Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

Assessment Framework for Defining the Maturity of Information Technology within Enterprise Risk Management (ERM)

Author 1: Rokhman Fauzi Author 2: Muharman Lubis
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 12, No. 10 · Published 2021

DOI: https://doi.org/10.14569/IJACSA.2021.0121075

Abstract

The process of reviewing, assessing and improving the organization's IT risk management requires some basic information summarized in a process maturity profile. In general, IT risk management standards or frameworks do not include a mechanism for assessing the maturity level of process implementations. This study was conducted to develop a framework, which can be applied to assess the maturity level of IT risk management under ISO / IEC 27005. A standards-based management system implementation can be represented as a model cycle of planning, implementation, validation and also action plan. The proposed evaluation framework consists of templates, methods, and working papers. Therefore, the template focus on the evaluation areas, which are planning, execution, validation, and execution, then evaluation area details (8 domains, 35 subdomains, 82 items), and evaluation metrics and criteria. Meanwhile, a working paper has been created to assist in conducting the evaluation. Actually, by using this evaluation framework, it can provide a representation of the maturity level from the entire process in managing IT risk, based on the provisions of ISO/IEC 27005. This framework complements the existing model with the representation of (1) providing a single-cycle planning, establishment, validation, and execution, (2) evaluation tools, (3) more comprehensive data collection methods, and (4) priority list of elements to be reformed and/or improved.

Keywords

How to Cite this Article

Fauzi, R., & Lubis, M. (2021). Assessment Framework for Defining the Maturity of Information Technology within Enterprise Risk Management (ERM). International Journal of Advanced Computer Science and Applications, 12(10). https://doi.org/10.14569/IJACSA.2021.0121075

Fauzi, Rokhman, and Muharman Lubis. "Assessment Framework for Defining the Maturity of Information Technology within Enterprise Risk Management (ERM)." International Journal of Advanced Computer Science and Applications, vol. 12, no. 10, 2021, https://doi.org/10.14569/IJACSA.2021.0121075.

@article{Fauzi2021,
  title     = {Assessment Framework for Defining the Maturity of Information Technology within Enterprise Risk Management (ERM)},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {12},
  number    = {10},
  year      = {2021},
  publisher = {The Science and Information Organization},
  author    = {Rokhman Fauzi and Muharman Lubis},
  doi       = {10.14569/IJACSA.2021.0121075},
  url       = {https://doi.org/10.14569/IJACSA.2021.0121075}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.