RAR P2: Treatment and Control for ALPS Healthcare
Introduction
The evaluation of risk treatments and controls is the second stage of the Risk Analysis and Review process.
It builds upon the Threat Register developed in RAR Part 1 by examining how ALPS Healthcare may currently manage, reduce, share, avoid, or formally retain the exposures associated with each identified threat.
While the Threat Register identifies potential sources of disruption, this chapter considers the organisational arrangements that should prevent those threats from occurring, reduce their consequences, support recovery, or transfer part of the resulting financial or service-delivery exposure.
A threat, risk treatment, and control are related but distinct concepts. A threat is a potential source of disruption, such as a flood, a supplier failure, a pandemic, or a ransomware attack.
A risk treatment is the overall management approach selected to address the resulting exposure.
The principal treatment approaches are risk avoidance, risk reduction, risk transference, and risk acceptance. A control is a specific policy, procedure, system, safeguard, contractual arrangement, or operational capability used to implement the selected treatment.
More than one treatment approach may be applied to the same threat. For example, ALPS Healthcare may reduce the consequences of a fire through detection, suppression, evacuation, alternate workplace, and data-recovery controls, while transferring part of the financial exposure through insurance.
Residual exposure may remain after these measures are applied, but any decision to accept that exposure should be informed, documented, approved by the appropriate authority, monitored, and reviewed when operating conditions change.
The presence of a control does not automatically demonstrate that a risk is adequately managed. Its design, ownership, implementation status, reliability, coverage, testing frequency, and actual effectiveness must also be assessed.
Controls that exist only on paper, depend on unavailable personnel, have not been tested, or contain single points of failure may provide limited protection during an actual disruption.
Consequently, assumed existing controls in this assessment require validation against ALPS Healthcare’s current policies, operating procedures, contracts, technical configurations, exercise reports, audit results, and incident records.
Control gaps should be converted into specific improvement actions with accountable owners, implementation deadlines, testing requirements, and evidence of completion.
This treatment-and-control analysis supports Business Continuity Strategy development, Crisis Management, IT Disaster Recovery, Third-Party Risk Management, and Operational Resilience by identifying where additional protection, redundancy, preparedness, and recovery capabilities may be required.
Assumptions
The following assessment uses every specific threat approved in RAR Part 1. No threat has been intentionally omitted or combined.
As detailed evidence of ALPS Healthcare’s current control environment was not provided:
- Existing controls are described as assumed controls requiring validation.
- Risk transference arrangements such as insurance, service-level agreements, indemnities, and managed recovery services are recorded as not evidenced unless they would normally be expected.
- Risk acceptance is not presumed. Any residual exposure that requires acceptance must be submitted through ALPS Healthcare’s approved governance and risk acceptance process.
- Planned controls identify recommended improvements and do not imply that current controls are ineffective until validated.
Table RAR P2: Treatment and Control for ALPS Healthcare
|
Threat |
Existing Risk Treatment – Risk Avoidance |
Existing Risk Treatment – Risk Reduction |
Existing Risk Treatment – Risk Transference |
Existing Risk Treatment – Risk Acceptance |
Existing Controls |
Additional Planned Controls |
|
Flood (Denial of Access – Natural Disaster) |
Partially Applicable – critical facilities may be selected outside known flood-prone locations, subject to validation. |
Assumed partially implemented through drainage maintenance, facility emergency procedures, remote working, alternate workplace arrangements, and protection of critical equipment above floor level. |
Property and business interruption insurance may share financial consequences; coverage requires validation. |
Not evidenced. Residual exposure should be accepted only by senior management after facility and recovery controls are validated. |
Assumed controls requiring validation: flood alerts; building emergency procedures; drainage inspection; protected server and electrical rooms; remote-access capability; alternate workplace; critical inventory protection. |
Facilities to complete site-specific flood assessments within 12 months; identify water-entry points; install barriers or sensors where justified; test remote-working activation annually; record evidence through inspection and exercise reports. |
|
Flash Flood (Denial of Access – Natural Disaster) |
Not Applicable – sudden localised flooding cannot be fully avoided; access and continuity measures are required. |
Assumed use of weather monitoring, travel advisories, flexible working, alternate routes, remote access, and delayed-shift arrangements. |
Transport and property insurance may provide limited financial transfer; not evidenced. |
Temporary disruption may be accepted within approved tolerance if remote operations remain available; approval and monitoring are required. |
Assumed controls: national weather alerts; staff notification channels; remote-working procedures; alternate site access; logistics escalation arrangements. |
Operations and Facilities to map access routes to critical sites, establish transport alternatives, define trigger points for remote working, and conduct an annual severe-weather accessibility exercise. |
|
Severe Storm (Denial of Access – Natural Disaster) |
Not Applicable – severe weather cannot be eliminated. |
Assumed reduction through weather monitoring, building maintenance, protected equipment, flexible staffing, remote working, and suspension of unsafe outdoor activities. |
Property, equipment, and business interruption insurance may apply; terms require validation. |
Acceptance may be appropriate for short residual interruptions within approved tolerance, subject to management approval. |
Assumed controls: weather alerts; roof and drainage inspection; emergency communications; UPS protection; remote work; supplier and logistics notification procedures. |
Facilities to review storm resilience annually; ICT to verify power and telecommunications redundancy; Procurement to test supplier communication during a simulated severe-weather event. |
|
Lightning (Denial of Access – Natural Disaster) |
Not Applicable – exposure cannot be completely avoided. |
Assumed lightning protection, surge protection, grounding, UPS systems, equipment shutdown procedures, and data backups. |
Equipment warranties and property insurance may transfer limited financial consequences; not evidenced. |
Residual exposure should be accepted only after electrical protection and recovery capability are tested. |
Assumed controls: building lightning conductors; surge suppressors; UPS units; backup generators; equipment maintenance; backup and recovery procedures. |
Facilities and ICT to commission periodic lightning and surge-protection testing, maintain inspection certificates, and validate recovery from a simulated power surge. |
|
Earthquake—Regional (Denial of Access – Natural Disaster) |
Not Applicable – regional seismic events cannot be avoided by ALPS. |
Reduction depends on geographically diversified suppliers, alternate transport routes, inventory buffers, supplier monitoring, and contingency sourcing. |
Marine cargo insurance, supplier contracts, and logistics agreements may transfer part of the loss; validation required. |
Acceptance may apply to low direct local exposure, but regional supply-chain consequences require active monitoring. |
Assumed controls: alternate suppliers; safety stock; supplier risk reviews; emergency sourcing; logistics escalation; crisis monitoring. |
Procurement to identify suppliers and logistics hubs concentrated in seismically exposed areas, establish alternatives for essential products, and conduct a regional supply interruption exercise within 12 months. |
|
Haze (Denial of Access – Natural Disaster) |
Partially Applicable – non-essential outdoor activity may be suspended when air quality reaches defined thresholds. |
Assumed air-quality monitoring, remote working, PPE availability, indoor filtration, workforce health guidance, and adjusted logistics operations. |
Not Applicable in most cases; insurance coverage is generally limited. |
Residual short-term effects may be accepted within approved health and operational thresholds. |
Assumed controls: air-quality alerts; health advisories; masks; remote work; indoor air-conditioning and filtration; escalation procedures. |
Human Resources and Facilities to define air-quality activation thresholds, maintain suitable respiratory protection, assess filtration capability, and test remote-work readiness before seasonal haze periods. |
|
Extreme Heat (Denial of Access – Natural Disaster) |
Partially Applicable – high-risk outdoor work may be rescheduled or prohibited during hazardous conditions. |
Assumed hydration, rest cycles, heat monitoring, ventilation, temperature alarms, cold-chain monitoring, and adjusted work schedules. |
Workers’ compensation and equipment insurance may transfer limited consequences; not evidenced. |
Acceptance may apply only within approved workplace safety and product integrity limits. |
Assumed controls: workplace heat guidance; temperature monitoring; cold-room alarms; equipment maintenance; staff rotation; incident escalation. |
Facilities and Operations to conduct heat-stress assessments, define work-rest regimes, install additional monitoring where required, and test cold-chain contingency arrangements annually. |
|
Pandemic-related Movement Restrictions (Denial of Access – Natural Disaster) |
Partially Applicable – non-essential travel and on-site activities may be suspended. |
Assumed remote-working capability, split teams, essential-worker arrangements, cross-training, alternate approvals, digital workflows, and workforce health protocols. |
Outsourced services and reciprocal staffing may share limited operational exposure; not evidenced. |
Temporary service reduction may require approval from the Crisis Management Team and daily monitoring. |
Assumed controls: pandemic plan; remote access; secure collaboration; delegated authorities; staff communications; supplier coordination; essential service prioritisation. |
BCM and HR to maintain scalable remote-work capacity, identify essential on-site roles, conduct annual pandemic exercises, and retain documented evidence of remote-access and workforce-availability tests. |
|
Fire (Denial of Access – Man-made Disaster) |
Partially Applicable – hazardous storage and ignition sources may be removed or prohibited. |
Assumed detection and suppression systems, evacuation procedures, fire compartmentation, maintenance, training, alternate workplace, backups, and emergency response. |
Property, equipment, and business interruption insurance may transfer financial loss; coverage requires validation. |
Significant uncontrolled fire exposure is not appropriate for acceptance. Residual exposure requires executive approval after control assurance. |
Assumed controls: alarms; sprinklers; extinguishers; emergency lighting; evacuation wardens; drills; electrical inspection; protected records; alternate workplace and IT recovery. |
Facilities to complete annual fire-control assurance, address inspection findings, conduct evacuation exercises at all critical sites, and verify recovery of essential functions following denial of access. |
|
Explosion (Denial of Access – Man-made Disaster) |
Partially Applicable – hazardous processes and materials may be restricted or removed from occupied premises. |
Assumed gas and electrical inspections, controlled storage, evacuation arrangements, access control, emergency coordination, and alternate workplace capability. |
Insurance and contractor indemnities may transfer part of the exposure; not evidenced. |
Major explosion exposure is not suitable for acceptance without strong life-safety and recovery controls. |
Assumed controls: building safety compliance; hazardous-material controls; evacuation plan; emergency services liaison; business continuity arrangements. |
Facilities to assess nearby explosion sources, confirm hazardous-material controls, include explosion scenarios in site risk assessments, and exercise relocation of critical teams. |
|
Chemical Spill (Denial of Access – Man-made Disaster) |
Partially Applicable – hazardous substances may be substituted, minimised, or excluded where possible. |
Assumed chemical handling procedures, segregation, spill kits, PPE, ventilation, emergency response, evacuation, and specialist cleanup arrangements. |
Environmental liability insurance and specialist contractor arrangements may share consequences; not evidenced. |
Residual risk may be accepted only within workplace-safety and environmental limits approved by management. |
Assumed controls: safety data sheets; trained handlers; spill kits; storage cabinets; emergency contacts; evacuation; incident reporting. |
Facilities and Safety to maintain a chemical inventory, verify spill-response competence, inspect storage quarterly, and conduct a spill-response drill with documented corrective actions. |
|
Gas Leak (Denial of Access – Man-made Disaster) |
Partially Applicable – unnecessary gas installations may be removed or isolated. |
Assumed detection, preventive maintenance, isolation valves, evacuation procedures, ventilation, contractor support, and emergency notification. |
Maintenance warranties and property insurance may share limited loss; not evidenced. |
Not appropriate for passive acceptance where personnel safety could be affected. |
Assumed controls: gas detectors; maintenance; emergency shutdown; evacuation; building management escalation; alternate workplace. |
Facilities to validate detector coverage, maintain calibration records, define isolation responsibilities, and test evacuation and alternate-site activation. |
|
Structural Failure (Denial of Access – Man-made Disaster) |
Applicable where unsafe premises are closed, repaired, or no longer used. |
Assumed statutory inspections, preventive maintenance, defect reporting, load controls, access restriction, and alternate workplace arrangements. |
Property insurance, landlord obligations, and contractor warranties may transfer portions of the exposure; not evidenced. |
Continued occupancy of a known unsafe structure is not acceptable. |
Assumed controls: building inspections; maintenance records; defect escalation; landlord coordination; evacuation; alternate work location. |
Facilities to maintain a structural inspection register, track remediation deadlines, confirm landlord responsibilities, and prohibit occupancy where safety certification is unavailable. |
|
Bomb Threat (Denial of Access – Man-made Disaster) |
Not Applicable – the threat cannot be fully avoided. |
Assumed security screening, suspicious-item reporting, call-handling procedures, evacuation, police liaison, access control, and alternate workplace activation. |
Not Applicable except limited insurance consequences. |
Residual exposure requires security oversight and periodic review; passive acceptance is inappropriate. |
Assumed controls: security procedures; emergency contacts; evacuation routes; access logs; staff awareness; crisis communication. |
Security to standardise bomb-threat checklists, train reception and contact-centre staff, conduct annual exercises, and verify emergency communications and accountability procedures. |
|
Terrorism (Denial of Access – Man-made Disaster) |
Partially Applicable – avoid locating critical operations adjacent to known high-risk sites where practicable. |
Assumed access control, security monitoring, national alert monitoring, emergency response, lockdown or evacuation, alternate operations, and crisis communication. |
Terrorism insurance may transfer limited financial loss; not evidenced. |
Residual exposure may be accepted only through enterprise risk governance with regular threat review. |
Assumed controls: guards; CCTV; access cards; visitor management; emergency procedures; inter-agency coordination; BCM and crisis plans. |
Security and BCM to conduct site-specific hostile-threat assessments, establish shelter and evacuation criteria, exercise crisis decision-making, and test alternative operating arrangements. |
|
Active Assailant (Denial of Access – Man-made Disaster) |
Not Applicable – the threat cannot be completely avoided. |
Assumed physical security, access restrictions, staff reporting, lockdown and evacuation guidance, emergency communication, police notification, and trauma support. |
Not Applicable beyond limited insurance and employee-support services. |
Not appropriate for acceptance without validated life-safety controls. |
Assumed controls: controlled access; CCTV; security personnel; emergency alarms; incident escalation; staff guidance; post-incident support. |
Security and HR to issue specific active-assailant guidance, train staff in reporting and protective actions, conduct scenario exercises, and maintain post-incident psychological-support arrangements. |
|
Public Transport Disruption (Denial of Access – Man-made Disaster) |
Not Applicable – ALPS cannot eliminate national transport disruption. |
Assumed flexible start times, remote working, staggered teams, alternate routes, taxi or shuttle arrangements for essential personnel, and cross-training. |
Reciprocal transport support or contracted transport may share limited exposure; not evidenced. |
Temporary delays may be accepted within approved service tolerances if minimum staffing remains available. |
Assumed controls: remote access; staff notification; alternate travel guidance; essential-role identification; workload prioritisation. |
HR and Operations to identify roles requiring physical attendance, define transport support for essential staff, and test minimum staffing under a major transport disruption. |
|
Major Traffic Incident (Denial of Access – Man-made Disaster) |
Not Applicable – external road incidents cannot be avoided. |
Assumed route monitoring, alternate delivery routes, dispatch coordination, emergency carrier escalation, and delivery prioritisation. |
Logistics contracts and cargo insurance may transfer part of the consequence; validation required. |
Short delays may be accepted within approved delivery tolerances; critical healthcare deliveries require escalation. |
Assumed controls: route planning; delivery tracking; carrier communication; alternate routes; priority delivery procedures. |
Logistics and Procurement to maintain alternate-route plans, define escalation thresholds for critical consignments, and require carriers to demonstrate road-disruption continuity arrangements. |
|
Pandemic (Unavailability of People) |
Not Applicable – widespread disease cannot be fully avoided. |
Assumed infection-control measures, remote working, split teams, cross-training, workforce monitoring, essential-role prioritisation, and supplier coordination. |
Outsourced support and temporary staffing may share limited operational exposure; not evidenced. |
Service degradation may be accepted only with Crisis Management Team approval, subject to defined minimum service levels and daily review. |
Assumed controls: pandemic plan; health advisories; remote access; staff segregation; succession; sick-leave monitoring; communications; continuity procedures. |
BCM and HR to update pandemic assumptions annually, test prolonged staff absenteeism, maintain cross-trained reserves, and define trigger-based service prioritisation. |
|
Infectious Disease Outbreak (Unavailability of People) |
Partially Applicable – affected work areas or non-essential activities may be closed temporarily. |
Assumed hygiene controls, contact management, remote work, cleaning, staff communications, isolation arrangements, and health authority guidance. |
Specialist cleaning and occupational health services may share response obligations; not evidenced. |
Residual localised exposure may be accepted within public-health guidance and approved operating limits. |
Assumed controls: health reporting; cleaning protocols; remote work; workplace distancing; staff awareness; incident escalation. |
HR and Facilities to develop site-specific outbreak procedures, maintain cleaning contracts, define closure and reopening criteria, and exercise outbreak response. |
|
Mass Illness (Unavailability of People) |
Not Applicable – simultaneous illness cannot be fully avoided. |
Assumed cross-training, succession, workload prioritisation, temporary staffing, remote work, and minimum staffing plans. |
Temporary staffing contracts or shared-service support may transfer some operational capacity; not evidenced. |
A temporary reduction in non-essential services may be approved by the relevant executive in accordance with MBCO requirements. |
Assumed controls: minimum staffing lists; deputies; cross-training; remote access; staff welfare support; escalation procedures. |
HR and business units to document minimum staffing by function, maintain a skills matrix, establish backup rosters, and test operations with significant absenteeism. |
|
High Staff Turnover (Unavailability of People) |
Partially Applicable – avoid excessive dependency on scarce or unsupported roles through workforce redesign. |
Assumed succession planning, knowledge management, competitive recruitment, staff engagement, cross-training, and documented procedures. |
Recruitment agencies or managed services may transfer limited resourcing pressure; not evidenced. |
Residual turnover may be accepted within workforce thresholds approved by senior management and monitored quarterly. |
Assumed controls: workforce planning; exit handover; procedure documentation; training; role backups; retention monitoring. |
HR and management to identify critical-role turnover thresholds, implement mandatory handover requirements, maintain talent pipelines, and report key-role vacancies to the risk committee. |
|
Loss of Key Personnel (Unavailability of People) |
Partially Applicable – eliminate single-person dependencies through role redesign and delegated authorities. |
Assumed succession, deputies, cross-training, documented procedures, shared access to records, and emergency delegation. |
Key-person insurance or external professional support may transfer limited consequences; not evidenced. |
Acceptance is appropriate only where a documented deputy and recovery arrangement exist; executive approval required. |
Assumed controls: succession plans; delegated authority matrix; cross-training; knowledge repository; role handover; emergency contact list. |
Business units to identify all key-person dependencies, nominate trained alternates, conduct annual role-recovery tests, and retain evidence that delegated authorities function during absence. |
|
Skills Shortage (Unavailability of People) |
Partially Applicable – avoid unsupported technologies and overly specialised processes where practical. |
Assumed training, workforce planning, cross-skilling, documentation, recruitment pipelines, and vendor support. |
Outsourcing or specialist service agreements may share delivery exposure; not evidenced. |
Temporary acceptance may be approved while recruitment or training is underway, with defined expiry and monitoring. |
Assumed controls: competency framework; training plans; vendor support; role backups; succession and recruitment processes. |
HR and functional leaders to maintain a critical-skills register, quantify coverage gaps, establish training deadlines, and report unresolved gaps through enterprise risk governance. |
|
Workplace Violence (Unavailability of People) |
Partially Applicable – identified high-risk behaviour or unsafe situations may be excluded from the workplace through lawful HR and security action. |
Assumed workplace conduct policies, reporting channels, access control, security response, conflict management, and employee assistance. |
Insurance and specialist security or counselling services may share limited consequences; not evidenced. |
Not appropriate for acceptance where credible threats to safety remain unresolved. |
Assumed controls: code of conduct; grievance process; security escalation; visitor control; emergency response; employee assistance. |
HR and Security to establish a formal threat-assessment process, train managers in warning signs, document escalation criteria, and exercise response to a violent-person scenario. |
|
Staff Fatigue (Unavailability of People) |
Partially Applicable – prohibit excessive hours and unsafe shift patterns. |
Assumed shift controls, workload rotation, mandatory rest, backup staffing, welfare monitoring, and supervisor oversight. |
Temporary staffing may share prolonged workload; not evidenced. |
Short-term residual fatigue may be accepted only within approved work-hour and safety limits. |
Assumed controls: rostering; rest periods; overtime approval; welfare checks; cross-training; escalation of capacity constraints. |
HR and Crisis Management to define maximum incident-working hours, maintain relief rosters, monitor fatigue indicators, and record compliance during prolonged events and exercises. |
|
Psychological Stress (Unavailability of People) |
Not Applicable – stress cannot be fully avoided during major incidents. |
Assumed employee assistance, manager support, workload rotation, psychosocial guidance, incident debriefing, and access to counselling. |
External counselling providers may share service delivery; not evidenced. |
Residual exposure requires active monitoring and cannot be treated as passive acceptance. |
Assumed controls: employee assistance programme; staff welfare checks; mental-health support; debriefing; confidential reporting. |
HR to define crisis welfare protocols, train recovery leaders in psychological first aid, monitor affected staff after incidents, and document follow-up actions. |
|
Mandatory Quarantine (Unavailability of People) |
Not Applicable – public-health directions cannot be avoided. |
Assumed remote work, team segregation, cross-training, delegated authority, secure digital access, and minimum-service prioritisation. |
Outsourced support and reciprocal staffing may share limited capacity; not evidenced. |
Temporary service reduction may require executive approval and daily reassessment. |
Assumed controls: remote access; role backups; secure collaboration; health reporting; continuity procedures; workforce communications. |
ICT and HR to test remote access at scale, maintain quarantined-team succession arrangements, and verify that essential approvals can be completed remotely. |
|
Supplier Failure (Disruption to the Supply Chain) |
Partially Applicable – avoid unsuitable or high-risk suppliers and avoid unnecessary sole-source arrangements. |
Assumed due diligence, performance monitoring, alternate suppliers, safety stock, continuity clauses, and supplier escalation. |
Contracts, warranties, indemnities, insurance, and alternate service agreements may share consequences; validation required. |
Residual exposure may be accepted only where alternatives are impracticable and senior management approves the dependency with enhanced monitoring. |
Assumed controls: supplier qualification; financial review; service-level monitoring; contingency sourcing; contract remedies; supplier contact escalation. |
Procurement to tier suppliers by criticality, obtain continuity evidence from critical suppliers, identify alternatives, conduct annual supplier exercises, and track corrective actions. |
|
Outsourcing Failure (Disruption to the Supply Chain) |
Partially Applicable – avoid outsourcing services where loss of control would create unacceptable exposure. |
Assumed due diligence, service levels, monitoring, retained capability, exit plans, data access, and business continuity requirements. |
Contractual remedies, indemnities, and managed recovery obligations may transfer part of the exposure. |
Acceptance requires approval from the accountable executive and confirmation that ALPS retains responsibility for essential services. |
Assumed controls: contracts; SLA reporting; governance meetings; audit rights; continuity clauses; escalation; exit assistance. |
Contract owners to validate exit plans, identify minimum retained capability, require recovery test evidence, and conduct a joint outage exercise with critical outsourcers. |
|
Cloud Service Provider Failure (Disruption to the Supply Chain) |
Partially Applicable – unsupported or high-risk cloud services may be avoided or discontinued. |
Assumed provider resilience, multi-zone hosting, backups, export capability, offline procedures, monitoring, and vendor escalation. |
Service credits, contractual recovery commitments, cyber insurance, and managed recovery may transfer limited consequences. |
Residual dependency may be accepted only after architecture, portability, recovery, and exit arrangements are approved. |
Assumed controls: SLA; provider status monitoring; backups; access controls; data export; vendor incident escalation; DR arrangements. |
ICT to assess concentration risk, define exit and portability plans, independently test backup restoration, and require evidence of provider recovery exercises. |
|
Telecommunications Failure (Disruption to the Supply Chain) |
Partially Applicable – avoid dependence on a single carrier or communication channel. |
Assumed dual carriers, mobile communications, internet failover, softphones, emergency contact channels, and remote access alternatives. |
Carrier SLAs and managed telecommunications services may transfer part of the service exposure. |
Short residual outages may be accepted within approved communication tolerances if alternate channels remain available. |
Assumed controls: redundant links; mobile devices; collaboration tools; carrier escalation; emergency call tree; network monitoring. |
ICT to eliminate single-carrier dependencies at critical sites, test failover quarterly, maintain satellite or mobile alternatives where justified, and retain test evidence. |
|
Utility Failure (Disruption to the Supply Chain) |
Partially Applicable – critical services may be located in facilities with resilient utility supplies. |
Assumed UPS, backup generation, water reserves where relevant, facility alarms, maintenance, remote work, and manual procedures. |
Utility-provider obligations, property insurance, and equipment warranties may share limited consequences. |
Residual short-duration outages may be accepted after generator and continuity capability are validated. |
Assumed controls: UPS; generators; fuel arrangements; environmental monitoring; emergency lighting; shutdown procedures; alternate site. |
Facilities to test generators under load, validate fuel replenishment, identify utility single points of failure, and exercise extended utility outage scenarios. |
|
Logistics Disruption (Disruption to the Supply Chain) |
Partially Applicable – avoid dependence on a single route, carrier, or distribution point. |
Assumed alternate carriers, route planning, priority deliveries, inventory buffers, tracking, emergency transport, and supplier coordination. |
Carrier contracts, cargo insurance, and alternate logistics agreements may transfer part of the exposure. |
Residual delay may be accepted only within product-specific delivery tolerances and, where necessary, with healthcare stakeholder approval. |
Assumed controls: carrier panel; delivery tracking; alternate routes; escalation; stock prioritisation; emergency delivery procedures. |
Logistics and Procurement to map critical routes, contract backup carriers, define emergency allocation rules, and conduct a delivery disruption simulation. |
|
Import Restrictions (Disruption to the Supply Chain) |
Partially Applicable – reduce dependency on restricted jurisdictions or products where alternatives exist. |
Assumed regulatory monitoring, alternate product qualification, diversified sourcing, safety stock, and early ordering. |
Supplier contracts and trade or cargo insurance may provide limited transfer; not evidenced. |
Residual exposure may require executive acceptance where no clinically acceptable substitute exists. |
Assumed controls: regulatory intelligence; supplier communication; product substitution process; inventory monitoring; alternate sourcing. |
Procurement and Quality to identify import-dependent critical items, pre-qualify substitutes, monitor regulatory developments, and document emergency approval pathways. |
|
Vendor Insolvency (Disruption to the Supply Chain) |
Partially Applicable – financially unstable vendors may be excluded from critical procurements. |
Assumed financial due diligence, credit monitoring, performance reviews, diversification, transition plans, and access to records and assets. |
Performance bonds, guarantees, indemnities, escrow, and insurance may transfer part of the exposure; validation required. |
Acceptance of a financially weak critical vendor requires executive approval, time-bound remediation, and enhanced monitoring. |
Assumed controls: financial assessment; contract termination rights; alternate supplier list; ongoing monitoring; inventory buffer. |
Procurement to introduce periodic financial-health reviews for critical vendors, define insolvency triggers, secure data and asset access rights, and test transition plans. |
|
Third-Party Cyber Incident (Disruption to the Supply Chain) |
Partially Applicable – avoid suppliers that cannot meet minimum cybersecurity requirements. |
Assumed cyber due diligence, access segregation, data minimisation, incident notification clauses, monitoring, alternative processes, and coordinated response. |
Cyber insurance, contractual indemnities, and managed security arrangements may transfer part of the loss. |
Residual exposure requires approval by information security and business ownership, with periodic reassessment. |
Assumed controls: supplier security assessment; least-privilege access; MFA; contractual notification; log monitoring; incident escalation; data backup. |
Information Security and Procurement to tier cyber-critical suppliers, require recovery and breach-notification evidence, restrict supplier access, and conduct joint incident exercises. |
|
Single Source Dependency (Disruption to the Supply Chain) |
Applicable – reliance on one provider should be avoided where feasible for essential services or products. |
Where unavoidable, assume safety stock, enhance supplier monitoring, use contractual priority, substitute products, and contingency sourcing. |
Long-term supply agreements, guarantees, and reserved capacity may share part of the exposure but do not remove accountability. |
Acceptance may be necessary only when no viable alternative exists; executive approval, documented rationale, and frequent review are required. |
Assumed controls: sole-source register; inventory buffers; supplier reviews; emergency sourcing; substitution process; continuity clauses. |
Procurement to maintain an enterprise sole-source register, set reduction targets, qualify alternatives, establish exit plans, and report unresolved critical dependencies quarterly. |
|
Cyber Attack (Equipment and IT-Related Disruption) |
Partially Applicable – prohibit unsupported systems, insecure configurations, and unnecessary external exposure. |
Assumed layered security, MFA, monitoring, network segmentation, endpoint protection, vulnerability management, backups, incident response, and awareness training. |
Cyber insurance and managed security services may transfer limited financial and operational consequences. |
Residual cyber exposure requires executive risk ownership and continuous monitoring; significant known weaknesses should not be accepted without remediation plans. |
Assumed controls: security policies; SOC monitoring; firewalls; EDR; patching; MFA; privileged-access management; backups; incident response; exercises. |
Information Security to complete control maturity assessment, close critical vulnerabilities to defined deadlines, test cyber recovery annually, and report unresolved high-exposure issues to senior management. |
|
Ransomware (Equipment and IT-Related Disruption) |
Partially Applicable – remove unsupported systems and restrict high-risk services and macros. |
Assumed EDR, email filtering, segmentation, least privilege, immutable backups, MFA, patching, user training, isolation, and recovery procedures. |
Cyber insurance, forensic retainers, and managed incident response may transfer part of the financial consequence. |
Not appropriate for acceptance where backups, segmentation, or recovery testing are materially deficient. |
Assumed controls: endpoint security; phishing protection; privileged-access controls; offline or immutable backups; incident response; recovery testing. |
ICT and Security to validate backup immutability, perform clean-room recovery tests, restrict lateral movement, simulate ransomware response, and track recovery time against business objectives. |
|
Malware (Equipment and IT-Related Disruption) |
Partially Applicable – unsafe applications, removable media, and unsupported software may be prohibited. |
Assumed anti-malware, application control, email and web filtering, patching, endpoint monitoring, least privilege, and user awareness. |
Managed security services and cyber insurance may share limited consequences. |
Residual commodity malware exposure may be accepted within approved cyber risk appetite if controls are continuously monitored. |
Assumed controls: EDR; antivirus; secure email gateway; web filtering; patch management; application allow-listing; incident response. |
Security to review endpoint coverage, block unapproved software, conduct regular phishing and malware simulations, and maintain evidence of remediation and control effectiveness. |
|
Distributed Denial of Service—DDoS (Equipment and IT-Related Disruption) |
Partially Applicable – unnecessary internet-facing services may be removed. |
Assumed traffic filtering, content delivery networks, rate limiting, resilient hosting, monitoring, provider escalation, and alternate communication channels. |
Cloud or telecommunications DDoS-protection services and SLA commitments may transfer part of the operational burden. |
Residual exposure may be accepted if essential internal operations remain available and outage tolerances are approved. |
Assumed controls: firewalls; provider filtering; monitoring; scalable infrastructure; incident escalation; status communication. |
ICT to identify all externally exposed critical services, obtain DDoS capacity assurance, test provider escalation, and conduct a service-unavailability exercise. |
|
Insider Threat (Equipment and IT-Related Disruption) |
Partially Applicable – conflicting duties, excessive privileges, and unsupported access should be removed. |
Assumed background screening, segregation of duties, least privilege, monitoring, access reviews, data loss prevention, staff awareness, and disciplinary procedures. |
Fidelity insurance and managed monitoring may transfer limited consequences; not evidenced. |
Significant unresolved privileged-access exposure is not appropriate for acceptance. |
Assumed controls: joiner-mover-leaver process; access approval; privileged-access monitoring; logging; segregation; whistleblowing; security awareness. |
HR, Security, and ICT to implement risk-based insider monitoring, quarterly privileged-access certification, rapid access revocation, and scenario-based insider-threat exercises. |
|
Data Breach (Equipment and IT-Related Disruption) |
Partially Applicable – unnecessary collection and retention of sensitive data may be eliminated. |
Assumed data classification, encryption, access control, monitoring, secure transfer, retention, breach response, and staff training. |
Cyber insurance and contractual indemnities may transfer limited costs. |
Residual privacy and confidentiality risk requires accountable data-owner approval and compliance monitoring. |
Assumed controls: encryption; DLP; access logs; MFA; records retention; incident response; privacy procedures; supplier clauses. |
Data Protection and Security to map critical data flows, validate encryption and access controls, test breach-notification procedures, and remediate excessive retention or access. |
|
Network Failure (Equipment and IT-Related Disruption) |
Partially Applicable – single points of network failure should be removed where practicable. |
Assumed redundant devices and links, monitoring, configuration backup, preventive maintenance, failover, alternate connectivity, and DR support. |
Carrier and managed network SLAs may transfer part of the service obligation. |
Short residual outages may be accepted only where business workarounds and alternate connectivity exist. |
Assumed controls: redundant switches and routers; dual links; monitoring; configuration backups; maintenance; escalation. |
ICT to document network single points of failure, conduct failover testing at least annually, retain spare equipment, and measure recovery performance. |
|
Server Failure (Equipment and IT-Related Disruption) |
Partially Applicable – unsupported or non-resilient servers should be retired. |
Assumed clustering, virtualisation, monitoring, spare capacity, backups, preventive maintenance, and DR replication. |
Vendor warranties and managed infrastructure services may share part of the consequence. |
Residual hardware failure may be accepted within approved RTOs after recovery tests demonstrate effectiveness. |
Assumed controls: high availability; monitoring; hardware support; backups; replication; incident escalation; DR procedures. |
ICT to classify servers by business criticality, align support and replication with RTOs, remove unsupported hardware, and conduct restoration tests. |
|
Database Corruption (Equipment and IT-Related Disruption) |
Partially Applicable – unsupported databases and uncontrolled direct changes should be prohibited. |
Assumed transaction logging, replication, integrity checks, access controls, tested backups, change management, and point-in-time recovery. |
Database support contracts and cyber insurance may transfer limited consequences. |
Not appropriate for acceptance where recovery points or integrity testing do not meet business requirements. |
Assumed controls: database monitoring; backup; replication; restricted administration; change control; integrity checks; recovery procedures. |
ICT to test point-in-time restoration, validate backup consistency, implement automated corruption detection, and document data-reconciliation procedures with business owners. |
|
Cloud Service Outage (Equipment and IT-Related Disruption) |
Partially Applicable – avoid unsupported or non-portable cloud architectures for critical functions. |
Assumed multi-zone deployment, provider monitoring, backups, offline procedures, data export, alternate access, and vendor escalation. |
Cloud SLAs, service credits, and managed recovery commitments may share limited consequences. |
Residual provider dependency requires executive and ICT approval with defined recovery and exit criteria. |
Assumed controls: provider SLA; multi-zone resilience; backup; status monitoring; support escalation; business workaround. |
ICT to assess multi-region requirements, validate independent backups, maintain offline procedures, test portability, and exercise extended provider outage scenarios. |
|
Power Failure (Equipment and IT-Related Disruption) |
Partially Applicable – critical systems may be hosted in facilities with resilient power architecture. |
Assumed UPS, backup generation, dual supplies, shutdown procedures, environmental monitoring, remote work, and DR facilities. |
Utility agreements, equipment warranties, and property insurance may share limited consequences. |
Short residual interruptions may be accepted after generator and UPS performance is validated. |
Assumed controls: UPS; generators; automatic transfer; fuel contracts; monitoring; emergency lighting; alternate site. |
Facilities and ICT to test power failover under load, verify generator autonomy, confirm fuel resupply, and document recovery of technology and business services. |
|
Hardware Failure (Equipment and IT-Related Disruption) |
Partially Applicable – obsolete and unsupported equipment should be removed. |
Assumed preventive maintenance, spare equipment, redundancy, asset lifecycle management, backups, and vendor support. |
Warranties, maintenance contracts, and equipment leasing may transfer part of the financial consequence. |
Residual isolated equipment failure may be accepted where replacement meets the applicable RTO. |
Assumed controls: asset register; maintenance; spare devices; standard builds; support contracts; replacement procedures. |
ICT to identify critical unsupported assets, maintain minimum spare holdings, monitor lifecycle status, and test rapid replacement of essential devices. |
|
Software Failure (Equipment and IT-Related Disruption) |
Applicable where defective, unsupported, or high-risk software is withdrawn or not deployed. |
Assumed change management, testing, rollback, vendor support, patching, monitoring, segregation of environments, and manual workarounds. |
Software warranties, vendor support, and managed application services may share part of the consequence. |
Residual defects may be accepted only after business ownership approves known limitations and compensating controls. |
Assumed controls: testing; release approval; rollback; version control; vendor escalation; incident management; workaround procedures. |
ICT and application owners to strengthen regression testing, document rollback criteria, maintain tested manual workarounds, and review unresolved defects before major releases. |
|
Internet Failure (Equipment and IT-Related Disruption) |
Partially Applicable – avoid single-provider connectivity. |
Assumed dual internet services, mobile failover, alternate sites, offline procedures, and communication alternatives. |
Provider SLAs may transfer part of the service obligation. |
Short outages may be accepted if failover and MBCO delivery remain effective. |
Assumed controls: redundant links; automatic failover; mobile hotspots; monitoring; carrier escalation; remote-work alternatives. |
ICT to test internet failover quarterly, assess bandwidth under recovery load, provide backup connectivity for critical teams, and retain performance evidence. |
|
Authentication System Failure (Equipment and IT-Related Disruption) |
Partially Applicable – eliminate single-instance authentication services where feasible. |
Assumed redundant identity services, emergency access accounts, offline authentication, backup administrators, monitoring, and recovery procedures. |
Cloud identity-provider SLAs or managed IAM services may share part of the operational burden. |
Residual identity-service dependency should be accepted only after break-glass and recovery controls are tested. |
Assumed controls: redundant directories; MFA; break-glass accounts; privileged-access controls; monitoring; backup and recovery. |
ICT and Security to test identity-service failover, protect and monitor emergency accounts, define manual access procedures, and measure recovery against critical business RTOs. |
|
Artificial Intelligence System Failure (Equipment and IT-Related Disruption) |
Applicable where unreliable AI outputs are excluded from autonomous decision-making or the system is suspended when validation fails. |
Assumed human oversight, output validation, fallback to conventional analytics, model monitoring, data-quality checks, access control, and change governance. |
Vendor warranties and support may share limited technical consequences; accountability remains with ALPS. |
Residual model uncertainty may be accepted only for advisory use within approved governance boundaries and with periodic review. |
Assumed controls requiring validation: human approval; documented use cases; access restrictions; audit logs; fallback processes; data-quality review. |
Data and ICT owners to establish AI governance, define prohibited uses, monitor drift and output quality, maintain manual fallback procedures, and test continuity without AI-enabled tools. |
Control Validation and Governance Requirements
The table provides a structured starting point for control assessment, but each assumed existing control should be validated before it is relied upon in the formal Risk Assessment Report. Validation should include the following activities:
- Document review: Examine policies, procedures, plans, contracts, insurance schedules, technical standards, maintenance records, and supplier agreements.
- Control-owner confirmation: Identify an accountable owner for each control and confirm its scope, operating frequency, dependencies, and escalation arrangements.
- Implementation evidence: Obtain system reports, inspection certificates, access reviews, backup logs, maintenance records, training records, supplier assurance reports, or other objective evidence.
- Testing and exercising: Confirm that preventive, response, recovery, and continuity controls operate under realistic conditions rather than relying solely on documented design.
- Gap recording: Record missing, incomplete, outdated, untested, or ineffective controls in a formal improvement register.
- Action governance: Assign every planned control to an accountable owner with a target date, priority, expected outcome, required evidence, and reporting route.
- Residual-risk decision: After controls have been validated, determine whether remaining exposure should be reduced further, transferred, avoided, or submitted for formal acceptance.
Risk-Acceptance Governance
Risk acceptance should not be inferred from the absence of additional controls.
Where ALPS Healthcare determines that further treatment is impracticable or disproportionate, the acceptance decision should document:
- the specific residual exposure being accepted;
- the reason additional treatment is not being pursued;
- the operational services and stakeholders that may be affected;
- the accountable risk owner;
- the approving authority;
- the validity period of the acceptance;
- monitoring indicators and reporting frequency;
- conditions that require reconsideration;
- compensating controls and contingency arrangements; and
- the next formal review date.
Threats affecting personnel safety, essential healthcare supply continuity, critical information, statutory obligations, or systemic technology capability should generally require approval at a senior governance level.
Temporary acceptance pending remediation should include a firm expiry date and should not become an indefinite substitute for control implementation.
The Treatment and Control assessment translates the Threat Register into a practical review of how ALPS Healthcare may manage its exposure to disruptive events.
By distinguishing among risk avoidance, risk reduction, risk transference, and risk acceptance, the assessment provides greater clarity regarding the purpose of each treatment and the specific controls required to implement it.
This distinction prevents routine preventive measures from being incorrectly classified as avoidance and ensures that outsourcing, insurance, or contractual arrangements are not treated as a means of removing ALPS Healthcare’s accountability for essential services.
The assessment also highlights that controls must be evaluated beyond their mere existence.
Their scope, ownership, reliability, integration, testing, and effectiveness determine whether they will perform as expected during a disruption.
Controls that are undocumented, dependent on a single person, based on untested assumptions, or unsupported by recovery arrangements may provide limited resilience despite appearing adequate in policy documents.
Identified control gaps should be converted into measurable planned actions.
These actions should specify what must be implemented, which function owns the work, when it must be completed, how effectiveness will be tested, and what evidence will demonstrate completion.
This approach provides senior management, risk owners, internal auditors, and regulators with a transparent basis for monitoring improvements in resilience.
The treatment-and-control assessment supports Business Continuity Strategy by identifying where alternate facilities, workforce arrangements, technology resilience, supplier diversification, manual workarounds, and recovery capabilities are required.
It also strengthens Crisis Management by clarifying escalation and response controls, and supports Operational Resilience by highlighting dependencies and single points of failure across people, premises, technology, information, utilities, and third parties.
This chapter does not determine the adequacy of residual risk or assign likelihood, impact, or risk ratings.
Those evaluations should be completed after the assumed controls have been validated and planned improvements have been considered.
The subsequent Risk Assessment stages will use this treatment-and-control baseline to assess control effectiveness, determine residual exposure, prioritise risks, and establish appropriate mitigation plans.
More Information About Business Continuity Management Courses


![[BCM] [ALPS] [Full Banner] Implementing Business Continuity Management for ALPS Healthcare](https://no-cache.hubspot.com/cta/default/3893111/a577c05a-ab89-4043-9a89-1dea0d883afc.png)




![Banner [Table] [BCM] [E3] [RAR] [Summing Up] [T2] Treatment and Control of Identified Threats](https://no-cache.hubspot.com/cta/default/3893111/6755d2e8-5050-4a5e-be0a-a1568a65e0ed.png)
![[BCM] [ALPS] [3/4 Banner] Implementing Business Continuity Management for ALPS Healthcare](https://no-cache.hubspot.com/cta/default/3893111/5bb3d163-ccf4-4942-8e51-90cb0e0de84f.png)
![[BCM] [ALPS] [E3] [BIA] MBCO Corporate MBCO](https://no-cache.hubspot.com/cta/default/3893111/3e0b35d2-08b6-4caf-b7db-144625ec8145.png)
![[BCM] [ALPS] [E3] [BIA] [PS] Key Product and Services](https://no-cache.hubspot.com/cta/default/3893111/ab611654-bce2-450c-affc-3970de6c8909.png)
![[BCM] [ALPS] [E3] [RAR] [T1] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/806c27e6-1db5-42a2-ac84-e0df3624bc49.png)
![[BCM] [ALPS] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/4c14572c-2ed4-46aa-82c8-5ead8fd31ced.png)
![[BCM] [ALPS] [E3] [BCS] [T1] Mitigation Strategies and Justification](https://no-cache.hubspot.com/cta/default/3893111/25548d11-adb7-4e6e-9a5a-054db2ea377d.png)
![[BCM] [ALPS] [E1] [C10] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/94f8b16c-55da-4543-a948-448f2241296e.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)





![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





