A Common Terminology for Software Risk Management

Author:

Masso Jhon1ORCID,García Félix2ORCID,Pardo César3,Pino Francisco J.4,Piattini Mario2

Affiliation:

1. Alarcos Research Group, Institute of Technologies and Information Systems, University of Castilla-La Mancha, Spain and GTI Research Group. Electronic and Telecommunications Engineering Faculty, University of Cauca, Popayán, Cauca

2. Alarcos Research Group, Institute of Technologies and Information Systems, University of Castilla-La Mancha, Castilla la Mancha, Spain

3. GTI Research Group. Electronic and Telecommunications Engineering Faculty, University of Cauca, Popayán, Cauca, Colombia

4. IDIS Research Group. Electronic and Telecommunications Engineering Faculty, University of Cauca, Popayán, Cauca, Colombia

Abstract

In order to improve and sustain their competitiveness over time, organisations nowadays need to undertake different initiatives to adopt frameworks, models and standards that will allow them to align and improve their business processes. In spite of these efforts, organisations may still encounter governance and management problems. This is where Risk Management (RM) can play a major role, since its purpose is to contribute to the creation and preservation of value in the context of the organisation's processes. RM is a complex and subjective activity that requires experience and a high level of knowledge about risks, and it is for this reason that standardisation institutions and researchers have made great efforts to define initiatives to overcome these challenges. However, the RM field nevertheless presents a lack of uniformity in its terms and concepts, due to the different contexts and scopes of application, a situation that can generate ambiguities and misunderstandings. To address these issues, this paper aims to present an ontology called SRMO (Software Risk Management Ontology) , which seeks to unify the terms and concepts associated with RM and provide an integrated and holistic view of risk. In doing so, the Pipeline framework has been applied in order to assure and verify the quality of the proposed ontology, and it has been implemented in Protégé and validated by means of competency questions. Three application scenarios of this ontology demonstrating their usefulness in the software engineering field are presented in this paper. We believe that this ontology can be useful for organisations that are interested in: (i) establishing an RM strategy from an integrated approach, (ii) defining the elements that help to identify risks and the criteria that support decision-making in risk assessment, and (iii) helping the involved stakeholders during the process of risk management.

Funder

Ministerio de Ciencia, Innovación y Universidades, y Fondo Europeo de Desarrollo Regional FEDER

Consejería de Educación, Cultura y Deportes de la Junta de Comunidades de Castilla La Mancha, y Fondo Europeo de Desarrollo Regional FEDER

Publisher

Association for Computing Machinery (ACM)

Subject

Software

Reference136 articles.

1. Vivek Agrawal. 2016. Towards the ontology of ISO/IEC 27005: 2011 Risk management standard. In HAISA.

2. Towards an Ontology-based Risk Assessment in Collaborative Environment Using the SemanticLIFE

3. Silvia Ansaldi, Marina Monti, Patrizia Agnello, and Franca Giannini. 2012. An ontology for the identification of the most appropriate risk management methodology. In On the Move to Meaningful Internet Systems: OTM 2012 Workshops, Springer Berlin, Berlin, 444–453.

4. AS/NZS. 2004. AS/NZS 4360: 2004: Risk management. Standards Australia; Standards New Zealand Sydney.

5. Managing Successful Projects with PRINCE2® 2017

Cited by 2 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. The Risk-Taking Software Engineer: A Framed Portrait;2023 IEEE/ACM 45th International Conference on Software Engineering: New Ideas and Emerging Results (ICSE-NIER);2023-05

2. AIRO: An Ontology for Representing AI Risks Based on the Proposed EU AI Act and ISO Risk Management Standards;Towards a Knowledge-Aware AI;2022-09-06

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3