This essay has been submitted by a student. This is not an example of the work written by professional essay writers.
Uncategorized

Information System-Based Risks

Pssst… we can write an original essay just for you.

Any subject. Any type of essay. We’ll even meet a 3-hour deadline.

GET YOUR PRICE

writers online

Information System-Based Risks

 

Author Note

Information System-Based Risks

 Amraoui, S., Elmaallam, M., Bensaid, H., & Kriouile (2019). Information Systems Risk Management: Literature Review. Canada Center of Science and Education, June 17. https://doi.org/10.5539/cis.v12n3p1

After viewing Information Systems Risk Management, it emerges that the authors’ objectives were:

Bullet one: defining the concept of risk and illustrating its relations with information system and work system.

Bullet two: outlining the state of risk management in information systems basing on the reviewed literature.

Bullet three: Describing and analyzing the approaches used in managing risks in information systems.

Article Summary

The article Information Systems Risk Management presents a critical analysis of risk management in an information system.  According to Amraoui et al. (2019), the safety of the organizational information system remains relevant towards achieving a business objective. An analysis of this study presents valid definitions of the terms risk, information work system, and risk management as it aims at explaining the safety of information systems. The issue of IT risk mitigation also shaped this study as authors defined and classified IT threats. For instance, they asserted that IT threats often determines the best activities in the IT risk mitigation because it gives a framework for business to find, administrate, and control IT threats. The prevalence of risk mitigation approaches and recorded means that ISO 31000 standard has limitations that could hinder efficiency in risk management.

Amraoui et al. (2019) analyzed that IT risk management help to ensure quality IT services, gives IT solutions and gains from IS, and, more so, offers benefits from missed opportunities in technological development hence improving business programs. This article illustrates that risk management allows the company to protect the IS resources as it also prevents them from losing from the emergence of unwanted activities that could negatively influence both IS goals and methods. More so, risk management allows for adequate distribution of information system resources. The process of risk management evaluates specific happenings and the expected outcomes for a given company before making an action-oriented decision on risk reduction to a required level.

Results

The article undertook a comparative evaluation of the risk management procedures, approaches, and standards to find the suitable one to impact risk management in information systems both in context and areas of efficiency. After dividing this section into three criteria, the following outcomes emerged. Concerning the management operations, there was a completeness of risk management operations within the ratio of n/8, which symbolizes the number of risk mitigation strategies needed and verifies among the 8. Here, ISO 31000 prevailed as the quality operational procedure that could suitably mitigate the prevailing scenario.

In comparison with the above criterion, Amraoui et al. (2019) explain that the procedures proposed by the ISO 310000 could adequately cover this scenario. Besides, the ISO 31000 measure via the two structural features, namely organizational framework and principles, validates components of criterion 2, the Integration of IS Risk Management within the general corporate management. It prevailed that the management risk establishes and conserve values while its integration in the organizational activities allows compulsory achievement of the two objectives of the criterion in prevalence. Basing on literature from Amraoui et al. (2019), a company-based risk management model could permit the organization of risk mitigation towards a constant level of risks. Moreover, the organization’s risk appetite could have a significant influence on IT risk management. About criteria three, it emerged that the generic components of the 1SO 31000 risk mitigation enable it to apply to every category of systems, especially the IS, which is a working system with all parts. The utility endorsed by ISO 310000 verifies approach 4; Risk management support for every IS element. This episode prevails because the said entity incorporates the issues illustrated by ISO-2009 towards standardizing risk-based vocabulary. This concept also aligns with the AS/NZS 4360 measure as depicted by the industrial reality.

Critique & Opinion

The current literature has shown that despite this study endorsing ISO 31000 as the best solution for risk mitigation, it emerges that the authors failed to note down its flaws. According to Edirimanna (2019), this concept allows for a narrow range of procedures to help mitigate risks. This standard could lead to flaws due to its exclusion of objective formulation despite depending on the same (Edirimanna, 2019).  This author further states that, ISO 31000 standard is also not generally feasible and, more so, has a narrow language and illogical definitions of major terms. In my opinion, there is a need to replace the risk management process with the approaches that suit the consumer’s security needs. More so, I agree with Weeserik & Spruit (2018) that companies get rid of risk listing language within the standard, thereby removing the confusion between risk management and managing risks. At the same time, despite the ISO31000 concept influencing an effective integration of the most publicized fundamentals, managers need to use experience feedback such as organizational crises to inquire about how to integrate it into the organizational business models. Conclusively, there is a need to see risk management as a practice-based concept, what managers engage in, and not what they possess.

Question

What are the best frameworks that could help implement a useful and accurate risk mitigation process bearing in mind that the existing ones have the least integration with the corporate control systems exemplified by the strategic planning and control administration?

 

 

 

 

 

 

 

 

 

 

References

Amraoui, S., Elmaallam, M., Bensaid, H., & Kriouile (2019). Information Systems Risk Management: Literature Review. Canada Center of Science and Education, June 17. https://doi.org/10.5539/cis.v12n3p1

Edirimanna S., Anoma (2019). Enterprise Risk Management -International Standards and Frameworks. Australian College of Business & Technology, July 15. https//: DOI: 10.29322/IJSRP.9.07. 2019.p9130

Weeserik, P., B., & Spruit, M. (2018). Improving Operational Risk Management Using Business Performance Management Technologies. Department of Information and Computing Sciences, February 28. https://doi:10.3390/su10030640

 

 

  Remember! This is just a sample.

Save time and get your custom paper from our expert writers

 Get started in just 3 minutes
 Sit back relax and leave the writing to us
 Sources and citations are provided
 100% Plagiarism free
error: Content is protected !!
×
Hi, my name is Jenn 👋

In case you can’t find a sample example, our professional writers are ready to help you with writing your own paper. All you need to do is fill out a short form and submit an order

Check Out the Form
Need Help?
Dont be shy to ask