首页    期刊浏览 2024年10月07日 星期一
登录注册

文章基本信息

  • 标题:New Developments in Practice I: Risk Management in Information Systems: Problems and Potential
  • 本地全文:下载
  • 作者:Smith, Heather A. ; McKeen, James D. ; Staples, Sandy
  • 期刊名称:Communications of the Association for Information Systems
  • 印刷版ISSN:1529-3181
  • 出版年度:2001
  • 卷号:7
  • 期号:1
  • 页码:13
  • 出版社:Association for Information Systems
  • 摘要:Risk management can be an extremely powerful approach to dealing with the complexities and uncertainties that increasingly surround technological change and its management. Conventionally in information technology (IT) projects, risks have been narrowly defined. Today, with IT becoming integral to a company's existence, the stakes are considerably higher and broader in scope. However, risk is sometimes seen a negative concept in information systems (IS) organizations because it implies that something could go wrong with an IT project. To understand effective risk management in IS, the authors convened a focus group of senior IS managers from a number of organizations in a variety of industries. The results of this discussion, the managers' presentations, and a review of the current research on risk management, were integrated and are presented in this paper. The nature of risk, identifying risk in IT initiatives, determining appropriate levels of risk, and dealing with unacceptable types and levels of risk are discussed. The following conclusions were reached. Risk management is a means to an end - whether it is a successful IS project; stable, secure technical operations; or a properly implemented business strategy using technology. It is not a one-time activity, but rather an ongoing process of identification, assessment, and action, which needs to be well integrated into every part of IS management. IS managers must learn to control both the problems and the potential that risk represents. Several general principles to help IS managers deal effectively with risks were identified. Effective risk management involves taking a holistic approach to risk, developing a risk management policy, establishing clear accountabilities and responsibilities, balancing risk exposure against controls, being open about risks to reduce conflict and information hiding, enforcing risk management practices, and learning what works and doesn't from past experience.
国家哲学社会科学文献中心版权所有