A Common Terminology for Software Risk Management

被引:4
|
作者
Masso, Jhon [1 ,2 ]
Garcia, Felix [1 ]
Pardo, Cesar [2 ]
Pino, Francisco J. [3 ]
Piattini, Mario [1 ]
机构
[1] Univ Castilla La Mancha, Inst Technol & Informat Syst, Alarcos Res Grp, Ciudad Real 13071, Castilla La Man, Spain
[2] Univ Cauca, Elect & Telecommun Engn Fac, GTI Res Grp, Calle 5 4-70, Popayan 190002, Cauca, Colombia
[3] Univ Cauca, IDIS Res Grp, Elect & Telecommun Engn Fac, Calle 5 4-70, Popayan 190002, Cauca, Colombia
关键词
Risk management; integrated risk management; risk ontology; ISO; 31000; ISO; 31000; ONTOLOGY; INFORMATION; PRINCIPLES; STANDARDS; FRAMEWORK; MATURITY; PROJECTS; SUCCESS; DESIGN;
D O I
10.1145/3498539
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In order to improve and sustain their competitiveness over time, organisations nowadays need to undertake different initiatives to adopt frameworks, models and standards that will allow them to align and improve their business processes. In spite of these efforts, organisations may still encounter governance and management problems. This is where Risk Management (RM) can play a major role, since its purpose is to contribute to the creation and preservation of value in the context of the organisation's processes. RM is a complex and subjective activity that requires experience and a high level of knowledge about risks, and it is for this reason that standardisation institutions and researchers have made great efforts to define initiatives to overcome these challenges. However, the RM field nevertheless presents a lack of uniformity in its terms and concepts, due to the different contexts and scopes of application, a situation that can generate ambiguities and misunderstandings. To address these issues, this paper aims to present an ontology called SRMO (Software RiskManagement Ontology), which seeks to unify the terms and concepts associated with RM and provide an integrated and holistic view of risk. In doing so, the Pipeline framework has been applied in order to assure and verify the quality of the proposed ontology, and it has been implemented in Protege and validated by means of competency questions. Three application scenarios of this ontology demonstrating their usefulness in the software engineering field are presented in this paper. We believe that this ontology can be useful for organisations that are interested in: (i) establishing an RM strategy from an integrated approach, (ii) defining the elements that help to identify risks and the criteria that support decision-making in risk assessment, and (iii) helping the involved stakeholders during the process of risk management.
引用
收藏
页数:47
相关论文
共 50 条
  • [21] A Critical Analysis of Software Risk Management Techniques in Large Scale Systems
    Pasha, Maruf
    Qaiser, Ghazia
    Pasha, Urooj
    IEEE ACCESS, 2018, 6 : 12412 - 12424
  • [22] An Investigation of Software Development Process Terminology
    Clarke, Paul
    Mesquida, Antoni-Lluis
    Ekert, Damjan
    Ekstrom, J. J.
    Gornostaja, Tatjana
    Jovanovic, Milos
    Johansen, Jorn
    Mas, Antonia
    Messnarz, Richard
    Villar, Blanca Najera
    O'Connor, Alexander
    O'Connor, Rory V.
    Reiner, Michael
    Sauberer, Gabriele
    Schmitz, Klaus-Dirk
    Yilmaz, Murat
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION (SPICE 2016), 2016, 609 : 351 - 361
  • [23] Study on Risk Management of Management Information System Software Project
    Wang Wensheng
    Zhao Yanmei
    Zhang Chengyi
    ADVANCES IN MANAGEMENT OF TECHNOLOGY, PT 1, 2008, : 192 - +
  • [24] Automated Risk Management Based Software Security Vulnerabilities Management
    Althar, Raghavendra Rao
    Samanta, Debabrata
    Kaur, Manjit
    Singh, Dilbag
    Lee, Heung-No
    IEEE ACCESS, 2022, 10 : 90597 - 90608
  • [25] Integrating software effort estimation with risk management
    Singal, Prerna
    Sharma, Prabha
    Kumari, A. Charan
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2022, 13 (05) : 2413 - 2428
  • [26] Agile risk management using software agents
    Odzaly, Edzreena Edza
    Greer, Des
    Stewart, Darryl
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2018, 9 (03) : 823 - 841
  • [27] Risk Exposure and Management in Software Development - A Survey of Multiple Software Startups
    Kazemi, Gholamhossein
    Cico, Orges
    Quang-Trung Nguyen
    Anh Nguyen-Quang
    SOFTWARE BUSINESS (ICSOB 2021), 2021, 434 : 98 - 104
  • [28] A novel approach to software quality risk management
    Bubevski, Vojo
    Software Testing Verification and Reliability, 2014, 24 (02) : 124 - 154
  • [29] Software Risk Management Barriers: an Empirical Study
    Odzaly, Edzreena Edza
    Greer, Des
    Sage, Paul
    ESEM: 2009 3RD INTERNATIONAL SYMPOSIUM ON EMPIRICAL SOFTWARE ENGINEERING AND MEASUREMENT, 2009, : 419 - 422
  • [30] Integrating software effort estimation with risk management
    Prerna Singal
    Prabha Sharma
    A. Charan Kumari
    International Journal of System Assurance Engineering and Management, 2022, 13 : 2413 - 2428