Analyzing Risk-Countermeasure in Organizations: a Quantitative Approach

نویسندگان

  • Yudistira Asnar
  • Paolo Giorgini
چکیده

Risk is one of inherent problems in all software systems. It becomes more significant if the software system is operated in a critical system (e.g., air traffic control, nuclear plant). It is because in this domain the software system is expected to be always dependable all the time of its operation. The system is dependable when all its risks are suppressed until acceptable level. Therefore, in such setting analysts must carefully analyze the socio-technical system (i.e., organizationalsetting and software systems) and understand how uncertain events may affect the systems. By means of the Tropos Goal-Risk, we model the socio-technical system including its risks. Essentially, the framework consists of goal, event, and treatment modeling. The goal layer represents what the stakeholders’ interests are and how to achieve them. The event layer depicts how uncertain events occur and impact the goals of stakeholders. The treatment layer represents what the possible measures that are available to treat the events. By quantifying the evidence value of the model, analysts can reason about the level of risk and choose the most appropriate alternative to achieve the stakeholders’ interests and the necessary treatment that should be employed to mitigate the risks. We use a case study on Air Traffic Management to illustrate the proposal.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Analyzing Dimensions, Consequences, and Inequalities of Organizational Citizenship Behaviour in Non-governmental Organizations of Crisis Management (Experimental Evidence: Red Crescent Society of the Islamic Republic of Iran)

INTRODUCTION: This research aimed to provide a dynamic model of organizational citizenship behavior (OCB) in crisis management non-governmental organizations with a social approach (experimental evidence: Red Crescent Society of the Islamic Republic of Iran). METHODS: This applied research was conducted using a mixed (quantitative-qualitative) method to analyze the data. The statistical popula...

متن کامل

An Approach to Select Cost-Effective Risk Countermeasures Exemplified in CORAS

Security risk analysis should be conducted regularly for organizationsto maintain an acceptable level of security. In principle, all risks thatare unacceptable according to the predefined criteria should be mitigated.However, risk mitigation comes at a cost, and only the countermeasuresthat cost-efficiently mitigate risks should be implemented. This reportpresents an app...

متن کامل

A risk model for cloud processes

Traditionally, risk assessment consists of evaluating the probability of "feared events", corresponding to known threats and attacks, as well as these events' severity, corresponding to their impact on one or more stakeholders. Assessing risks of cloud-based processes is particularly difficult due to lack of historical data on attacks, which has prevented frequency-based identification...

متن کامل

Proposing a quantitative approach to measure the success of energy management systems in accordance with ISO 50001: 2011 using an analytical hierarchy process (AHP)

ISO 50001: 2011 provides an integrated and systematic framework to plan, implement, operate, certify, and maintain energy management systems (EMSs). Evaluation of organizations in relation to meeting the standard requirements is performed by an auditing qualitative approach. In this research, a quantitative approach has been proposed and implemented to assess organizations and rank them based o...

متن کامل

Providing a Comprehensive Model of Promoting the Monitoring System in Sports Organizations with a Mixed Approach

Purpose: This research was conducted to develop a comprehensive model for improving the supervision system in sports organizations of the country. Methodology: In terms of purpose, the research was applied and developmental, and in terms of the method of data collection, it was a mixed type of sequential exploratory design. In the qualitative phase of the research, semi-structured interviews w...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008