Critical Incident Management

 < Day Day Up > 


Using questionnaires is one of the most effective and efficient means to collect information from a wide variety of persons. The ideal situation is one in which the interviewer conducts the interview in person, thereby answering qualifying questions from the interviewee. Work from an organizational chart, workflow chart, and the knowledge of the risk team members are the best methods to determine the appropriate persons to be interviewed.

In the case of critical employees, team members will want to conduct those interviews personally. Personal interviews should be brief and to the point, lasting no more than 30 minutes. Interviewers should take quick notes and complete their documentation after the interview has been completed. Interviews should logically begin with a brief review of the control standard outlining the official policy. Validating that the interview subject is in compliance with those policies can be attempted here, but compliance should really be left to the auditors as it may adversely affect the interview's results. Notes taken during the interview are merely reminders of the content of the interview and are not intended to be a verbatim transcript. Keep a copy of the notes, along with all the completed questionnaires as part of the team's work papers. These documents may be important if the enterprise is targeted for an audit or legal action. Having relevant documentation is the mark of professional due diligence and can prove that a required task was completed.

There are automated questionnaires and programs that facilitate the risk analysis process. They are commercially available and can be used in place of the customized questionnaires (see Exhibit 4 for a sample).

Exhibit 4: Sample Questionnaire

Background

Operational Impact

Financial Impact

Critical Assets

Threat Identification

Vulnerabilities (Weaknesses)

Safeguards

Other

A well-written questionnaire will generally provide the structure needed by the team to document the needed information. At first, it is important that the questionnaire is the same for all recipients, as this will greatly help in evaluating and comparing the responses. Team members should formulate their questions based on the organization's documentation and their knowledge and experience. Questions should address those items that will progress toward identifying critical assets, threats and their frequency, vulnerabilities, and safeguards. Be sure to track the completed questionnaire responses, as that will assure the various business divisions and units are adequately represented in the survey.


 < Day Day Up > 

Категории