search menu icon-carat-right cmu-wordmark

Risk Management Framework

Technical Report
In this report, the authors specify (1) a framework that documents best practice for risk management and (2) an approach for evaluating a program's risk management practice in relation to the framework.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-2010-TR-017
DOI (Digital Object Identifier)
10.1184/R1/6583466.v1

Abstract

Although most programs and organizations use risk management when developing and operating software-reliant systems, preventable failures continue to occur at an alarming rate. In many instances, the root causes of these preventable failures can be traced to weaknesses in the risk management practices employed by those programs and organizations. To help improve existing risk management practices, SEI researchers undertook a project to define what constitutes best practice for risk management. The SEI has conducted research and development in the area of risk management since the early 1990s. Past SEI research has applied risk management methods, tools, and techniques across the life cycle (including acquisition, development, and operations) and has examined various types of risk, including software development risk, system acquisition risk, operational risk, mission risk, and information security risk, among others.  

In this technical report, SEI researchers have codified this experience and expertise by specifying (1) a Risk Management Framework that documents accepted best practice for risk management and (2) an approach for evaluating a program’s or organization’s risk management practice in relation to the framework.

Cite This Technical Report

Alberts, C., & Dorofee, A. (2010, August 1). Risk Management Framework. (Technical Report CMU/SEI-2010-TR-017). Retrieved March 3, 2024, from https://doi.org/10.1184/R1/6583466.v1.

@techreport{alberts_2010,
author={Alberts, Christopher and Dorofee, Audrey},
title={Risk Management Framework},
month={Aug},
year={2010},
number={CMU/SEI-2010-TR-017},
howpublished={Carnegie Mellon University, Software Engineering Institute's Digital Library},
url={https://doi.org/10.1184/R1/6583466.v1},
note={Accessed: 2024-Mar-3}
}

Alberts, Christopher, and Audrey Dorofee. "Risk Management Framework." (CMU/SEI-2010-TR-017). Carnegie Mellon University, Software Engineering Institute's Digital Library. Software Engineering Institute, August 1, 2010. https://doi.org/10.1184/R1/6583466.v1.

C. Alberts, and A. Dorofee, "Risk Management Framework," Carnegie Mellon University, Software Engineering Institute's Digital Library. Software Engineering Institute, Technical Report CMU/SEI-2010-TR-017, 1-Aug-2010 [Online]. Available: https://doi.org/10.1184/R1/6583466.v1. [Accessed: 3-Mar-2024].

Alberts, Christopher, and Audrey Dorofee. "Risk Management Framework." (Technical Report CMU/SEI-2010-TR-017). Carnegie Mellon University, Software Engineering Institute's Digital Library, Software Engineering Institute, 1 Aug. 2010. https://doi.org/10.1184/R1/6583466.v1. Accessed 3 Mar. 2024.

Alberts, Christopher; & Dorofee, Audrey. Risk Management Framework. CMU/SEI-2010-TR-017. Software Engineering Institute. 2010. https://doi.org/10.1184/R1/6583466.v1