A conceptual model for enterprise risk management

被引:20
|
作者
Almeida, Rafael [1 ]
Teixeira, Jose Miguel [2 ]
da Silva, Miguel Mira [1 ]
Faroleiro, Paulo [1 ]
机构
[1] Univ Lisbon, Inst Super Tecn, Lisbon, Portugal
[2] Compta, Dept Business Serv Management, Lisbon, Portugal
关键词
Risk management; Conceptual modelling; Enterprise architecture; Archimate; ISO; 31000; DESIGN SCIENCE RESEARCH; INTEGRATION; STANDARD;
D O I
10.1108/JEIM-05-2018-0097
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Purpose The purpose of this paper is to ease the ISO 31000 standard understanding and provide mechanisms that allow organizations to adopt and adapt this standard to their reality. Design/methodology/approach The research methodology adopted in this research was the design science research methodology. Findings Key finding is that enterprise architecture (EA) models and EA tools can help reduce the complexity of the ISO 31000 standard and improve the communication between stakeholders. Practical implications - The research proposal serves the purpose of supporting the evidence collection for an enterprise risk management (ERM) initiative in an as-was, as-is, or to-be perspective. Originality/value Traditional ERM efforts operate on silos, limiting the sharing of risk information and the achievement of an organization-wide view of risks. EA can provide a common way to model complex business systems, from the strategic level to implementation details. This paper proposes the use of an EA model and an EA tool (Atlas) to represent ISO 31000, allowing a better understanding on the value of assets that can be affected from the manifestation of some risks over time.
引用
收藏
页码:843 / 868
页数:26
相关论文
共 50 条
  • [2] An integrated conceptual model for information system security risk management supported by enterprise architecture management
    Mayer, Nicolas
    Aubert, Jocelyn
    Grandry, Eric
    Feltus, Christophe
    Goettelmann, Elio
    Wieringa, Roel
    SOFTWARE AND SYSTEMS MODELING, 2019, 18 (03): : 2285 - 2312
  • [3] An integrated conceptual model for information system security risk management supported by enterprise architecture management
    Nicolas Mayer
    Jocelyn Aubert
    Eric Grandry
    Christophe Feltus
    Elio Goettelmann
    Roel Wieringa
    Software & Systems Modeling, 2019, 18 : 2285 - 2312
  • [4] Conceptual Integration of Enterprise Architecture Management and Security Risk Management
    Grandry, Eric
    Feltus, Christophe
    Dubois, Eric
    17TH IEEE INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE WORKSHOPS (EDOCW 2013), 2013, : 114 - 123
  • [5] Enterprise Risk Management: Its Origins and Conceptual Foundation
    Gerry Dickinson
    The Geneva Papers on Risk and Insurance - Issues and Practice, 2001, 26 : 360 - 366
  • [6] Enterprise risk management: Its origins and conceptual foundation
    Dickinson, G
    GENEVA PAPERS ON RISK AND INSURANCE-ISSUES AND PRACTICE, 2001, 26 (03): : 360 - 366
  • [7] Enterprise Risk Management and Value Creation: A Conceptual Framework
    Sprcic, Danijela Milos
    INNOVATION MANAGEMENT AND EDUCATION EXCELLENCE THROUGH VISION 2020, VOLS I -XI, 2018, : 1360 - 1368
  • [8] Enterprise Risk Management Maturity, Entrepreneurial Orientation and Business Performance: Building of A Conceptual Model
    Dvorski Lackovic, Ivana
    Milos Sprcic, Danijela
    EDUCATION EXCELLENCE AND INNOVATION MANAGEMENT: A 2025 VISION TO SUSTAIN ECONOMIC DEVELOPMENT DURING GLOBAL CHALLENGES, 2020, : 7384 - 7399
  • [9] An Integrated Conceptual Model for Information System Security Risk Management and Enterprise Architecture Management Based on TOGAF
    Mayer, Nicolas
    Aubert, Jocelyn
    Grandry, Eric
    Feltus, Christophe
    PRACTICE OF ENTERPRISE MODELING, POEM 2016, 2016, 267 : 353 - 361
  • [10] Enterprise risk management: Coping with model risk
    Wu, De Heng Dash
    Olson, David L.
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON RISK MANAGEMENT AND ENGINEERING MANAGEMENT, 2008, : 1 - 13