Risk Management Standard

from Wikipedia, the free encyclopedia

A Risk Management Standard (RMS) is an on formal procedures and structures for risk management in organizations oriented standard . There are several national standards from standardization institutes as well as frameworks from committees and professional organizations.

object

Since the 1990s, system-oriented sets of rules and standards for risk management have been developed to an increasing extent worldwide, specifying generally applicable principles for the establishment and application of risk management standards. There are currently over 80 frameworks and standards for risk or risk management worldwide , with the subject area ranging from terminology to safety, health protection and environmental protection standards to general risk management guidelines with areas of application in space technology, medicine, biotechnology, petrochemicals and software technology.

Risk management standards for risk management in organizations represent a type of standardized management system that organizations use as an aid to designing formalized risk management systems. B. Quality management standards and environmental management standards .

Examples of risk management standards and risk management frameworks

  • CAN / CSA Q850 Risk Management: Guideline for Decision Makers (Canada 1997)
  • BS-6079-3: 2000 Project Management. Guide to the management of business related project risk (Great Britain 2000)
  • JIS Q 2001: 2001 Guidelines for development and implementation of a risk management system (Japan 2001)
  • IEC Guide 73: 2009 Risk Management – ​​Vocabulary - Guidelines for use in standards (international November 13, 2009)
  • COSO ERM Enterprise Risk Management - Integrated Framework (USA 2004)
  • ONR 49000: 2004 ff. Risk management for organizations and systems: terms and principles (Austria 2004)
  • AS / NZS 4360: 2004 Risk Management (Australia, New Zealand 2004)
  • ONR 49000: 2008 ff. Risk management for organizations and systems - Terms and principles - Use of ISO / DIS 31000 in practice (Austria 2008)
  • ISO / IEC 31000: 2009 Risk Management - Guidelines for principles and implementation of risk management (international, November 15, 2009)
  • ISO / IEC 31010: 2009 Risk management - Risk assessment techniques (international, November 27, 2009)
  • ISACA Risk IT - IT Risk Management Framework (international, December 8, 2009)
  • ISO / IEC 27005: 2011 - Information security risk management (international, 2011)
  • ISO / TR 31004: 2013 - Guidance for the implementation of ISO 31000 (international, Oct. 11, 2013)
  • ONR 49000: 2014 ff. Risk management for organizations and systems - Terms and principles - Implementation of ISO 31000 in practice (Austria, January 1, 2014)
  • BSI Standard 200-3: Risk Management (Germany, 2016)

literature

  • Bläsing, Jürgen P. (2008): Medical devices: Risk management in the life cycle model according to ISO 14971: 2007; Monitoring and reporting systems, TQU Verlag, Ulm [1]
  • Brühwiler, B. (2008): ISO / DIS 31000 and ONR 49000: 2008 - New standards in risk management, in: MQ Management und Qualität 5/2008, pp. 26-27.
  • Eckert, S. (2006): Controlling Lexicon: COSO Enterprise Risk Management Framework, in: Controlling, 18 (2006), 3, pp. 161–163
  • Weidemann, M. (2001): The Australian-New Zealand standard AS / NZS 4360: 1999 for risk management, in: Der Betrieb, Vol. 54 (2001), H. 50, pp. 2613-2618.
  • Weidemann, M./Wieben, H.-J. (2001): On the certifiability of risk management systems, in: Der Betrieb, vol. 54 (2001), no. 34, pp. 1789–1795.
  • Weis, U. (2009): Risk management according to ISO 31000. System - Actual Analysis - Methods, WEKA Media Verlag, Kissing 2009; ISBN 978-3-8276-3916-5
  • Weis, U. (2009): Risk management according to ISO 31000. Recognizing and successfully controlling risks, WEKA Media Verlag, Kissing 2009; ISBN 978-3-8276-2967-8
  • Winter, P. (2007): Risk controlling in non-financial companies: Development of a viable risk controlling concept and proposal for the design of a risk calculation, Lohmar / Cologne 2007.
  • Winter, P. (2007): Risk management standards as guidelines for formalized corporate risk management systems - overview and assessment, in: ZRFG, Vol. 2 (2007), Heft 4, pp. 149–155.
  • Winter, P. (2008): Standards in Risk Management, in: Romeike, F. [Hrsg.] Legal foundations of risk management - liability and avoidance of penalties for corporate compliance, Erich Schmidt Verlag, Berlin 2008, pp. 71-100.

See also

Web links

Individual evidence

  1. https://www.bsi.bund.de/DE/Themen/ITGrundschutz/ITGrundschutzStandards/Standard203/ITGStandard203_node.html