Estrella Partners
Solutions for Our Times
RISK MANAGEMENT

GOVERNANCE RISK COMPLIANCE (GRC)
management practices into their operation.  Clients are in need of developing policy and
procedures that identify which data elements are required to meet the ever increasing
demands for reliable and verifiable information, as well as ensuring adherence to such
policies.  Our seasoned staff has deep risk management experience working directly with
regulatory agencies to ensure compliance.  

OPERATIONAL RISK MANAGEMENT
Our experienced staff provides Operational Risk support and guidance in the following
areas; Strategic Alignment – addresses operational risk reduction from a different
perspective.  This occurs by create strategic planning processes which identify technology
enabling capabilities to enhance business process effectiveness; thus reducing
operational risk.  Those strategies must be grounded in and focus on the “art of the
possible.”

    Risk Assessment – Identifies threats and vulnerabilities identifies existing controls
    and their anticipated effectiveness.
    .
    Risk Strategy begins by gauging Management’s Risk Appetite and offering
    mitigations strategies to accommodate that appetite.

    Institutionalizing the Solution – involves working with the client’s staff to embed the
    mitigation solutions into the daily workload.

    Compliance Management – is putting a structure to ensure the mitigation solutions
    are working as anticipated and tweaking them as needed.  It also involves revisiting
    the Risk Assessment to determine if the business or corporate environment has
    changed and validating that resources are addressing the appropriate priorities.


BUSINESS CONTINUITY MANAGEMENT
Business Continuity Management must expand beyond the traditional IT focus to include
the Business Unit operational needs.  These include relocation, revised operational
procedures at the relocation site, staffing, provisioning for the relocation site, human impact
from the disaster, corporate policies on compensation until normal operations resumes,
supply chain or outsourcing due diligence.  The optimal precursor to this service is a Risk
Assessment.  Our staff has extensive experience developing Business Continuity Plans,
Assessing existing Continuity Plans with formal recommendations, Testing Continuity
Plans, and the implementation of plans.

DISASTER RECOVERY
Disaster Recovery follows a traditional focus on IT, but from a Business Impact
perspective.  By concentrating on those processes that are mission critical, we can help
your firm survive a disaster in the most cost effective manner.  Among the affiliated
endeavors for this service offering are Data Center renovations or relocation, cost savings
for infrastructure upgrades, alternatives or hardening.  The optimal precursor to this service
is a Risk Assessment.

INCIDENT RESPONSE PLANNING
Incident Response Planning covers the policies and procedures for dealing with an
incident be it workplace violence, pandemic, a disaster at headquarters, or a remote site.  It
includes interactions with public safety, information flow to Executive / Senior Management
and Public Relations.  Our staff can assist clients with minimizing the risks associated with
these and other potential scenarios that can have a direct impact on your business
operations.

CRISIS MANAGEMENT
Crisis Management focuses on Executive Management’s information flow related to the
crisis, marshaling resources, processes for managing the crisis with a view towards both
effective resolution and a “paper trail” of reasonable and prudent deliberation and actions,
Public Relations activities, and interactions with regulators or external authorities such as
the SEC, Banks, or security analysts.  For business partners, suppliers and customers, the
goal is to reassure customers and suppliers by providing them with accurate and reliable
information on the extent of the problem and the anticipated resumption of “normal
operations

OUTSOURCING RISK MANAGEMENT
Just as many firms outsource payroll functions, component manufacturing, or legal
services, Risk Management can be outsourced.  Estrella Partners offer services after a Risk
Management process has been put in place.  We can assist in establishing Risk
Management procedures, as well as the ongoing management of those procedures for
firms that do not have the resources or internal capabilities to do so.    As independent
agents we can provide various services such as a compliance assessment, facilitating
management risk review meetings, and performing an updated risk assessment.  In
addition, as many firms are turning to off-shore outsourcing solutions for technology and
services, we can provide objective risk assessments and recommendations for risk
mitigation of those activities.

TECHNOLOGY RISK MANAGEMENT
Our Technology Risk Management services are focused in the area of Network and Data
Center Security, which addresses the digital and physical aspects of data security.  It
identifies data leakage or loss by malicious employees, competitors, or inappropriate
distribution.  This services provides mitigation solutions to secure your most valuable asset
(information)