Assessing the effects of IT changes on IT risk - A business process-oriented view
نویسنده
چکیده
The economic relevance of IT risk is increasing due to various operational, technical as well as regulatory reasons. Increasing flexibility of business processes and rising dependability on IT require continuous risk assessment, challenging current methods of risk management. Extending these methods by a business process-oriented view is a promising approach for taking the occurring dynamics and interlinks into consideration. In this contribution, a layer based approach for systematic modeling of relations between causes (threats) and effects (direct and indirect loss) is pursued. On the basis of these cause-effect relations, the presented IT Risk Indicator InTRIn measures changes in the IT support of business processes. It is discussed how InTRIn can provide accurate and real-time information on the IT risk situation and thus improve IT risk management. 1 Flexible Business Processes and IT Risk The flexibility to adapt business processes to customers’ changing demands is regarded as an important instrument for companies in order to be able to distinguish themselves from their competitors (e.g. [Sa95; BG05; Mi07]). To create flexibility, information technology adopts an increasingly supportive role. While, at least in Germany, two out of three companies already use IT systems such as ERP or SCM to manage their business processes [Sa05], the need for flexibility is further reinforced by current technological trends. The increasing operational use of web services and the realization of service-oriented architectures (SOA), as well as the use of virtualization approaches or so-called services on demand, provide a helpful and suitable IT infrastructure [Mi07; Kr05]. However, increasing automation of business processes by relying on a flexible IT infrastructure does not only improve business process performance but also places particular emphasis on IT risk. On the one hand, business processes are directly linked with a company’s economic return as well as compliance with regulations, contracts, and standards [LK06] [Ka08]. Increasing dependency of business processes on IT also increases the possible indirect losses resulting from a malfunction of IT that can easily
منابع مشابه
Impact of Information Technology on Iran Distribution Company Performance in View of Organizational Infrastructures
The relationship between information technology investments and firm value as an area of inquiry has sustained interest among IS researchers over the past decade. Based on literature review of published work at corporate level productivity, researchers have developed three different approaches in assessing the correlation between IT implementation and productivity measures. Broadly speaking, th...
متن کاملAdapted Loss Database - A New Approach to Assess IT Risk in Automated Business Processes
Service-oriented architectures (SOA) provide companies with dynamic IT infrastructures to adapt business processes flexibly to new requirements. However, the success of SOA will also depend on the ability to manage risk resulting from frequent and context-specific changes of IT support for automated business processes. Assessing this IT risk is challenging, since frequently changing relations b...
متن کاملA Reference Model for Process-Oriented IT Risk Management
The economic relevance of IT risks is increasing due to various operational, technical as well as regulatory reasons. Increasing flexibility of business processes and increasing dependability on IT require continuous risk assessment, challenging current methods for risk management. Extending IT risk management by a business process-oriented view is a promising approach for taking the occurring ...
متن کاملConcept drift detection in business process logs using deep learning
Process mining provides a bridge between process modeling and analysis on the one hand and data mining on the other hand. Process mining aims at discovering, monitoring, and improving real processes by extracting knowledge from event logs. However, as most business processes change over time (e.g. the effects of new legislation, seasonal effects and etc.), traditional process mining techniques ...
متن کاملThe Study of the Effect of Diversification Strategy, Cost Leader-ship Strategies and Product Differentiation on Business Unit Value
Changes in credit risk may arise when either the value or the risk of corporate assets changes. Changes in the equity value associated with the changes in the asset value and changes in asset risk can be characterized into potentially countervailing direct and indirect effects. The indirect effect of risk on equity value is a function of factors that affect the debt value of including leverage,...
متن کامل