Integration of an IT-Risk Management / Risk Assessment Framework with Operational Processes
نویسندگان
چکیده
This paper discusses the background and results of a research project which was conducted by ENISA (European Network and Information Security Agency) in cooperation with the BOC Information Technologies Consulting GmbH. The project was initiated with respect to the main task of ENISA: ensuring a high and effective level of network and information security within organisations in the European Union. As an important step towards this goal the research project aimed at increasing the level of integration between an enterprise-level IT Risk Management/Risk Assessment on the one hand, and selected operational business processes, on the other hand. The proposed integration is mainly established on the level of document flows between processes and activities respectively. In particular, operational processes which are closely related to IT were selected for integration. The introduced approach promises a better overall quality of IT Risk Management in an enterprise in general, as well as an improved management of risks in operational processes.
منابع مشابه
System Engineering Implementation Process for Super-Systems
System engineering is one of the most powerful tools for comprehensive project management and control. This tool emphasized the life cycle of the projects, manages every single activity and helps manage the main elements of the project through a set of management and engineering processes. The goal of the current study is to use a system engineering approach in design phase in order or to meet ...
متن کاملOperational Risk Management Framework for Service Outsourcing: Consideration of Risk Dimensions and their Application into the Framework
As outsourcing is becoming mandate for today’s business, there has been a variety of researches taking place. This paper discusses on managing operational risks in an organization where one or more business processes are being outsourced. We first review on changing nature of operational risks not only in outsourced process itself, but also among any other interrelated processes. Then a concept...
متن کاملارائه الگویی برای ارزیابی ریسک آتشسوزیهای عمدی
Background & Objectives : It is not possible to live without using fire. However, fire could destruct human properties in a short time. One of the most important types of fire is intentional fire. This type of fire has become a great problem for insurance companies, fire departments, industries, government and business in the recent years. This study aimed to provide a framework for risk assess...
متن کاملRisk Management Framework in Islamic Banking: Basel II and III, Challenges and Implications in Islamic Banking
The time to fix the roof is when the sun is shining risk management has not been uppermost on the Islamic banking sector’s agenda in recent years. It is crucial for Islamic banks (IBs) to have comprehensive risk management framework as there is growing realization among IBs that sustainable growth critically depends on the development of a comprehensive risk management framework. Islamic b...
متن کاملA Fuzzy AHP-TOPSIS Framework for the Risk Assessment of Green Supply Chain Implementation in the Textile Industry
In the emerging supply chain environment, green supply chain risk management plays a significant role than ever. Risk is an inherent uncertainty and has tendency to disrupt the typical green supply chain management (GSCM) operations and eventually reduce the success rate of industries. In order to mitigate the consequences, a fuzzy multi-criteria group decision making modeling (FMCGDM) which co...
متن کامل