4.6 Article

Integrated risk management process assessment model for IT organizations based on ISO 31000 in an ISO multi-standards context

Journal

COMPUTER STANDARDS & INTERFACES
Volume 60, Issue -, Pages 57-66

Publisher

ELSEVIER SCIENCE BV
DOI: 10.1016/j.csi.2018.04.010

Keywords

Integrated risk management; IT organizations; ISO/IEC 15504-330xx; Process reference and assessment models engineering; Design science research method

Funding

  1. Spanish Ministry of Science and Technology
  2. ERDF fund [TIN2016-76956-C3-3-R]

Ask authors/readers for more resources

With risk management as a key challenge for most organizations, aligning and improving organisational and business processes is essential. Capability and Maturity Models can contribute to assess and then enable process improvement. With the need to integrate risk management in IT Organizations (IT department/organisation), ISO/IEC 15,504-330xx process assessment approach combined with the latest version of ISO 31,000 for risk management can be the foundations for new process models. An integrated process-based approach with various popular and market demands ISO standards (ISO 9001, ISO 21,500, ISO/IEC 20,000-1 and ISO/IEC 27,001) is proposed in the paper; it explains how the Integrated Risk Management Process Assessment Model for IT Organizations in an ISO multi-standards context is developed with a Design Science research method.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available