Integrating risk management in IT settings from ISO standards and management systems perspectives

Show simple item record

dc.contributor.author Barafort, B.
dc.contributor.author Mesquida, A.L.
dc.contributor.author Mas, A.
dc.date.accessioned 2025-05-22T10:42:13Z
dc.date.available 2025-05-22T10:42:13Z
dc.identifier.citation Barafort, B., Mesquida, A.L. i Mas, A. (2016). Integrating risk management in IT settings from ISO standards and management systems perspectives. Computer Standards & Interfaces, 54(3), 176-185. http://dx.doi.org/10.1016/j.csi.2016.11.010 ca
dc.identifier.uri http://hdl.handle.net/11201/170280
dc.description.abstract [eng] Organizational capabilities in companies, within IT settings, can be strengthened by a centralized and integrated risk management approach based on ISO standards. This paper analyses risk management activities throughout various selected ISO standards in order to provide the basis to improve, coordinate and interoperate risk management activities in IT settings for various purposes related to quality management, project management, IT service management and information security management. Taking as a basis the ISO 31000 international standard for risk management, a comparison is performed with the aim of identifying risk management related activities in the ISO high level structure for management system standards, ISO 9001, ISO 21500, ISO/IEC 20000-1 and ISO/IEC 27001. These standards are of high interest for practitioners in IT settings, benefitting from the integration of process-based activities, implementing mechanisms for linking IT and non-IT entities of their organization with risk management challenges to address. Integration vectors such as the understanding of the organisation and its context, risk-based thinking, leadership and commitment, process approach and PDCA structure are elicited. en
dc.format application/pdf en
dc.format.extent 176-185
dc.publisher Elsevier
dc.relation.ispartof Computer Standards & Interfaces, 2016, vol. 54, num. 3, p. 176-185
dc.rights all rights reserved
dc.subject.classification 004 - Informàtica ca
dc.subject.other 004 - Computer Science and Technology. Computing. Data processing en
dc.title Integrating risk management in IT settings from ISO standards and management systems perspectives en
dc.type info:eu-repo/semantics/article
dc.type info:eu-repo/semantics/publishedVersion
dc.type Article
dc.date.updated 2025-05-22T10:42:14Z
dc.date.embargoEndDate info:eu-repo/date/embargoEnd/2100-01-01
dc.subject.keywords Management system en
dc.subject.keywords Risk management en
dc.subject.keywords ISO standards en
dc.subject.keywords Integrated risk management en
dc.rights.accessRights info:eu-repo/semantics/closedAccess
dc.identifier.doi http://dx.doi.org/10.1016/j.csi.2016.11.010


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search Repository


Advanced Search

Browse

My Account

Statistics