John Pentanol was appointed as risk manager at HZ Company a year ago and he decided that his first task was to examine the risks that faced the company. He concluded that the company faced three major risks, which he assessed by examining the impact that would occur if the risk were to materialise. He assessed Risk 1 as being of low potential impact as even if it materialised it would have little effect on the company’s strategy. Risk 2 was assessed as being of medium potential impact whilst a third risk, Risk 3, was assessed as being of very high potential impact.When John realised the potential impact of Risk 3 materialising, he issued urgent advice to the board to withdraw from the activity that gave rise to Risk 3 being incurred. In the advice he said that the impact of Risk 3 was potentially enormous and it would be irresponsible for HZ to continue to bear that risk.The company commercial director, Jane Xylene, said that John Pentanol and his job at HZ were unnecessary and that risk management was ‘very expensive for the benefits achieved’. She said that all risk managers do is to tell people what can’t be done and that they are pessimists by nature. She said she wanted to see entrepreneurial risk takers in HZ and not risk managers who, she believed, tended to discourage enterprise.John replied that it was his job to eliminate all of the highest risks at HZ Company. He said that all risk was bad and needed to be eliminated if possible. If it couldn’t be eliminated, he said that it should be minimised.(a) The risk manager has an important role to play in an organisation’s risk management.Required:(i) Describe the roles of a risk manager. (4 marks)(ii) Assess John Pentanol’s understanding of his role. (4 marks)(b) With reference to a risk assessment framework as appropriate, criticise John’s advice that HZ shouldwithdraw from the activity that incurs Risk 3. (6 marks)(c) Jane Xylene expressed a particular view about the value of risk management in HZ Company. She also said that she wanted to see ‘entrepreneurial risk takers’.Required:(i) Define ‘entrepreneurial risk’ and explain why it is important to accept entrepreneurial risk in businessorganisations; (4 marks)(ii) Critically evaluate Jane Xylene’s view of risk management. (7 marks)

不可分散的风险(Nondiversifiable risk)

风险厌恶者(Risk averter)

风险中性(Risk neutral)

-So could you make an exception and accept D/P? -__________________________ A I shall tell you frankly it would drastically increase our risk. ;B Thanks, we are inclined to accept your price. ;C We have already tried our best.

下列叙述正确的是( )。A.INPUT语句只能接受字符串B.ACCEPT命令只能接受字符串C.ACCEPT语句可以接受任意类型的VFP表达式D.WAIT只能接受一个字符,而必须按〈Enter〉键

下列叙述中,正确的是A.INPUT命令只能接受字符串B.ACCEPT命令只能接受字符串C.ACCEPT命令可以接收任意类型的Visual FoxPro表达式D.WAIT只能接收一个字符,且必须按Enter键

风险的优先级通常是根据( )设定。A.风险影响(Risk Impact)B.风险概率(Risk Probability)C.风险暴露(Risk Exposure)D.风险控制(Risk Control)

收到;接受;选择(  )。A.receive;accept;choiceB.receive;choice;acceptC.accept:receive;choiceD.accept;choice;receive

A deviation from an organization-wide security policy requires which of the following?从组织范围的安全策略偏离需要下列哪项?()A、Risk Reduction降低风险B、Risk Containment风险控制C、Risk acceptance风险接受D、Risk Assignment风险分配

对risk matrix理解正确的是?()A、风险级别表B、风险登记表C、风险矩阵图D、风险分析报告





有害生物风险分析(Pest Risk Analysis,PRA)

风险评估(Risk assessment)包括哪几个过程?()A、风险识别B、风险分析C、人群脆弱性分析D、风险评价E、风险沟通

对于信息安全风险的描述不正确的是()。A、企业信息安全风险管理就是要做到零风险B、在信息安全领域,风险(Risk)就是指信息资产遭受损坏并给企业带来负面影响及其潜在可能性C、风险管理(Risk Management)就是以可接受的代价,识别控制减少或消除可能影响信息系统的安全风险的过程D、风险评估(Risk Assessment)就是对信息和信息处理设施面临的威胁、受到的影响、存在的弱点以及威胁发生的可能性的评估


名词解释题可接受的危险度(acceptable risk)

名词解释题接受风险(Accept Risk)

名词解释题有害生物风险分析(Pest Risk Analysis,PRA)



名词解释题风险爱好者(Risk lover)

名词解释题不可分散的风险(Nondiversifiable risk)

单选题对risk matrix理解正确的是?()A风险级别表B风险登记表C风险矩阵图D风险分析报告