Developing a Framework for Maturing IT Risk Management Capabilities

被引:0
|
作者
Carcary, Marian [1 ]
机构
[1] Natl Univ Ireland Maynooth, Innovat Value Inst, Maynooth, Kildare, Ireland
关键词
IT risks; IT risk management; maturity model; IT CMF; critical capability; DESIGN SCIENCE; INFORMATION;
D O I
暂无
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Understanding the value derived from IT investments and IT enabled operational improvements is difficult, and has been a subject of research and debate among ICT practitioners and academics for many years. This is particularly so because innovative technological developments have supported transformative changes in organizational operational activities. Research continues to investigate approaches to not only understanding the value derived by IT but also to optimizing this value. One of the key aspects of optimizing IT-driven value is the requirement to effectively manage risk. The continual evolution of the IT risk landscape requires effective Risk Management (RM) practices for all IT risk areas, such as, but not limited to security, investments, service contracts, data protection and information privacy. Effectively managing these risk areas pose specific concerns from the perspective of Chief Information Officers (CIOs) and Chief Risk Officers (CROs). Hence, significant considerations should be given to not only the processes involved in assessing, prioritizing, handling and monitoring these risks but also to ensuring the development of an appropriate risk culture and the establishment of effective RM governance structures, to support effective RM. This paper examines the maturity model/framework approach to improving an organization's IT capabilities, with specific reference to effectively managing IT-related risks, and increasing value derived over time. A new IT Risk Management maturity model is presented; this framework is part of the IT Capability Maturity Framework (IT CMF) which supports value-driven IT management practices. It was developed by the Innovation Value Institute at the National University of Ireland Maynooth, following a design science and open innovation research approach. The IT CMF, consisting of 33 Critical Capabilities, focuses on maturing key activities of the IT organization. The Risk Management Critical Capability presented in this paper enables organizations to determine their IT RM maturity and identify key recommendations in specific areas to improve maturity overtime. Thereafter the paper presents an analysis of the maturity model approach to managing risk, to improving an organization's IT capabilities, and to deriving enterprise-wide value from more mature IT practices.
引用
收藏
页码:33 / 40
页数:8
相关论文
共 50 条
  • [1] Risk management: developing a framework for a water authority
    Dalgleish, Fraser
    Cooper, Barry J.
    [J]. MANAGEMENT OF ENVIRONMENTAL QUALITY, 2005, 16 (03) : 235 - 249
  • [2] Developing a strategic flood risk management framework for Bangkok, Thailand
    Singkran, Nuanchan
    Kandasamy, Jaya
    [J]. NATURAL HAZARDS, 2016, 84 (02) : 933 - 957
  • [3] A Framework for Risk Management in Small Medium Enterprises in Developing Countries
    Mthiyane, Zodwa Z. F.
    van der Poll, Huibrecht M.
    Tshehla, Makgopa F.
    [J]. RISKS, 2022, 10 (09)
  • [4] Developing a risk management assessment framework for public administration in Taiwan
    She-I Chang
    Shi-Ming Huang
    Jinsheng Roan
    I-Cheng Chang
    Pu-Jui Liu
    [J]. Risk Management, 2014, 16 : 164 - 194
  • [5] Developing a risk management assessment framework for public administration in Taiwan
    Chang, She-I
    Huang, Shi-Ming
    Roan, Jinsheng
    Chang, I-Cheng
    Liu, Pu-Jui
    [J]. RISK MANAGEMENT-AN INTERNATIONAL JOURNAL, 2014, 16 (03): : 164 - 194
  • [6] Developing a strategic flood risk management framework for Bangkok, Thailand
    Nuanchan Singkran
    Jaya Kandasamy
    [J]. Natural Hazards, 2016, 84 : 933 - 957
  • [7] Developing a Risk Management Framework in Construction Project Based on Agile Management Approach
    Ahmed, Mohammed Neamah
    Mohammed, Sawsan Rasheed
    [J]. CIVIL ENGINEERING JOURNAL-TEHRAN, 2019, 5 (03): : 608 - 615
  • [8] Developing program management capabilities - A knowledge management perspective
    Owen, Jill
    [J]. Organisational Challenges for Knowledge Management, 2005, : 172 - 185
  • [9] Organisational learning without fire? Risk analyses as a basis for developing crisis management capabilities
    Eriksson, Kerstin
    [J]. SAFETY SCIENCE, 2023, 163
  • [10] BPM promotion framework for startups: developing dynamic capabilities
    Almeida de Souza Santos, Ana Augusta
    Dallavalle de Padua, Silvia Ines
    [J]. BUSINESS PROCESS MANAGEMENT JOURNAL, 2023, 29 (01) : 140 - 158