DocumentCode :
2319974
Title :
Implementing corrective and preventive actions in risk assessment software
Author :
Dareshuri, Ali Farhang ; Darehshori, Elnaz Farhang ; Hardoroudi, Amir Hatami ; Sarkan, Haslina Md
Author_Institution :
Adv. Inf. Sch., Univ. of Technol. Malaysia, Kuala Lumpur, Malaysia
fYear :
2011
fDate :
25-28 Sept. 2011
Firstpage :
327
Lastpage :
331
Abstract :
Many IT companies are faced with an alarming rate of risks in their businesses. This can be a result of lack of experiences to control re-occurrence and prevent new risks according to the previous projects experience. On the other hand, Corrective and Preventive Actions (CAPA) are known concepts for learning from experiences to avoid non-conformities. The successful implementations of CAPA in different systems have convinced the authors to use CAPA in Risk Assessment Process to decrease the likelihood and impact of risks by learning from the past. To achieve this, our application should survey and rank the possibility and effect of risks, as well as their related elements (such as assets, threats, safeguards, vulnerabilities and team accountability). After each appearance of a risk, the system should review and correct the ranks. It must perform a Root Cause Analysis (RCA). Another requirement for the system is to be able to find similar items. The system can distinguish the similarities by categorizing risk related elements according to their properties and finding possible comparable substances. In addition, this system also uses its data to produce useful high level recommendations and other required documents. By applying this model and after identifying all weaknesses, the value of risks abates dramatically. This Corrective Action and Preventive Actions in Risk Assessment (CAPRA) has been successfully designed and implemented as a web based application.
Keywords :
risk management; software development management; CAPRA; RCA; corrective action and preventive actions in risk assessment; risk assessment software; root cause analysis; Companies; Conferences; Documentation; Engines; ISO standards; Open systems; Risk management; CAPA; Corrective Action; Preventive Action; Risk Assessment;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Open Systems (ICOS), 2011 IEEE Conference on
Conference_Location :
Langkawi
Print_ISBN :
978-1-61284-931-7
Type :
conf
DOI :
10.1109/ICOS.2011.6079271
Filename :
6079271
Link To Document :
بازگشت