A conceptual model for enterprise risk management

被引:21
作者
Almeida, Rafael [1 ]
Teixeira, Jose Miguel [2 ]
da Silva, Miguel Mira [1 ]
Faroleiro, Paulo [1 ]
机构
[1] Univ Lisbon, Inst Super Tecn, Lisbon, Portugal
[2] Compta, Dept Business Serv Management, Lisbon, Portugal
关键词
Risk management; Conceptual modelling; Enterprise architecture; Archimate; ISO; 31000; DESIGN SCIENCE RESEARCH; INTEGRATION; STANDARD;
D O I
10.1108/JEIM-05-2018-0097
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Purpose The purpose of this paper is to ease the ISO 31000 standard understanding and provide mechanisms that allow organizations to adopt and adapt this standard to their reality. Design/methodology/approach The research methodology adopted in this research was the design science research methodology. Findings Key finding is that enterprise architecture (EA) models and EA tools can help reduce the complexity of the ISO 31000 standard and improve the communication between stakeholders. Practical implications - The research proposal serves the purpose of supporting the evidence collection for an enterprise risk management (ERM) initiative in an as-was, as-is, or to-be perspective. Originality/value Traditional ERM efforts operate on silos, limiting the sharing of risk information and the achievement of an organization-wide view of risks. EA can provide a common way to model complex business systems, from the strategic level to implementation details. This paper proposes the use of an EA model and an EA tool (Atlas) to represent ISO 31000, allowing a better understanding on the value of assets that can be affected from the manifestation of some risks over time.
引用
收藏
页码:843 / 868
页数:26
相关论文
共 41 条
[1]  
Abu el Ata N., 2016, TYRANNY UNCERTAINTY, P3
[2]  
Almeida R., 2016, P 13 EUR MED MIDDL E
[3]  
Almeida R., 2016, INT C INF SYST DEV I
[4]  
[Anonymous], 2017, RES ACT THEORETICAL
[5]  
[Anonymous], ENTERPRISE ARCHITECT
[6]   On the new ISO guide on risk management terminology [J].
Aven, Terje .
RELIABILITY ENGINEERING & SYSTEM SAFETY, 2011, 96 (07) :719-726
[7]  
Baranoff E.G., 2001, RISK MANAGEMENT INSU, V4, P51
[8]  
Bartens Y., 2014, P ANN HAW INT C SYST
[9]   Socio-technical IS design science research: developing design theory for IS integration management [J].
Carlsson, Sven A. ;
Henningsson, Stefan ;
Hrastinski, Stefan ;
Keller, Christina .
INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2011, 9 (01) :109-131
[10]  
Dali A., 2012, EDPACS, V45, P1, DOI [10.1080/07366981.2012.682494, DOI 10.1080/07366981.2012.682494]