BSI PD ISO/IEC TR 33015:2019
$167.15
Information technology. Process assessment. Guidance for process risk determination
Published By | Publication Date | Number of Pages |
BSI | 2019 | 42 |
This document provides guidance on the application of the results of a process assessment for process risk determination.
The guidance provided does not presume specific organizational structures, management philosophies, life cycle models or development methods. In relation to process risk determination, this guidance is applicable within any customer–supplier relationship, and to any organization wishing to perform a process risk determination of its processes.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | National foreword |
7 | Foreword |
8 | Introduction |
9 | 1 Scope 2 Normative references 3 Terms and definitions 4 General introduction 4.1 Determining process-related risk |
10 | 4.2 Process risk determination — purpose and outcomes |
11 | 4.3 Significance of the process risk determination results 4.3.1 Impact of the assessment scope and the process context on the results of the process risk determination 4.3.2 Categorizing process-related risks |
12 | 4.3.3 Defining specific rating guidelines 5 Process risk determination process 5.1 Overview 5.2 Activities of process risk determination 5.2.1 Step 1 – Initiate process risk determination |
13 | 5.2.2 Step 2 – Identify relevant processes and the relevant process context 5.2.3 Step 3 – Define target process profile 5.2.4 Step 4 – Define target assessment input 5.2.5 Step 5 – Assess current process quality |
14 | 5.2.6 Step 6 – Determine proposed process quality characteristic achievement 5.2.7 Step 7 – Verify proposed process quality characteristic achievement |
15 | 5.2.8 Step 8 – Analyse process-related risk 5.2.9 Step 9 – Act on results 6 Guidance on process risk determination 6.1 General 6.2 Initiating the process risk determination |
16 | 6.3 Determining the target assessment input 6.3.1 General 6.3.2 Selecting the process quality characteristic and the process measurement framework 6.3.3 Selecting process reference model(s) 6.3.4 Selecting the process assessment model 6.3.5 Selecting the set of processes |
17 | 6.3.6 Determining the process context 6.4 Defining target process profile |
20 | 6.5 Guidelines for assessments used for process risk determination 6.5.1 General 6.5.2 Specific guidelines on determining the target assessment input 6.5.3 Specific criteria for data and information collection |
21 | 6.5.4 Specific rating rules or recommendations 6.6 Evaluating process-related risk 6.6.1 Inferring process-related risk from assessment output |
23 | 6.6.2 Analysing weaknesses 6.7 Using process risk determination for supplier selection |
24 | 6.8 Comparability of assessment output analysis |
25 | Annex A (informative) Categorizing types of process-related risks |
29 | Annex B (informative) Analysing process-related risks |
34 | Annex C (informative) Target process profiles |
41 | Bibliography |