A Framework for Implementation of Risk Management System in third Party managed Cloud
Adeniran Solomon Abiodun
Abstract
Adeniran Solomon Abiodun
Abstract
A lot of research has been carried out in the field of risk management, as well as IT auditing, however risks and operation of information and data still threaten organizations processes and activities. Also, these two disciplines have been discretely managed and researched in the industry and academic, respectively. It therefore will be of importance to investigate the interface between the two disciplines. The purpose of this research is to investigate and understand audit and risk management system in the information technology environment. To lay a foundation for a discussion of the role of information systems in risk management, we must first define and understand the needs that drive organizations to implement risk management functions (Gibson, 1997). Information System (IS) was introduced to the business as a means of improving operational efficiency. It was initially used as a tool only for performing organisations operations, now it is a very important aspect of an organisation’s existence and survival, no operation can be carried out in an organisation without IS. Therefore we have to place an emphasis on IS risk management. The disruption of operations can also become more Important than the replacement of IS assets. Due to the costly cost of delays brought about by breakdown of IS which sometimes is caused by negligence and malicious intent the need for Risk management of IS facilities, process and staff came about and since the advent of this there has been a great improvement in business process because disruptions are less (Kamesam, 2001). In ideal risk management, a prioritization process is followed whereby the risks with the greatest loss and the greatest probability of occurring are handled first, and risks with lower probability of occurrence and lower loss are handled in descending order of occurrence and can often be mishandled (ISO/IEC, 2009). Risk management also faces difficulties allocating resources. This is the idea of opportunity cost. Resources spent on managing risks could have been spent on more profitable activities. Again,
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
A lot of research has been carried out in the field of risk management, as well as IT auditing, however risks and operation of information and data still threaten organizations processes and activities. Also, these two disciplines have been discretely managed and researched in the industry and academic, respectively. It therefore will be of importance to investigate the interface between the two disciplines. The purpose of this research is to investigate and understand audit and risk management system in the information technology environment. To lay a foundation for a discussion of the role of information systems in risk management, we must first define and understand the needs that drive organizations to implement risk management functions (Gibson, 1997). Information System (IS) was introduced to the business as a means of improving operational efficiency. It was initially used as a tool only for performing organisations operations, now it is a very important aspect of an organisation’s existence and survival, no operation can be carried out in an organisation without IS. Therefore we have to place an emphasis on IS risk management. The disruption of operations can also become more Important than the replacement of IS assets. Due to the costly cost of delays brought about by breakdown of IS which sometimes is caused by negligence and malicious intent the need for Risk management of IS facilities, process and staff came about and since the advent of this there has been a great improvement in business process because disruptions are less (Kamesam, 2001). In ideal risk management, a prioritization process is followed whereby the risks with the greatest loss and the greatest probability of occurring are handled first, and risks with lower probability of occurrence and lower loss are handled in descending order of occurrence and can often be mishandled (ISO/IEC, 2009). Risk management also faces difficulties allocating resources. This is the idea of opportunity cost. Resources spent on managing risks could have been spent on more profitable activities. Again,
Key concepts: Risk management, Audit, Risk analysis (engineering), Risk management information systems, Process (computing), Business, Process management, Internal audit