How to elicit processes for an ISO-based integrated risk management process reference model in IT settings?

2Citations
Citations of this article
20Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Process performance remains a key challenge in organizations. Improving processes can be guided by Capability Maturity Models resting on processes that can be assessed. Several ISO standards propose process models for Management System Standards, such as ISO 9001, ISO/IEC 20000-1 and ISO/IEC 27001, and project management proposes processes in ISO 21500. The ISO 31000 standard provides guidance for Risk management with a process approach and systemic perspective. This paper presents the approach for eliciting processes based on ISO 31000 as the main thread in a process reference model (PRM). This PRM integrates risk management dimensions with the selected ISO standards: ISO 9001, ISO 21500, ISO/IEC 20000-1 and ISO/IEC 27001.

Cite

CITATION STYLE

APA

Barafort, B., Mesquida, A. L., & Mas, A. (2017). How to elicit processes for an ISO-based integrated risk management process reference model in IT settings? In Communications in Computer and Information Science (Vol. 748, pp. 43–57). Springer Verlag. https://doi.org/10.1007/978-3-319-64218-5_4

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free