff
• Understand that IT Risk Management and risk awareness are a key part of the organization’s culture and their job
• Understand their role in managing individual risks
• Understand how they can enable continuous improvement of IT Risk Management
• Systematically and promptly report to their CIO Program
Manager any perceived new risks or failures of existing control measures
IT Risk Manager (s) (IT Programs and CIO Programs)
• Identify the frequency of when the risks are discussed and reported. For example, holding weekly, bi-weekly, monthly, or quarterly risk discussions are held and frequency of reporting the risk register
• Develop and maintain a risk register for their IT Programs regardless of size of the IT Programs
• Lead and conduct joint (IT and Business) continuous risk planning and execution activities as outlined in the IT Risk Management Strategy and Process Document
• Periodically review their risk register with their department director or equivalent and their C-Level executive if appropriate
• Work together as a team of IT and Business members in managing the risks; provide regular reporting to the CIO and CXO of those risks in accordance with the risk reporting paths as outlined in this document
OIT Managers
• Participate in the review of IT Risks within their areas
• Review and approve recommended risk responses for reported/escalated risks
• Support the IT Risk Manager with execution of selected risk response
Roles Responsibilities
• Escalate IT Risks as appropriate
• Promote healthy IT Risk Management practices across the organization
CIO/CIO Leadership Team
• Review and approve recommended risk responses for reported/escalated risks
• Support the IT Risk Manager with execution of selected risk response
• Report/escalate IT Risks as appropriate, including escalation to the RMO and the Executive Management Committee
• Promote healthy IT Risk Management practices across the organization
IT Risk Management Process Owner
• Define and maintain a standard risk management process
• Coordinate and or perform various functions and work activities at all levels of the process
• Make changes in the process (as necessary) and manage the entire process cycle to ensure performance effectiveness
• Report IT Risks to the RMO on behalf of the CIO
• Support the CIO Leadership Team with addressing
Inspector General inquiries on IT Risk Management
4. The IT Risk Management Process
PBGC has designed an IT Risk Management Process that consists of several tasks and decisions, as shown in Figure 2 on the next page. The results of the process are captured in an IT Risk Register.
Figure 2. PBGC’s IT Risk Management Process
Monitor The RisksAs Risks Are Identified
Execute IT Risk Response
Identify And Document IT Risk
Response
Assess And Document The IT
Risk
Review And Re- Evaluate IT Risks And Responses
Retire IT Risk And Manage As
An Issue
Report Progress & Escalate
IT Risk Realized?
IT Risks Still Exists?
Is IT Risk Response Effective?
Retire IT Risk
Yes
Yes
No
No
No
Yes
Identify IT Risks
IT Risk Management is a continuous process that is performed throughout the life of a program with IT Risks entering and retiring at various times. The following are instructions for completing each of the steps in the IT Risk Management Process.
4.1 Identify IT Risks
IT Risk Identification usually occurs in two different ways. The first is Formal Risk Identification. The second is Ongoing Risk Identification.
Formal Risk Identification: To establish the initial IT Risk Register for a program, a session or a portion of a meeting is normally held with stakeholders to identify potential IT Risks.
Ongoing Risk Identification: IT Risks are also identified throughout the life of the program as the scope, budget, resources, and priorities change or as new information is obtained.
Again, risks are things that can or will go wrong in any program. Some examples of risk are below.
• A change of uncertain requirements
• Budget overages, shortfalls, hardware, and software renewal costs
• A change in business need • Unplanned changes in staff
• Organizational change • Inadequate facilities in which to place new staff or contractors
• Unprecedented efforts – estimates unavailable
• Lack of response to data calls for contracts inventory and staffing
• Infeasible design • Lack of compliance with federal standards, guidance, and policies
• Unavailable technology • Uncertain or inadequate new subcontractor capability
• Unrealistic schedule estimates or allocation
• Uncertain or inadequate new vendor capability
• Inadequate staffing, skills, or tool resources
• Insufficient capacity to handle data growth and new systems due in part to an unforeseen large plan termination or several small plan terminations
• Cost or funding issues • Other risks outside of the realm of technology
To further help in the identification of risks, the Office of Management and Budget (OMB) has established 14 risk categories for use. (See Appendix A - OMB Risk Categories)
4.2 Assess and Document IT Risks
Continue the IT Risk Management Process by assessing and documenting the IT Risks.
• Determine the impact and probability of the IT Risk (Section 2.2)
• Calculate the risk rating (Section 2.3)
• Evaluate the priority/visibility of the risk (Section 2.3)
• Determine whether the risk needs reporting/escalation (Section 2.3)
• Enter the information into the program’s IT Risk Register
4.3 Identify and Document IT Risk Response
The next step in the process is to identify and document the IT Risk Response necessary to reduce the probability and/or impact of the risk. This is an important element which requires the IT Risk Manager to balance the cost of mitigating the risk with the risk rating and priority.
IT Risks can be positive or negative. Positive IT Risks are opportunities to increase value or produce positive outcomes. Thus, risk responses may include enhancing, increasing, or ensuring that the opportunity will definitely happen. The response can also include sharing the risk with another organization or ignoring the probability of the opportunity occurring.
Negative IT Risks or threats decrease value or produce a negative outcome.
Therefore, the risk response should mitigate or minimize the IT Risk to an acceptable level through avoidance, reduction, transference, or acceptance or any combination thereof.
Regardless of whether the IT Risk is positive or negative, a response must be developed and documented to treat the opportunity or threat.
4.3.1 Evaluate Potential IT Risk Treatment
Once an IT Risk has been identified and assessed, techniques to manage the IT Risk fall into one or more of these major categories:
• RETAIN/ACCEPT the risk: If, after controls are put in place, the remaining risk is deemed acceptable to the organization, the risk can be retained. However, plans should be put in place to manage and fund the consequences of the risk should it occur.
• REDUCE THE PROBABILITY of the risk occurring (Mitigate):
This is done through preventative maintenance, audit and compliance programs, supervision, contract conditions, policies, procedures, testing, program management, portfolio management, training of staff, technical controls, and quality assurance programs etc.
• REDUCE THE IMPACT of the risk occurring: This is achieved through active and contingency planning, communication, contract conditions, public relations, emergency procedures, staff training etc.
• TRANSFER/SHARE the risk: This involves another party bearing or sharing some part of the risk using contracts, Memorandums Of Understanding, outsourcing, partnerships, etc.
• EXPLOIT the risk: This strategy involves taking steps to ensure an opportunity happens. For example, a project manager may want to assign the most talented resources to a project by reducing completion time and lowering costs from what was originally planned.
• AVOID the risk: This is a decision not to proceed with the activity likely to generate the risk and is used when practical.
4.3.2 Develop The Appropriate IT Response
Selecting the appropriate IT Risk response requires aligning the suitable risk treatment with options available. In some situations, a single treatment may work best, while for others, the ultimate strategy may be the product of two or more risk treatments. Judgment is required;
therefore, having a thorough understanding of the risk treatments as well as the IT Risk is necessary.
Once the response has been determined, it must be documented in the risk register. The response should be expressed in short statements describing the approach to managing the IT Risk and should include deliverables and milestones.
A contingency plan should be developed for negative IT Risks that cannot be mitigated, or which are too expensive to mitigate.
The ideal use of some response strategies may not be possible. Certain responses may involve trade-offs that are not acceptable to the organization or person making the risk management decisions. In those situations, compromises will need to be made, and IT Risks may need to be shared. When agreements cannot be reached, reporting, or escalating the risk to the next level of management is required.
4.4 Execute IT Risk Response
For each risk in the risk register, continually follow its IT Risk Response. Maintain the risk register to reflect the current state of the risk and progress on the response.
4.5 Risk Review
The risk register should be reviewed and updated periodically and as needed with appropriate stakeholders (e.g., Department Directors, CXOs, CIO, Program Managers, Project Managers, Risk Owners, Sponsors, etc.).
The IT Risk Management Process Owner will review them periodically for completeness, accuracy, and appropriateness and provide feedback to the risk manager. Continued risks of the same subject will be reported or escalated for resolution. Additionally, the IT Risk Management Process Owner will review risk registers to identify risk patterns, risk interdependencies, same risks across risk registers, and cumulative risks across risk registers and make recommendations to the CIO Leadership team on actions to take to manage the overall risk identified.
The IT Risk Management Process Owner will also report “High” risks to the Chief Information Officer monthly. In addition, the IT Risk Management Process Owner will report CIO Programs risks, having an IT Risk Rating of 13 – 25, to the PBGC RMO annually. OIT High Risk submitted to the PBGC RMO will be managed in a Centralized Risk Register maintained by the OIT Risk Management Council Representative.
4.6 Review And Re-Evaluate IT Risks And Responses
IT Risk Managers are required to regularly review the status of IT Risks and
• Determine if the risk response is working or if the IT Risk has been realized
• Ensure all actions defined by the risk response are performed timely, including but not limited to actions requiring review are actually reviewed and actions requiring approval are signed
• Determine if the risk response is sufficient or if it requires adjustments
As part of the review, the following questions should be asked with the appropriate actions:
https://pbgcgov.sharepoint.com/Sites/p-OMA/RMG/RiskRegister/Lists/Risk%20Register/OIT.aspx
4.6.1 Has The IT Risk Been Realized?
If the risk has been realized (actually happened), it should be noted and closed on the risk register. The risk is then tracked as an issue in an issue log and the reporting/escalation points notified.
4.6.2 Does The IT Risk Still Exist?
If the determination is that an IT Risk no longer exists (e.g., fully mitigated, does not exist anymore, etc.), the risk should be retired.
4.6.3 Is IT Risk Response Effective?
If the risk response is determined to be ineffective (either because the response was designed poorly or new information is available), a new risk response should be determined. (Refer to paragraph 4.3, “Identify and Document IT Risk Response”, for guidance).
Afterwards, the risk register should be updated to reflect all changes.
5. IT Risk Management Strategy and Process Maintenance
An effective IT Risk Management Strategy and Process requires ongoing maintenance to ensure it meets current requirements and guidelines, established federal statutes, regulations, other government mandates and PBGC policies as well as recommendations from the PBGC’s Office of Inspector General. It also requires ensuring that current industry best practices are used to meet the requirements set forth by the guidance.
As part of continuous process improvement and as the organizations mature, the IT Risk Management Process can be adjusted, improved, and matured by seeking input from the IT Risk Managers, government and industry best practices, audit findings, etc.
In addition, the effectiveness of the process and continuous evaluation could result in process adjustments.
To ensure that this process and procedures document is kept current, the IT Risk Management Process Owner will perform content reviews at least annually, and more frequently if necessary. Depending upon the results of the review, updates may be required along with implementation of the updated process. Implementation may involve a scheduled rollout, small group piloting, organizational change management and cultural acceptance.
Updates will be coordinated with the appropriate CIO Program Area (such as Security, Enterprise Architecture, IT Portfolio Management, etc.) or as identified by the Governance Coordination Board (GCB). Recommended updates will be presented to the OIT Leadership Team for review and approval only after coordination with the appropriate CIO Program Manager. OIT Leadership Team approved updates will go before the GCB for final approval. Afterwards, the updates will be incorporated in this guide, socialized with the impacted Program Managers, and implemented.
Appendix A – OMB Risk Categories
No. Name Description 1 Technology Risk(s) associated with technical functionality or IT tools.
2 Project Schedule and Resources
Risk(s) associated with the adequacy of the time estimated for completion of IT program milestones.
3 Business Risk(s) associated with acquisition planning and contract management.
Organizational and Change Management
Risk(s) associated with the organizational/Agency/Government-wide cultural resistance to change and standardization.
5 Strategic Risk(s) associated with the Investment's failure to achieve the Agency's strategic goals or to drive Agency priorities.
6 Security Risk(s) associated with threats to the confidentiality, integrity, or availability of Agency information.
7 Privacy Risk(s) to individuals associated with creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of Personally Identifiable Information (PII).
8 Data Risk(s) associated with the data or information collection burden and accuracy.
9 Integration Risk(s) associated with the integration of technology, people, and processes.
10 Project Team Risk(s) associated with the investment having a team of qualified professionals with the necessary skills and experience to execute upon the project's goals, budget, and timelines.
11 Requirements Risk(s) associated with the adequacy of requirements definition and agreement by relevant functional and technical subject matter experts.
12 Cost Risk(s) associated with inadequate cost estimates during planning or unanticipated overruns.
13 Project Management
Risk(s) associated with an investment having qualified management, strong leadership, and effective communication.
Climate Risks and Greenhouse Gas Emissions
The risks from observed and expected changes in climate, such as acute events (hurricanes, floods, wildfires) and gradual changes (sea level rise, aridification), and requirements for reductions in greenhouse gas emissions.
Appendix B – Acronyms
Acronym Description AO Authorizing Official BISD Business Innovation Services Department BPIT Budget Planning Integration Team CAP Corrective Action Plan CIO Chief Information Officer CISO Chief Information Security Officer CXO C-Level Executive Officer DME Development, Modernization and Enhancement EAD Enterprise Architecture Division ECD Enterprise Cybersecurity Department EMC Executive Management Committee ERM Enterprise Risk Management GCB Governance Control Board ICAP Individual Corrective Action Plan IT Information Technology ITIOD IT Infrastructure Operations Department ITPRB Information Technology Portfolio Review Board ITPD Information Technology Portfolio Division OIT Office of Information Technology OMB Office of Management and Budget PBGC Pension Benefit Guaranty Corporation PCD Policy and Compliance Division PGD Program Governance Division
PMI Project Management Institute PPL Process and Procedures Library PxI Probability and Impact RMC Risk Management Council RMF Risk Management Framework RMO Risk Management Officer
Approval
This document is considered approved according to the undersigned.
Velma Briscoe___________________________________________Date _______________ GCB Chair
Velma Briscoe 03/18/2025
| 1. Introduction |
| 2. IT Risk Management Framework |
| 2.1 Definitions |
| 2.1.1 IT Risk |
| 2.1.2 IT Risk Management |
| 2.1.3 IT Risk Register |
| 2.2 Consistent Approach to Determining Probability and Impact |
| 2.3 IT Risk Rating and Tolerance |
| 2.4 IT Risk Reporting |
| 3. Roles and Responsibilities |
| 4. The IT Risk Management Process |
| 4.1 Identify IT Risks |
| 4.2 Assess and Document IT Risks |
| 4.3 Identify and Document IT Risk Response |
| 4.3.1 Evaluate Potential IT Risk Treatment |
| 4.3.2 Develop The Appropriate IT Response |
| 4.4 Execute IT Risk Response |
| 4.5 Risk Review |
| 4.6 Review And Re-Evaluate IT Risks And Responses |
| 4.6.1 Has The IT Risk Been Realized? |
| 4.6.2 Does The IT Risk Still Exist? |
| 4.6.3 Is IT Risk Response Effective? |
| 5. IT Risk Management Strategy and Process Maintenance |
| Appendix A – OMB Risk Categories |
| Appendix B – Acronyms |
| Approval |
File details come from the government source that posted it. Updated .