2014
DOI: 10.14738/tmlai.26.793
|View full text |Cite
|
Sign up to set email alerts
|

Development of the ISR3M model for IS risk management evaluation using the Focus Area structure according to the MMDPIS generic process

Abstract: Risk management (RM) is one of the main IS governance pillars. However, to remain a center of profit and cost optimization for the company, this activity must be evaluated, monitored and improved continuously. Hence the interest to develop an IS risk management maturity model. This paper aims to address this need by providing the ISR3M (Information System Risk Management Maturity Model) model. After a summary of literature review, it presents the design approach, then describes the model and evaluates it.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1

Citation Types

0
3
0

Year Published

2019
2019
2019
2019

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
(3 citation statements)
references
References 13 publications
0
3
0
Order By: Relevance
“…Managing the risks of an information system involves managing the risks of its nine axes in relation to their evaluation elements. According to Elmaallam and Kriouile (2015), the evaluation elements of each axis are identified through (1) the missions and requirements of the work system framework as defined in the literature (Alter and Sherer, 2004), ( 2) the application of the theory Resource Based-View (RBV) (Wade and Hulland, 2004) on IS defined as WS considering both dynamic resources such as skills, as static as the technical infrastructure, (3) the IS risk factors (Alter and Sherer, 2004) and ( 4) interviews with IS experts. Table 1 lists the evaluation elements for each component.…”
Section: Is Risk Managementmentioning
confidence: 99%
See 2 more Smart Citations
“…Managing the risks of an information system involves managing the risks of its nine axes in relation to their evaluation elements. According to Elmaallam and Kriouile (2015), the evaluation elements of each axis are identified through (1) the missions and requirements of the work system framework as defined in the literature (Alter and Sherer, 2004), ( 2) the application of the theory Resource Based-View (RBV) (Wade and Hulland, 2004) on IS defined as WS considering both dynamic resources such as skills, as static as the technical infrastructure, (3) the IS risk factors (Alter and Sherer, 2004) and ( 4) interviews with IS experts. Table 1 lists the evaluation elements for each component.…”
Section: Is Risk Managementmentioning
confidence: 99%
“…Indeed: (1) Communication is considered as an activity inherent to every phase of the process (Sienou, 2009), (2) the cycle of management preserves its iterative character, but no longer requires synchronization of all stages with a monitoring phase (Sienou, 2009) and (3) Treatment may be the cause of a new iteration process (Sienou, 2009). The development of ISR3M model should provide answers to the problem of assessing IS risk management from two perspectives (Elmaallam and Kriouile, 2015). The first perspective is academic.…”
Section: Improvement Plan Definition Algorithm: "Path Prerequisites"mentioning
confidence: 99%
See 1 more Smart Citation