A DEA-based approach for information technology risk assessment through risk information technology framework
نویسندگان
چکیده
The use of Information Technology (IT) in organizations is subject to various kinds of potential risks. Risk management is a key component of project management enables an organization to accomplish its mission(s). However, IT projects have often been found to be complex and risky to implement in organizations. The organizational relevance and risk of IT projects make it important for organizations to focus on ways in order to successfully implement IT projects. This paper focuses on the IT risk management, especially the risk assessment model and proposes a process oriented approach to risk management. To do this end, this paper applies the risk IT framework which has three main domains, i.e., Risk Governance (RG), risk analysis, Risk Response (RR) and 9 key processes. Then, a set of scenarios, which can improve the maturity level of risk IT processes, are considered and the impact of each scenario on the risk IT processes is determined by the expert opinions. Finally, the Data Envelopment Analysis (DEA) is customized to evaluate improvement scenarios and select the best one. The proposed methodology is applied to the Iran Telecommunication Research Centre (ITRC) to improve the maturity level of its IT risk management processes.
منابع مشابه
Implementation Procedures for the Risk in Early Design (RED) Method
Risk assessments performed at the conceptual design phase of a product may offer the greatest opportunity to increase product safety and reliability at the least cost. This is an especially difficult proposition, however, as often the product has not assumed a physical form at this early design stage. This paper introduces the Risk in Early Design (RED) method, a method for performing risk asse...
متن کاملA New Extended Analytical Hierarchy Process Technique with Incomplete Interval-valued Information for Risk Assessment in IT Outsourcing
Information technology (IT) outsourcing has been recognized as a new methodology in many organizations. Yet making an appropriate decision with regard to selection and use of these methodologies may impose uncertainties and risks. Estimating the occurrence probability of risks and their impacts organizations goals may reduce their threats. In this study, an extended analytical hierarchical proc...
متن کاملRisk Analysis in E-commerce via Fuzzy Logic
This paper describes the development of a fuzzy decision support system (FDSS) for the assessment of risk in E-commerce (EC) development. A Web-based prototype FDSS is suggested to assist EC project managers in identifying potential EC risk factors and the corresponding project risks. A risk analysis model for EC development using a fuzzy set approach is proposed and incorporated into the FDSS....
متن کاملDesign of Multi-Objective Model for Disruption Risk Assessment of Supply Chain Using Combined Genetic Algorithm and Simulated Annealing
Due to the many risks involved in the supply chain, and the high costs associated with damage to the supply chain, risk identification and evaluation should be a top priority in risk management programs in organizations. Risk assessment and ratings determine the superiority of each risk based on the relevant indicators and thus provide an appropriate response to each risk. In this regard, this ...
متن کاملBeyond effectiveness: the evaluation of information systems using a comprehensive health technology assessment framework
A Comprehensive Health Technology Assessment Framework is presented as a conceptual tool for decision-making about health technologies, including information technologies. The aim of the model is to provide an empirical, evidence-based foundation for health technology decisions. The major framework dimensions are (1) population at risk, (2) population impact, (3) economic concerns, (4) social c...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Int. Arab J. Inf. Technol.
دوره 13 شماره
صفحات -
تاریخ انتشار 2016