International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 174 - Number 30 |
Year of Publication: 2021 |
Authors: Rafael De Almeida Azevedo, Paulo Caetano Da Silva, André Magno De Costa Araújo |
10.5120/ijca2021921237 |
Rafael De Almeida Azevedo, Paulo Caetano Da Silva, André Magno De Costa Araújo . IT Risk Management Maturity Model for SOA. International Journal of Computer Applications. 174, 30 ( Apr 2021), 25-32. DOI=10.5120/ijca2021921237
Risk management is an important area of knowledge in corporate environments, allowing risks to be known and adequately mitigated and addressed. A structured information technology risk management environment can influence the improvement of the flexibility and adaptability of an organization's business processes. In this context, the concept of service-oriented architecture (SOA), aims at the union of organizational processes with the resources provided by information technology (IT). Although SOA has been widely debated and applied in organizational environments, it realizes little attention has been paid to the investigation of a risk management model to assess the maturity of business processes in information technology based on SOA. This work presents a risk management maturity model, formed by the union of good information technology risk management practices and existing maturity models, to be applied in a service-oriented architecture. The proposed model aims to assist in assessing the level of risk management maturity in the SOA scope. To evaluate the proposed model, the scenario of a health organization was used, and the results showed that, the level of IT risk management maturity based on SOA was measured, which provided a holistic view of risk management on the dimensions, people, processes, and technology.