888 resultados para Risk Management, Sicurezza informatica, Telecom Italia, telecomunicazioni, Multi-Project Management, Project Management Office, cyber security


100.00% 100.00%



Questo lavoro di tesi muove da tematiche relative alla sicurezza IT e risulta dagli otto mesi di lavoro all’interno della funzione Technical Security di Telecom Italia Information Technology. Il compito primario di questa unità di business è ridurre il rischio informatico dei sistemi di Telecom Italia per mezzo dell’attuazione del processo di ICT Risk Management, che coinvolge l’intera organizzazione ed è stato oggetto di una riprogettazione nel corso del 2012. Per estendere tale processo a tutti i sistemi informatici, nello specifico a quelli caratterizzati da non conformità, all’inizio del 2013 è stato avviato il Programma Strutturato di Sicurezza, un aggregato di quattro progetti dalla durata triennale particolarmente articolato e complesso. La pianificazione di tale Programma ha visto coinvolto, tra gli altri, il team di cui ho fatto parte, che ha collaborato con Telecom Italia assolvendo alcune delle funzioni di supporto tipiche dei Project Management Office (PMO).


100.00% 100.00%



Information security policy defines the governance and implementation strategy for information security in alignment with the corporate risk policy objectives and strategies. Research has established that alignment between corporate concerns may be enhanced when strategies are developed concurrently using the same development process as an integrative relationship is established. Utilizing the corporate risk management framework for security policy management establishes such an integrative relationship between information security and corporate risk management objectives and strategies. There is however limitation in the current literature on presenting a definitive approach that fully integrates security policy management with the corporate risk management framework. This paper presents an approach that adopts a conventional corporate risk management framework for security policy development and management to achieve alignment with the corporate risk policy. A case example is examined to illustrate the alignment achieved in each process step with a security policy structure being consequently derived in the process. It is shown that information security policy management outcomes become both integral drivers and major elements of the corporate-level risk management considerations. Further study should involve assessing the impact of the use of the proposed framework in enhancing alignment as perceived in this paper.


100.00% 100.00%



This paper presents a distributed multi-agent scheme for enhancing the cyber security of smart grids which integrates computational resources, physical processes, and communication capabilities. Smart grid infrastructures are vulnerable to various cyber attacks and noises whose influences are significant for reliable and secure operations. A distributed agent-based framework is developed to investigate the interactions between physical processes and cyber activities where the attacks are considered as additive sensor fault signals and noises as randomly generated disturbance signals. A model of innovative physical process-oriented counter-measure and abnormal angle-state observer is designed for detection and mitigation against integrity attacks. Furthermore, this model helps to identify if the observation errors are caused either by attacks or noises.


100.00% 100.00%



This paper presents a distributed multi-agent scheme for enhancing the cyber security of smart grids which integrates computational resources, physical processes, and communication capabilities. Smart grid infrastructures are vulnerable to various cyber attacks and noises whose influences are significant for reliable and secure operations. A distributed agent-based framework is developed to investigate the interactions between physical processes and cyber activities where the attacks are considered as additive sensor fault signals and noises as randomly generated disturbance signals. A model of innovative physical process-oriented counter-measure and abnormal angle-state observer is designed for detection and mitigation against integrity attacks. Furthermore, this model helps to identify if the observation errors are caused either by attacks or noises.


100.00% 100.00%



Several parties (stakeholders) are involved in a construction project. The conventional Risk Management Process (RMP) manages risks from a single party perspective, which does not give adequate consideration to the needs of others. The objective of multi-party risk management is to assist decision-makers in managing risk systematically and most efficiently in a multi-party environment. Multi-party Risk Management Processes (MRMP) consist of risk identification, structuring, analysis and developing responses from all party perspectives. The MRMP has been applied to a cement plant construction project in Thailand to demonstrate its effectiveness.


100.00% 100.00%



Purpose: The purpose of this paper is to analyse the risk management process conducted by some private and not-for-profit affordable housing providers in South East Queensland, and draw conclusions about the relationship between risk assessments/responses and past experiences.----- Design/methodology/approach: In-depth interviews of selected non-government housing providers have been conducted to facilitate an understanding of their approach to risk assessment in developing and in managing affordable housing projects. Qualitative data are analysed using thematic analysis to find emerging themes suggested by interview participants.----- Findings: The paper finds that informal risk management process is used as part of normal business process in accordance with industry standards. Many interviewees agree that the recognition of financial risk and the fear of community rejection of such housing projects have restrained them from committing to such investment projects. The levels of acceptance of risk are not always consistent across housing providers which create opportunities to conduct multi-stakeholder partnership to reduce overall risk.----- Research limitations/implications: The paper has implications for developers or investors who seek to include affordable housing as part of their portfolio. However, data collected in the study are a cross-section of interviews that will not include the impact on recent tax incentives offers by the Australian Commonwealth Government.----- Practical implications: The study suggests that implementing improvements to the risk mitigation and management framework may assist in promoting the supply of affordable housing by non-government providers.----- Originality/value: The focus of the study is the interaction between partnerships and risk management in development and management of affordable rental housing.


100.00% 100.00%



Jakarta, Indonesia’s chronic housing shortage poses multiple challenges for contemporary policy-makers. While it may be in the city’s interest to increase the availability of housing, there is limited land to do so. Market pressures, in tandem with government’s desire for housing availability, demand consideration of even marginal lands, such as those within floodplains, for development. Increasingly, planning for a flood resilient Jakarta is complicated by a number of factors, including: the city is highly urbanized and land use data is limited; flood management is technically complex, creating potential barriers to engagement for both decision-makers and the public; inherent uncertainty exists throughout modelling efforts, central to management; and risk and liability for infrastructure investments is unclear. These obstacles require localized watershed-level participatory planning to address risks of flooding where possible and reduce the likelihood that informal settlements occur in areas of extreme risk. This paper presents a preliminary scoping study for determination of an effective participatory planning method to encourage more resilient development. First, the scoping study provides background relevant to the challenges faced in planning for contemporary Jakarta. Second, the study examines the current use of decision-support tools, such as Geographic Information Systems (GIS), in planning for Jakarta. Existing capacity in the use of GIS allows for consideration of the use of an emerging method of community consultation - Multi-Criteria Decision-Making (MCDM) support systems infused with geospatial information - to aid in engagement with the public and improve decision-making outcomes. While these methods have been used in Australia to promote stakeholder engagement in urban intensification, the planned research will be an early introduction of the method to Indonesia. As a consequence of this intervention, it is expected that planning activities will result in a more resilient city, capable of engaging with disaster risk management in a more effective manner.


100.00% 100.00%



Major disasters, such as bushfires or floods, place significant stress on scarce public resources. Climate change is likely to exacerbate this stress. An integrated approach to disaster risk management (DRM) and climate change adaptation (CCA) could reduce the stress by encouraging the more efficient use of pooled resources and expertise. A comparative analysis of three extreme climate-related events that occurred in Australia between 2009 and 2011 indicated that a strategy to improve interagency communication and collaboration would be a key factor in this type of policy/planning integration. These findings are in accord with the concepts of Joined-up Government and Network Governance. Five key reforms are proposed: developing a shared policy vision; adopting multi-level planning; integrating legislation; networking organisations; and establishing cooperative funding. These reforms are examined with reference to the related research literature in order to identify potential problems associated with their implementation. The findings are relevant for public policy generally but are particularly useful for CCA and DRM.


100.00% 100.00%



The UK government introduced the Private Finance Initiative (PFI) and, latterly, the Local Improvement Finance Trust (LIFT) in an attempt to improve public service provision. As a variant of PFI, LIFT seeks to create a framework for the effective provision of primary care facilities. Like conventional PFI procurement, LIFT projects involve long-term contracts, complex multi-party interactions and thus create various risks to public sector clients. This paper investigates the advantages and disadvantages of LIFT with a focus on how this approach facilitates or impedes risk management from the public sector client perspective. Our paper concludes that LIFT has a potential for creating additional problems, including the further reduction of public sector control, conflicts of interest, the inappropriate use of enabling funds, and higher than market rental costs affecting the uptake of space in the buildings by local health care providers. However, there is also evidence that LIFT has facilitated new investment and that Primary Care Trusts (PCTs) have themselves started addressing some of the weaknesses of this procurement format through the bundling of projects and other forms of regional co-operation.


100.00% 100.00%



In a global business economy, firms have a broad range of corporate real estate needs. During the past decade, multiple strategies and tactics have emerged in the corporate real estate community for meeting those needs. We propose here a framework for analysing and prioritising the various types of risk inherent in corporate real estate decisions. From a business strategy perspective, corporate real estate must serve needs beyond the simple one of shelter for the workforce and production process. Certain uses are strategic in that they allow access to externalities, embody the business strategy, or provide entrée to new markets. Other uses may be tactical, in that they arise from business activities of relatively short duration or provide an opportunity to pre-empt competitors. Still other corporate real estate uses can be considered “core” to the existence of the business enterprise. These might be special use properties or may be generic buildings that have become embodiments of the organisation’s culture. We argue that a multi-dimensional matrix approach organised around three broad themes and nine sub-categories allow the decision-maker to organise and evaluate choices with an acceptable degree of rigor and thoroughness. The three broad themes are Use (divided into Core, Cyclical or Casual) – Asset Type (which can be Strategic, Specialty or Generic) and Market Environment (which ranges from Mature Domestic to Emerging Economy). Proper understanding of each of these groupings brings critical variables to the fore and allows for efficient resource allocation and enhanced risk management.


100.00% 100.00%



This paper examines the implications of using marketing margins in applied commodity price analysis. The marketing-margin concept has a long and distinguished history, but it has caused considerable controversy. This is particularly the case in the context of analyzing the distribution of research gains in multi-stage production systems. We derive optimal tax schemes for raising revenues to finance research and promotion in a downstream market, derive the rules for efficient allocation of the funds, and compare the rules with an without the marketing-margin assumption. Applying the methodology to quarterly time series on the Australian beef-cattle sector and, with several caveats, we conclude that, during the period 1978:2 - 1988:4, the Australian Meat and Livestock Corporation optimally allocated research resources.


100.00% 100.00%



This research investigates the factors that lead Latin American non-financial firms to manage risks using derivatives. The main focus is on currency risk management. With this purpose, this thesis is divided into an introduction and two main chapters, which have been written as stand-alone papers. The first paper describes the results of a survey on derivatives usage and risk management responded by the CFOs of 74 Brazilian non-financial firms listed at the São Paulo Stock Exchange (BOVESPA), and the main evidence found is: i) larger firms are more likely to use financial derivatives; ii) foreign exchange risk is the most managed with derivatives; iii) Brazilian managers are more concerned with legal and institutional aspects in using derivatives, such as the taxation and accounting treatment of these instruments, than with issues related to implementing and maintaining a risk management program using derivatives. The second paper studies the determinants of risk management with derivatives in four Latin American countries (Argentina, Brazil, Chile and Mexico). I investigate not only the decision of whether to use financial derivatives or not, but also the magnitude of risk management, measured by the notional value of outstanding derivatives contracts. This is the first study, to the best of my knowledge, to use derivatives holdings information in emerging markets. The use of a multi-country setting allows the analysis of institutional and economic factors, such as foreign currency indebtedness, the high volatility of exchange rates, the instability of political and institutional framework and the development of financial markets, which are issues of second-order importance in developed markets. The main contribution of the second paper is on the understanding of the relationship among currency derivatives usage, foreign debt and the sensitivity of operational earnings to currency fluctuations in Latin American countries. Unlikely previous findings for US firms, my evidence shows that derivatives held by Latin American firms are capable of producing cash flows comparable to financial expenses and investments, showing that derivatives are key instruments in their risk management strategies. It is also the first work to show strong and robust evidence that firms that benefit from local currency devaluation (e.g. exporters) have a natural currency hedge for foreign debt that allows them to bear higher levels of debt in foreign currency. This implies that firms under this revenue-cost structure require lower levels of hedging with derivatives. The findings also provide evidence that large firms are more likely to use derivatives, but the magnitude of derivatives holdings seems to be unrelated to the size of the firm, consistent with findings for US firms.


100.00% 100.00%



The purpose of this study is to understand how different members manage risk in the global supply chain. Through a multi-case study of the Brazilian mango exportation chain to the United States, four actors of this chain were investigated: supplier, exporter, importer and logistics operator. A research protocol was developed based on previous research conducted by Christopher, et al. (2011). Main results show that risk management is heterogeneous among members of the mango chain, the exporter is the most penalized by the results of the risk chain and collaboration is the main mitigation strategy observed