{"title":"对IT风险管理过程的实际看法","authors":"Maksim Goman","doi":"10.1145/3360664.3360730","DOIUrl":null,"url":null,"abstract":"Risk management (RM) process is one of the key aspects in IT management standards. However, additionally to the existing ambiguity about risk concept in IT management standards and guidelines, IT RM process is usually very simplistic and brief. We propose an improved IT RM process in this paper. The enchanced process is based on an advanced definition of risk and its consequences.","PeriodicalId":409365,"journal":{"name":"Proceedings of the Third Central European Cybersecurity Conference","volume":"115 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A practical view on IT risk management process\",\"authors\":\"Maksim Goman\",\"doi\":\"10.1145/3360664.3360730\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Risk management (RM) process is one of the key aspects in IT management standards. However, additionally to the existing ambiguity about risk concept in IT management standards and guidelines, IT RM process is usually very simplistic and brief. We propose an improved IT RM process in this paper. The enchanced process is based on an advanced definition of risk and its consequences.\",\"PeriodicalId\":409365,\"journal\":{\"name\":\"Proceedings of the Third Central European Cybersecurity Conference\",\"volume\":\"115 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-11-14\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the Third Central European Cybersecurity Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3360664.3360730\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the Third Central European Cybersecurity Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3360664.3360730","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Risk management (RM) process is one of the key aspects in IT management standards. However, additionally to the existing ambiguity about risk concept in IT management standards and guidelines, IT RM process is usually very simplistic and brief. We propose an improved IT RM process in this paper. The enchanced process is based on an advanced definition of risk and its consequences.