2018
DOI: 10.1002/smr.1984
|View full text |Cite
|
Sign up to set email alerts
|

ISO 31000‐based integrated risk management process assessment model for IT organizations

Abstract: Governance, Risk management, and Compliance activities are key challenges faced by organizations. Process Models and Capability Process Assessments are governance instruments that can help organization in assessing and improving their processes. Several ISO standards propose process models for Management System Standards based on ISO 9001, ISO/IEC 20000‐1, and ISO/IEC 27001, and for project management with ISO 21500. The ISO 31000 standard provides guidance for Risk management with a process approach and syste… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
14
0
1

Year Published

2020
2020
2022
2022

Publication Types

Select...
5
3

Relationship

0
8

Authors

Journals

citations
Cited by 17 publications
(15 citation statements)
references
References 22 publications
(34 reference statements)
0
14
0
1
Order By: Relevance
“…Bakar et al , 2015; Hannigan et al , 2019), despite possibly an increasing level of complexity (Heston and Phifer, 2011). However, researchers also highlight partial misalignments in the terminology, structure and scope of management system standards (Barafort et al , 2019). Methods and harmonization strategies are described in six papers in our review (8%).…”
Section: Thematic Findingsmentioning
confidence: 99%
See 2 more Smart Citations
“…Bakar et al , 2015; Hannigan et al , 2019), despite possibly an increasing level of complexity (Heston and Phifer, 2011). However, researchers also highlight partial misalignments in the terminology, structure and scope of management system standards (Barafort et al , 2019). Methods and harmonization strategies are described in six papers in our review (8%).…”
Section: Thematic Findingsmentioning
confidence: 99%
“…Majerník et al (2017) describe a conceptual model for the integration of ISO/IEC 27001, ISO 9001 for quality management, ISO 14001 for environmental management and OHSAS 18001 for occupational health and safety (now replaced by the ISO 45001). The work of Barafort et al (2017, 2018, 2019) focuses on risk management activities foreseen by ISO/IEC 27001, ISO 9001, ISO 21500 (guidance on project management) and ISO/IEC 20000 (IT service management). Hoy and Foley (2015) delve into the integration of ISO 9001 and ISO/IEC 27001 audits.…”
Section: Thematic Findingsmentioning
confidence: 99%
See 1 more Smart Citation
“…Pada penelitian yang dilakukan oleh [2], disimpulkan bahwa sebelas prinsip dalam ISO 31000:2009 standar manajemen risiko sangat potensial untuk dijadikan basis best practice dan dapat mempercepat penerapan manajemen risiko. Penerapan ISO 31000 dilakukan oleh [9] untuk membangun model proses penilaian risiko terintegrasi yang dapat meningkatkan kinerja dan koordinasi aktivitas manajemen risiko di organisasi teknologi informasi. Penerapan standar ISO 31000 juga dilakukan pada manajemen risiko untuk rantai pasokan.…”
Section: Pendahuluanunclassified
“…Various ISO standards target management systems such as quality perspectives in ISO 9001, IT Service Management (ITSM) in ISO/IEC 20000 -1, project management in ISO 21500, and information security in ISO/IEC 27001. These IT-related and non-IT standards are significant for many companies [6].…”
Section: Introductionmentioning
confidence: 99%