A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT
Abstract
Keywords
References
- Arena, M., Arnaboldi, M., and Azzone, G. (2010). The organizational dynamics of enterprise risk management. Accounting, Organizations and Society, 35(7), 659–675. doi: 10.1016/j.aos.2010.07.003
- Aven, T. (2016). Risk assessment and risk management: review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1–13. doi: 10.1016/j.ejor.2015.12.023
- Barker, W. C. (2016). Guide for applying the risk management framework to federal information systems: A security life cycle approach. National Institute of Standards and Technology.
- Bayuk, J. L. (2010). Cyber Security Policy Guidebook. Hoboken, NJ: Wiley.
- Beasley, M. S. (2016). Enterprise risk management: today's leading research and best practices for tomorrow's executives (Vol. 504). John Wiley and Sons.
- Bjerga, T., Dingsør, A., and Kjelland, H. (2013). Risk management in the Norwegian oil and gas industry: Implementation of ISO 31.000. Safety Science, 55, 82-91.
- Bromiley, P., McShane, M., Nair, A., and Rustambekov, E. (2015). Enterprise Risk Management: Review, Critique, and Research Directions. Long Range Planning, 48(4), 265–276. doi: 10.1016/j.lrp.2014.07.005
- Chew, E., Swanson, M., Stine, K., Bartol, N., Brown, A., and Robinson, W. (2008). Performance measurement guide for information security. NIST Special Publication, 800(55), 1-64.
Details
Primary Language
English
Subjects
Business Administration
Journal Section
Review Article
Authors
Ahmet Efe
*
0000-0002-2691-7517
Türkiye
Publication Date
July 31, 2023
Submission Date
May 3, 2023
Acceptance Date
July 28, 2023
Published in Issue
Year 2023 Volume: 3 Number: 2