{"title":"A proposed framework: An appropriation for principle and practice in information technology risk management","authors":"Urairat Maneerattanasak, Nitaya Wongpinunwatana","doi":"10.1109/ICRIIS.2017.8002513","DOIUrl":null,"url":null,"abstract":"This study proposed the appropriation for principle and practice in information technology risk management (ITRM). Due to the various patterns of cyber threat against the advanced information systems and technologies, the well-practiced ITRM is expected from an organization's stakeholders. The well-established principle is the starting point of the practice. The methodology employed in this study is the theoretical review of relevant theories such as principle, practice and task-technology fit, and the review of general ITRM principle and framework documents. Additionally, content analysis method is applied to obtain keywords and classified into groups as derived success factors. The derived success factors for the appropriation consist of a suitable general principle and framework, an organization's well-established principle, a well-designed process, team structure, expertise of team, level of task complexity, and level of interdependence. Additionally, strong risk culture, good communication, training, and tools and techniques. The contribution of the proposed framework is to provide the factors for the appropriate assessment in ITRM principle development and practice.","PeriodicalId":384130,"journal":{"name":"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)","volume":"17 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICRIIS.2017.8002513","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
This study proposed the appropriation for principle and practice in information technology risk management (ITRM). Due to the various patterns of cyber threat against the advanced information systems and technologies, the well-practiced ITRM is expected from an organization's stakeholders. The well-established principle is the starting point of the practice. The methodology employed in this study is the theoretical review of relevant theories such as principle, practice and task-technology fit, and the review of general ITRM principle and framework documents. Additionally, content analysis method is applied to obtain keywords and classified into groups as derived success factors. The derived success factors for the appropriation consist of a suitable general principle and framework, an organization's well-established principle, a well-designed process, team structure, expertise of team, level of task complexity, and level of interdependence. Additionally, strong risk culture, good communication, training, and tools and techniques. The contribution of the proposed framework is to provide the factors for the appropriate assessment in ITRM principle development and practice.