A Common Terminology for Software Risk Management

被引:4
|
作者
Masso, Jhon [1 ,2 ]
Garcia, Felix [1 ]
Pardo, Cesar [2 ]
Pino, Francisco J. [3 ]
Piattini, Mario [1 ]
机构
[1] Univ Castilla La Mancha, Inst Technol & Informat Syst, Alarcos Res Grp, Ciudad Real 13071, Castilla La Man, Spain
[2] Univ Cauca, Elect & Telecommun Engn Fac, GTI Res Grp, Calle 5 4-70, Popayan 190002, Cauca, Colombia
[3] Univ Cauca, IDIS Res Grp, Elect & Telecommun Engn Fac, Calle 5 4-70, Popayan 190002, Cauca, Colombia
关键词
Risk management; integrated risk management; risk ontology; ISO; 31000; ISO; 31000; ONTOLOGY; INFORMATION; PRINCIPLES; STANDARDS; FRAMEWORK; MATURITY; PROJECTS; SUCCESS; DESIGN;
D O I
10.1145/3498539
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In order to improve and sustain their competitiveness over time, organisations nowadays need to undertake different initiatives to adopt frameworks, models and standards that will allow them to align and improve their business processes. In spite of these efforts, organisations may still encounter governance and management problems. This is where Risk Management (RM) can play a major role, since its purpose is to contribute to the creation and preservation of value in the context of the organisation's processes. RM is a complex and subjective activity that requires experience and a high level of knowledge about risks, and it is for this reason that standardisation institutions and researchers have made great efforts to define initiatives to overcome these challenges. However, the RM field nevertheless presents a lack of uniformity in its terms and concepts, due to the different contexts and scopes of application, a situation that can generate ambiguities and misunderstandings. To address these issues, this paper aims to present an ontology called SRMO (Software RiskManagement Ontology), which seeks to unify the terms and concepts associated with RM and provide an integrated and holistic view of risk. In doing so, the Pipeline framework has been applied in order to assure and verify the quality of the proposed ontology, and it has been implemented in Protege and validated by means of competency questions. Three application scenarios of this ontology demonstrating their usefulness in the software engineering field are presented in this paper. We believe that this ontology can be useful for organisations that are interested in: (i) establishing an RM strategy from an integrated approach, (ii) defining the elements that help to identify risks and the criteria that support decision-making in risk assessment, and (iii) helping the involved stakeholders during the process of risk management.
引用
收藏
页数:47
相关论文
共 50 条
  • [1] Risk Management Terminology
    Luko, Stephen N.
    QUALITY ENGINEERING, 2013, 25 (03) : 292 - 297
  • [2] Information security risk management terminology and key concepts
    Schmidt, Michael
    RISK MANAGEMENT-AN INTERNATIONAL JOURNAL, 2023, 25 (01):
  • [3] Risk management in the software life cycle: A systematic literature review
    Masso, Jhon
    Pino, Francisco J.
    Pardo, Cesar
    Garcia, Felix
    Piattini, Mario
    COMPUTER STANDARDS & INTERFACES, 2020, 71
  • [4] Risk terminology -: a platform for common understanding and better communication
    Christensen, FM
    Andersen, O
    Duijm, NJ
    Harremoës, P
    JOURNAL OF HAZARDOUS MATERIALS, 2003, 103 (03) : 181 - 203
  • [5] Design and Development of Ontology for Risk Management in Software Project Management
    Robin, C. R. Rene
    Uma, G. V.
    COMPUTING, COMMUNICATION, AND CONTROL, 2011, 1 : 253 - 257
  • [6] Reviews of standards and related material: Risk management terminology
    Luko, S.N. (stephen.luko@utas.utc.com), 1600, Bellwether Publishing, Ltd. (25): : 292 - 297
  • [7] Involving user perspective in a software risk management process
    Lindholm, Christin
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2015, 27 (12) : 953 - 975
  • [8] Information security risk management terminology and key concepts
    Michael Schmidt
    Risk Management, 2023, 25
  • [9] Risk Assessment Myth Busters: Defining Risk Management Processes and Terminology
    Roberts, Daniel
    Graves, Rene
    IEEE INDUSTRY APPLICATIONS MAGAZINE, 2020, 26 (03) : 22 - 28
  • [10] Risk and risk management in software projects: A reassessment
    Bannerman, Paul L.
    JOURNAL OF SYSTEMS AND SOFTWARE, 2008, 81 (12) : 2118 - 2133