An Applied Risk Identification Approach in the ICT Governance and Management Macroprocesses of a Brazilian Federal Government Agency

E. Canedo, A. Vale, Rogério Machado Gravina, R. L. Patrão, Leomar Camargo de Souza, Vinicius Eloy dos Reis, Fábio L. L. Mendonça, Rafael Timóteo de Sousa Júnior
{"title":"An Applied Risk Identification Approach in the ICT Governance and Management Macroprocesses of a Brazilian Federal Government Agency","authors":"E. Canedo, A. Vale, Rogério Machado Gravina, R. L. Patrão, Leomar Camargo de Souza, Vinicius Eloy dos Reis, Fábio L. L. Mendonça, Rafael Timóteo de Sousa Júnior","doi":"10.5220/0010475902720279","DOIUrl":null,"url":null,"abstract":"The process of identifying and managing Information and Communication Technology (ICT) risks has become a concern and a challenge for public and private organizations. In this context, risk management methodologies within the Brazilian Federal Public Administration organizations have become indispensable to help the managers of these organizations in decision making, especially in the distribution of public funds, elaboration of public policies focused on transparency, social actions contemplating indemnities, and social benefits, among others. In addition, the various ICT projects controlled by the public administration need a methodology to perform their management of ICT resources. In this article, we present the Governance and Risk Management methodology used to model the Administrative Council for Economic Defense (CADE) macro processes. The proposed methodology used the risk management process aligned to the ISO 31000 standards. This alignment was necessary for mapping CADE’s risk events, regardless of their complexity. The modeled ICT risk processes will support the organization’s managers in decision making and may be used or customized by any other organization of the Brazilian Federal Public Administration.","PeriodicalId":271024,"journal":{"name":"International Conference on Enterprise Information Systems","volume":"27 1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-04-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference on Enterprise Information Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5220/0010475902720279","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The process of identifying and managing Information and Communication Technology (ICT) risks has become a concern and a challenge for public and private organizations. In this context, risk management methodologies within the Brazilian Federal Public Administration organizations have become indispensable to help the managers of these organizations in decision making, especially in the distribution of public funds, elaboration of public policies focused on transparency, social actions contemplating indemnities, and social benefits, among others. In addition, the various ICT projects controlled by the public administration need a methodology to perform their management of ICT resources. In this article, we present the Governance and Risk Management methodology used to model the Administrative Council for Economic Defense (CADE) macro processes. The proposed methodology used the risk management process aligned to the ISO 31000 standards. This alignment was necessary for mapping CADE’s risk events, regardless of their complexity. The modeled ICT risk processes will support the organization’s managers in decision making and may be used or customized by any other organization of the Brazilian Federal Public Administration.
巴西联邦政府机构信息通信技术治理和管理宏观过程中的应用风险识别方法
识别和管理信息和通信技术(ICT)风险的过程已成为公共和私人组织的关注和挑战。在这方面,巴西联邦公共行政组织内部的风险管理方法已成为帮助这些组织的管理人员进行决策,特别是在分配公共资金、拟订以透明度为重点的公共政策、考虑赔偿和社会福利的社会行动等方面不可或缺的方法。此外,公共行政部门控制的各种信息和通信技术项目需要一种方法来管理信息和通信技术资源。在本文中,我们介绍了用于模拟经济防御行政委员会(CADE)宏观过程的治理和风险管理方法。建议的方法使用与ISO 31000标准一致的风险管理过程。这种对齐对于映射CADE的风险事件是必要的,而不管它们的复杂性如何。建模的ICT风险流程将支持该组织的管理人员进行决策,并可由巴西联邦公共行政的任何其他组织使用或定制。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信