A General, But Readily Adaptable Model of Information System Risk
نویسندگان
چکیده
This article is the first of two whose goal is to advance the discussion of IS risk by addressing limitations of the current IS risk literature. These limitations include: • inconsistent or unclear definitions of risk, • limited applicability of risk models, • frequent omission of the temporal nature of risk, and • lack of an easily communicated organizing framework for risk factors. This article presents a general, but broadly adaptable model of system-related risk. The companion article, Volume 14, Article 2[Sherer and Alter, 2004] focuses on IS risk factors and how these factors can be organized. This article starts by identifying criteria for a general, but broadly applicable risk model. It compares alternative conceptualizations of risk and provides clarifications of the definitions of risk and of different treatments of goals, expectations, and baselines for assessing risk. It presents several of the risk models in the IS literature and discusses the temporal nature of risk. Based on that background it presents a general and broadly adaptable model of risk that encompasses: • goals and expectations, • risk factors and other sources of uncertainty, • the operation of the system or project whose risks are being managed, • the risk management effort, • the possible outcomes and their probabilities, • impacts on other systems, 2 Communications of the Association for Information Systems (Volume 14, 2004) 1-28 A General, but Readily Adaptable Model of Information Risk by S. Alter and S.A. Sherer • and the resulting financial gains or losses. The model’s adaptability allows users to eliminate facets that are not important for their purposes. For example, the majority of current practitioners would probably think of risk in terms of negative outcomes rather than the full distribution of possible outcomes. A comparison of the general model with other risk models in the IS literature shows that it covers most of the ideas expressed by previous IS risk models while also providing a practical approach that managers can use for thinking about IS risk at whatever level of detail makes sense to them.
منابع مشابه
Systems Risk Analysis UsingHierarchical Modeling
A fresh look at the system analysis helped us in finding a new way of calculating the risks associated with the system. The author found that, due to the shortcomings of RPN, more researches needed to be done in this area to use RPNs as a new source of information for system risk analysis. It is the purpose of this article to investigate the fundamental concepts of failure modes and effects ana...
متن کاملFuzzy Risk Analysis Model for E-tourism Investment
This paper provides a Fuzzy based decision support system (DSS) for risk analysis in E-tourism ( Electronic Tourism ) investment. In general term, E-tourism is the use of information and communication technology (ICT) in tourism which may allow operating tourism in least variable cost, least time and increased work efficiency. It is worth noting that there are many factors that affect the deve...
متن کاملInformation Systems Risks and Risk Factors: Are They Mostly About Information Systems?
This article is the second of two whose goal is to advance the discussion of IS risk by addressing limitations of the current IS risk literature. The first article [Alter and Sherer, 2004] presented a general, but broadly adaptable model of system-related risk that addressed the limited usefulness of existing IS risk models for business managers. In this article, we focus on organizing risk fac...
متن کاملAN INTELLIGENT INFORMATION SYSTEM FOR FUZZY ADDITIVE MODELLING (HYDROLOGICAL RISK APPLICATION)
In this paper we propose and construct Fuzzy Algebraic Additive Model, for the estimation of risk in various fields of human activities or nature’s behavior. Though the proposed model is useful in a wide range of scientific fields, it was designed for to torrential risk evaluation in the area of river Evros. Clearly the model’s performance improves when the number of parameters and the actual d...
متن کاملInvestigating the risk-taking behavior of the banking industry in the form of the general equilibrium model of overlapping generations (OLG)
In this paper, using a general equilibrium model of overlapping generations, the impact of different financing plans of the banking industry on their risk-taking motivation is investigated. In the non-competitive banking industry, financing is done by imposing taxes on the older generation or the bankchr('39')s internal resources (bank shares). As an effective policy, this action optimizes soci...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- CAIS
دوره 14 شماره
صفحات -
تاریخ انتشار 2004