MULTIPLE CRITERIA ANALYSIS FOR EVALUATION OF INFORMATION SYSTEM RISK

被引:8
|
作者
Olson, David L. [1 ]
Wu, Desheng Dash [2 ,3 ]
机构
[1] Univ Nebraska, Dept Management, Lincoln, NE 68583 USA
[2] Univ Toronto, RiskLab, Toronto, ON M5S 3E6, Canada
[3] Univ Toronto, RiskChina Res Ctr, Toronto, ON M5S 3E6, Canada
关键词
Enterprise risk management; Information technology risks; enterprise systems; multiple criteria; DEA (Data Envelopment Analysis); PCA (Principal Component Analysis);
D O I
10.1142/S021759591100303X
中图分类号
C93 [管理学]; O22 [运筹学];
学科分类号
070105 ; 12 ; 1201 ; 1202 ; 120202 ;
摘要
Information technology (IT) involve a wide set of risks. Enterprise information systems are a major developing form of information technology involving their own set of risks, thus creating potential blind spots. This paper describes risk management issues involved in enterprise resource planning systems (ERP) which have high impact on organizations due to their high cost, and their pervasive impact on organizational operations. Alternative means of acquiring ERP systems, to include outsourcing to application service providers (ASPs) are available. But outsourcing ERP involves many risks that are often overlooked. After identification of typical risks involved with representative alternative forms of ERP, multiple criteria analysis is proposed as a useful tool for tradeoff analysis in this selection decision. SMART is compared with popular approaches such as DEA and PCA-based DEA. A demonstration of how multiple criteria analysis can be applied in the international ERP alternative selection decision is given by including outsourcing to China and South Korea.
引用
收藏
页码:25 / 39
页数:15
相关论文
共 50 条