ITIL Risk Management

In both the construction of sound business caseIn order to be able to control and contain risk it is
proposals and other areas of service managementnecessary to fully understand it. Risk Analysis is
risk will need to be managed. Risk may be defined asconcerned with gathering information about exposure
follows:to risk so that the organisation can make decisions
"Risk is the uncertainty of outcome, whether positiveand manage risk appropriately.
opportunity or negative threat "Each risk needs to be identified. It should have an
Risk is usually posed as something to be avoidedowner who is responsible for the management of
because it represents danger. While this is true fewthat risk. Each risk needs to be evaluated and
opportunities exist which are truly devoid of risk.dependent on the likely outcome and the
Failure to take the opportunity may in itself presentconsequential damage each risk should have agreed
risks. Decisions about risk need to be managed sotolerance levels set. If that level is breached then
that the potential benefits are worth more to theactions need to be taken.
organisation than it costs to address the risks.