Review Article

A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT

Volume: 3 Number: 2 July 31, 2023
EN TR

A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT

Abstract

Risk management frameworks play an essential role in identifying, assessing, and mitigating risks to ensure the effective governance and operation of organizations. It is also one of the key elements of assurance and consultancy services of internal auditing in risk-based audit plans and programs. This study aims to provide an in-depth comparison of four widely used risk management frameworks: the Committee of Sponsoring Organizations of the Treadway Commission Enterprise Risk Management (COSO-ERM), the National Institute of Standards and Technology Risk Management Framework (NIST RMF), the International Organization for Standardization 31000 (ISO 31.000), and Control Objectives for Information and Related Technologies (COBIT). The analysis is conducted based on their underlying principles, structure, risk assessment methodologies, and applicability in various industries. We evaluate the strengths and weaknesses of each framework, including their adaptability and relevance in addressing emerging risks, such as cybersecurity and data privacy. It is found that implementing ISO 31000 and COBIT frameworks requires addressing challenges and limitations, including commitment from top management, knowledge and training, customization, and monitoring. To succeed, organizations should demonstrate commitment, provide training, customize the frameworks, and establish robust monitoring systems. The findings from this study serve as a guide for organizations seeking to adopt or transition between risk management frameworks, ultimately enabling them to select the most suitable approach tailored to their specific needs and risk landscape.

Keywords

References

  1. Arena, M., Arnaboldi, M., and Azzone, G. (2010). The organizational dynamics of enterprise risk management. Accounting, Organizations and Society, 35(7), 659–675. doi: 10.1016/j.aos.2010.07.003
  2. Aven, T. (2016). Risk assessment and risk management: review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1–13. doi: 10.1016/j.ejor.2015.12.023
  3. Barker, W. C. (2016). Guide for applying the risk management framework to federal information systems: A security life cycle approach. National Institute of Standards and Technology.
  4. Bayuk, J. L. (2010). Cyber Security Policy Guidebook. Hoboken, NJ: Wiley.
  5. Beasley, M. S. (2016). Enterprise risk management: today's leading research and best practices for tomorrow's executives (Vol. 504). John Wiley and Sons.
  6. Bjerga, T., Dingsør, A., and Kjelland, H. (2013). Risk management in the Norwegian oil and gas industry: Implementation of ISO 31.000. Safety Science, 55, 82-91.
  7. Bromiley, P., McShane, M., Nair, A., and Rustambekov, E. (2015). Enterprise Risk Management: Review, Critique, and Research Directions. Long Range Planning, 48(4), 265–276. doi: 10.1016/j.lrp.2014.07.005
  8. Chew, E., Swanson, M., Stine, K., Bartol, N., Brown, A., and Robinson, W. (2008). Performance measurement guide for information security. NIST Special Publication, 800(55), 1-64.

Details

Primary Language

English

Subjects

Business Administration

Journal Section

Review Article

Publication Date

July 31, 2023

Submission Date

May 3, 2023

Acceptance Date

July 28, 2023

Published in Issue

Year 2023 Volume: 3 Number: 2

APA
Efe, A. (2023). A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT. Denetim Ve Güvence Hizmetleri Dergisi, 3(2), 185-205. https://izlik.org/JA99XP55AJ
AMA
1.Efe A. A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT. AUDAS. 2023;3(2):185-205. https://izlik.org/JA99XP55AJ
Chicago
Efe, Ahmet. 2023. “A Comparison of Key Risk Management Frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT”. Denetim Ve Güvence Hizmetleri Dergisi 3 (2): 185-205. https://izlik.org/JA99XP55AJ.
EndNote
Efe A (July 1, 2023) A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT. Denetim ve Güvence Hizmetleri Dergisi 3 2 185–205.
IEEE
[1]A. Efe, “A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT”, AUDAS, vol. 3, no. 2, pp. 185–205, July 2023, [Online]. Available: https://izlik.org/JA99XP55AJ
ISNAD
Efe, Ahmet. “A Comparison of Key Risk Management Frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT”. Denetim ve Güvence Hizmetleri Dergisi 3/2 (July 1, 2023): 185-205. https://izlik.org/JA99XP55AJ.
JAMA
1.Efe A. A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT. AUDAS. 2023;3:185–205.
MLA
Efe, Ahmet. “A Comparison of Key Risk Management Frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT”. Denetim Ve Güvence Hizmetleri Dergisi, vol. 3, no. 2, July 2023, pp. 185-0, https://izlik.org/JA99XP55AJ.
Vancouver
1.Ahmet Efe. A comparison of key risk management frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT. AUDAS [Internet]. 2023 Jul. 1;3(2):185-20. Available from: https://izlik.org/JA99XP55AJ