Risk Mitigation
At Infosys, a detailed plan for risk identification, monitoring and mitigation is a part of project planning. It covers risk identification, prioritization and mitigation options. Our business continuity plans are focused on:
Infrastructure
- Well-defined Business Continuity and Disaster Recovery Plans at organization and client level
- Global de-risked development centers
- State-of-the-art fail-safe network connectivity with multiple fall-back options
- Interoperability to ensure seamless relocation
- Locations far away from potentially conflict-ridden zones
- Fully equipped Offsite Disaster Recovery Facility in Mauritius
Security
- Stringent physical security and network security
- Secure Human Resources practices
- Regular external audits to ensure compliance and cover blind spots
Confidentiality and Privacy
- Access restrictions and controls for all Information Assets
- Context-dependent security measures including physical isolation of projects, if needed
- Legal agreements with employees to ensure compliance
- Agreements under relevant jurisdiction for the client
People
- Built-in redundancies for key personnel
- Back-up of project artifacts and experiential repositories
Infosys undertook an organization-wide Risk Self-Identification (RSI) exercise. It covered all business units, verticals, service offerings, support groups and subsidiaries. The results offered a deeper, more diverse and quantified feedback on risks. The results of the RSI were collated and categorized and the probability and impact-magnitude assessment was completed. Using the Basic Risk Inventory, we identified primary risk categories that form the Infosys enterprise-wide Risk Management (IRM) framework. This enables us to address actual and potential risk events in a systematic manner.