Management by risks of automated information system quality
Abstract
Quality risk management is a systematic process for the assessment, control, communication, and review of risks. It is an iterative process used throughout the entire computerized system life cycle from concept to retirement. Such a framework is most effectively implemented when it is incorporated into the overall QMS, and is fully integrated with the system life cycle. Risks that cannot be eliminated by design should be reduced to an acceptable level by controls or manual procedures. Risk reduction includes applying controls to lower the severity, decrease probability, or increase detectability. The aim is to present the methodology of risk management for improving the quality of automated information systems and presentation control strategy to reduce risks. Application of quality risk management enables effort to be focused on critical aspects of a computerized system, in a controlled and justified manner, leading to specific benefits The five step risk management process has been designed such that it may be scaled according to risk, complexity, and novelty of individual systems, with each step of the process building upon the previous output. Appropriate risk management processes should be followed throughout the life cycle in order to manage identified risks and to determine the rigor and extent of the activities required at each phase of the life cycle. The process of risk management can solve a problem of fuzzy identifying risks and potential variations in characteristics as automated information system and the problem of improper risk analysis based on multilevel models as stages of the life cycle of the system
Keywords
risk management, automation, quality verification, specification, design
References
- Davydenko,Ye.O. (2012). Analysis of approaches to identifying risks in software development and maintenance. In Modern Information Systems and Technologies: Proceedings of the 1st International Scientific and Practical Conference, Sumy, May 15–18, 2012 (pp. 76–77). Sumy: SumDU.
- DeMarco,T. (2005). Dancing with bears: Managing risk in software development projects. Moscow: P.M. Office.
- Department of Defense (DoD). (2006). Risk management guide for risk acquisition. USA.
- Dubrovin,V.I. (2012). Decision-making in project risk management: A textbook. Zaporizhzhia: ZNTU.
- European Medicines Agency (EMA). (2011). Quality risk management (ICH Q9) (EMA/INS/GMP/79766/2011). Retrieved January 31, 2011.
- Gruzdo,I.V. (2009). Improving software project quality through risk management. Information Processing Systems, National Aerospace University named after N.E. Zhukovsky "KhAI", (1[75]), 141–146.
- Katrenko,A.V. (2008). Risk management methods in IT projects. In Computer Science and Information Technologies (CSIT–2008): Proceedings of the 3rd International Scientific and Practical Conference, September 25–27, 2008 (pp. 245–247). Lviv.
- Lypaev,V.V. (2003). Analysis and reduction of risks in complex software projects. Moscow: Sinteg.
- Rishnyak,I.V. (2004). A model for project risk management. Computer-Aided Design Systems. Theory and Practice. Bulletin of the National University "Lviv Polytechnic", (522), 155–160.
- Rishnyak,I.V. (2010). Methods of operational risk management in information technology projects. Bulletin of the National University "Lviv Polytechnic". Computer Science and Information Technologies, (686), 218–224.
- Veres,O.M., Katrenko,A.V., Rishnyak,I.V., & Chaplyha,V.M. (2003). Risk management in project activities. Information Systems and Networks: Bulletin of the National University "Lviv Polytechnic", (489), 38–49.