A Common Terminology for Software Risk Management

被引:4
作者
Masso, Jhon [1 ,2 ]
Garcia, Felix [1 ]
Pardo, Cesar [2 ]
Pino, Francisco J. [3 ]
Piattini, Mario [1 ]
机构
[1] Univ Castilla La Mancha, Inst Technol & Informat Syst, Alarcos Res Grp, Ciudad Real 13071, Castilla La Man, Spain
[2] Univ Cauca, Elect & Telecommun Engn Fac, GTI Res Grp, Calle 5 4-70, Popayan 190002, Cauca, Colombia
[3] Univ Cauca, IDIS Res Grp, Elect & Telecommun Engn Fac, Calle 5 4-70, Popayan 190002, Cauca, Colombia
关键词
Risk management; integrated risk management; risk ontology; ISO; 31000; ISO; 31000; ONTOLOGY; INFORMATION; PRINCIPLES; STANDARDS; FRAMEWORK; MATURITY; PROJECTS; SUCCESS; DESIGN;
D O I
10.1145/3498539
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In order to improve and sustain their competitiveness over time, organisations nowadays need to undertake different initiatives to adopt frameworks, models and standards that will allow them to align and improve their business processes. In spite of these efforts, organisations may still encounter governance and management problems. This is where Risk Management (RM) can play a major role, since its purpose is to contribute to the creation and preservation of value in the context of the organisation's processes. RM is a complex and subjective activity that requires experience and a high level of knowledge about risks, and it is for this reason that standardisation institutions and researchers have made great efforts to define initiatives to overcome these challenges. However, the RM field nevertheless presents a lack of uniformity in its terms and concepts, due to the different contexts and scopes of application, a situation that can generate ambiguities and misunderstandings. To address these issues, this paper aims to present an ontology called SRMO (Software RiskManagement Ontology), which seeks to unify the terms and concepts associated with RM and provide an integrated and holistic view of risk. In doing so, the Pipeline framework has been applied in order to assure and verify the quality of the proposed ontology, and it has been implemented in Protege and validated by means of competency questions. Three application scenarios of this ontology demonstrating their usefulness in the software engineering field are presented in this paper. We believe that this ontology can be useful for organisations that are interested in: (i) establishing an RM strategy from an integrated approach, (ii) defining the elements that help to identify risks and the criteria that support decision-making in risk assessment, and (iii) helping the involved stakeholders during the process of risk management.
引用
收藏
页数:47
相关论文
共 50 条
  • [41] Consistency and conflict in terminology in software engineering standards
    Rout, TP
    FOURTH IEEE INTERNATIONAL SYMPOSIUM AND FORUM ON SOFTWARE ENGINEERING STANDARDS - PROCEEDINGS, 1999, : 67 - 74
  • [42] A Study on Software Risk Management Strategies and Mapping with SDLC
    Roy, Bibhash
    Dasgupta, Ranjan
    Chaki, Nabendu
    ADVANCED COMPUTING AND SYSTEMS FOR SECURITY, VOL 2, 2016, 396 : 121 - 138
  • [43] Risking: A Game for Teaching Risk Management in Software Projects
    Santos, Sebastido
    Carvalho, Flavia
    Costa, Yandson
    Viana, Davi
    Rivero, Luis
    SBQS: PROCEEDINGS OF THE 18TH BRAZILIAN SYMPOSIUM ON SOFTWARE QUALITY, 2019, : 188 - 197
  • [44] Outsource evaluation and selection in software outsourcing risk management
    Wang, MY
    Proceedings of the 2005 International Conference on Management Science and Engineering, 2005, : 643 - 651
  • [45] Risk Management in Agile Software Development: a Comparative Study
    Albadarneh, Aalaa
    Albadarneh, Israa
    Qusef, Abdallah
    2015 IEEE JORDAN CONFERENCE ON APPLIED ELECTRICAL ENGINEERING AND COMPUTING TECHNOLOGIES (AEECT), 2015,
  • [46] Gamification Proposal for a Software Engineering Risk Management Course
    Uyaguari, Fernando Uyaguari
    Intriago, Monserrate
    Jacome, Elizabeth Salazar
    NEW CONTRIBUTIONS IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, PT 1, 2015, 353 : 795 - 802
  • [47] Knowledge packaging supporting risk management in software processes
    Ardimento, Pasquale
    Boffoli, Nicola
    Cimitile, Marta
    Persico, Aldo
    Tammaro, Aldo
    PROCEEDINGS OF THE 10TH IASTED INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND APPLICATIONS, 2006, : 127 - +
  • [48] Providing for continuous risk management in distributed software projects
    Górski, J
    Miler, J
    ARTIFICIAL INTELLIGENCE AND SECURITY IN COMPUTING SYSTEMS, 2003, 752 : 271 - 281
  • [49] Research on Risk Analysis and Management in the Software Development Process
    Huang, Quanzhou
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON EDUCATION, MANAGEMENT, INFORMATION AND MEDICINE (EMIM 2015), 2015, 8 : 1294 - 1298
  • [50] Strategies for Scheduling Risk Mitigation in Software Project Management
    Zhou, Peng
    Leung, Hareton K. N.
    SOFTWARE TECHNOLOGIES (ICSOFT 2013), 2014, 457 : 3 - 23