vulnerability assessment & analysis (vaa) overview

33
VULNERABILITY ASSESSMENT AND ANALYSIS (VAA)

Upload: susan-rantall

Post on 14-Jun-2015

627 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Vulnerability Assessment & Analysis (VAA) Overview

VULNERABILITY ASSESSMENT AND ANALYSIS (VAA)

Page 2: Vulnerability Assessment & Analysis (VAA) Overview

What is VAA?

Decision support methodology to help identify and prioritize defects for elimination.

What is VAA?

Page 3: Vulnerability Assessment & Analysis (VAA) Overview

Identifies critical equipment and/or systems

What is VAA?

Page 4: Vulnerability Assessment & Analysis (VAA) Overview

Identifies key vulnerabilities to deliver safe and reliability operations

What is VAA?

Page 5: Vulnerability Assessment & Analysis (VAA) Overview

Establishes a prioritized defect list for subsequent functional review and remediation

What is VAA?

Page 6: Vulnerability Assessment & Analysis (VAA) Overview

How does VAA work?

Based on a Hazop style brainstorming approach

Page 7: Vulnerability Assessment & Analysis (VAA) Overview

How does VAA work?

Involves small groups of engineering and operating staff, plus individual interviews

Page 8: Vulnerability Assessment & Analysis (VAA) Overview

How does VAA work?

Produces a substantial amount of information

Page 9: Vulnerability Assessment & Analysis (VAA) Overview

What’s the purpose of VAA?

To analyze, categorize, and prioritize vulnerabilities

Page 10: Vulnerability Assessment & Analysis (VAA) Overview

And then what happens?

More detailed information is obtained in subsequent studies

FMEAFault Trees

SIL

Level of Protection Analysis

Page 11: Vulnerability Assessment & Analysis (VAA) Overview

Why?

To validate the risk issues raised in the qualitative Hazop review

Page 12: Vulnerability Assessment & Analysis (VAA) Overview

An over-arching methodology

VAA can be used on any process during any phase

Page 13: Vulnerability Assessment & Analysis (VAA) Overview

An integrated approach

When vulnerabilities are discovered that are not immediately manageable

…the action items flow into the appropriate secondary methodology

Page 14: Vulnerability Assessment & Analysis (VAA) Overview

Classical Hazop methodology

Team of senior representative

s e.g. design,

project, operating staff

Understanding of the process under study, condition of equipment &

consequences of failure

VAA is a blend

Page 15: Vulnerability Assessment & Analysis (VAA) Overview

Typical output

Page 16: Vulnerability Assessment & Analysis (VAA) Overview

Methodology

1) Pre-Assessment

2) Facilitated Assessment & Analysis

3) Post Assessment Phase

Page 17: Vulnerability Assessment & Analysis (VAA) Overview

Pre-Assessment

- Identifying the VAA objectives-Determining measures of success- Finalizing what elements of the

methodology will be included- Ensuring access to information-Developing an assessment schedule

Page 18: Vulnerability Assessment & Analysis (VAA) Overview

Pre-Assessment

Objectives and measures of success must be tailored to the organization and its needs

Page 19: Vulnerability Assessment & Analysis (VAA) Overview

Possible objectives could include:

- Identify all critical vulnerabilities- Identify and rank all key assets based

on a common “vulnerability maturity matrix”

- Develop the business case for making vulnerability reduction investments

- Enhance awareness / make VAA an integral part of business strategy

Page 20: Vulnerability Assessment & Analysis (VAA) Overview

Facilitated Assessment and Analysis

Page 21: Vulnerability Assessment & Analysis (VAA) Overview

VAA Facilitation Workflow

Page 22: Vulnerability Assessment & Analysis (VAA) Overview

Facilitated Assessment and Analysis

VAA starts with the fullest description of the system / process and then questions every part of it

Page 23: Vulnerability Assessment & Analysis (VAA) Overview

Post Assessment

- Ranking vulnerabilities by risk category- Prioritizing assessment

recommendations- Developing an action plan- Capturing lessons learned and best

practices- Conducting periodic assessments to

report progress

Page 24: Vulnerability Assessment & Analysis (VAA) Overview

Post Assessment

Risk mitigation activities that are low cost or result in cost savings should get special attention

Page 25: Vulnerability Assessment & Analysis (VAA) Overview

Post Assessment

Other vulnerabilities might require further assessment using quantitative methods in order to identify appropriate risk reduction actions

Page 26: Vulnerability Assessment & Analysis (VAA) Overview

Deliverables

The VAA process delivers a comprehensive report documenting the study, resulting assessment and identified actions

Page 27: Vulnerability Assessment & Analysis (VAA) Overview

Deliverables

A typical report may include:- Visual representation of

vulnerabilities and criticalities- Identification of vulnerabilities by

system or area- Vulnerability by category- Prioritized action list- Action by type

Page 28: Vulnerability Assessment & Analysis (VAA) Overview
Page 29: Vulnerability Assessment & Analysis (VAA) Overview
Page 30: Vulnerability Assessment & Analysis (VAA) Overview
Page 31: Vulnerability Assessment & Analysis (VAA) Overview

Summary

VAA is an over-arching methodology designed to expose and discover vulnerabilities across a wide segment of possible impacts

Page 32: Vulnerability Assessment & Analysis (VAA) Overview

Summary

FMEA, Risk Assessment, and RCM have a purpose

But that purpose is best served after the VAA

When VAA comes 1st it delivers focus more broadly on consequences from all parts of the system or process

Page 33: Vulnerability Assessment & Analysis (VAA) Overview

About ARMS Reliability

Since 1995, ARMS Reliability has been at the forefront of proactive asset management strategies for a range of blue chip companies throughout the world

Through a unique blend of consulting, education and software solutions, we enable our clients to make better decisions to improve asset reliability.

www.armsreliability.com