Based on the standards and frameworks what I have known, I have organised them into a structured framework that can be utilised for governance, risk management, project management, and quality assurance.
Framework of Standards and Methodologies
1. ISO Standards
- ISO 9001: Quality Management Systems
- ISO 13485: Medical Devices - Quality Management Systems
- ISO 27001: Information Security Management Systems
- ISO 27005: Information Security Risk Management
- ISO 27701: Privacy Information Management
- ISO 42001: Management Systems for AI Management
- ISO 27017: Cloud Security Guidelines
- ISO 27018: Protection of Personal Data in the Cloud
- ISO 22301: Business Continuity Management
- ISO 31000: Risk Management
- ISO 20000: IT Service Management
2. IT Service Management
- ITIL v4: IT Infrastructure Library
- COBIT: Control Objectives for Information and Related Technologies
3. Agile and Project Management Frameworks
- Kanban: Lean Workflow Management
- Scrum: Agile Framework for Managing Projects
- SAFe: Scaled Agile Framework
- PRINCE2 Agile: Project Management Methodology
4. Quality Improvement Methodologies
- Six Sigma: Data-driven approach to eliminate defects
- Theory of Constraints: Management philosophy focusing on constraints
- Hoshin Kanri: Strategic planning process
- TRIZ: Theory of Inventive Problem Solving
- Balanced Scorecard (BSC): Strategic management tool
5. Governance and Compliance
- SOC 1: Controls relevant to user entities’ internal control over financial reporting
- SOC 2: Controls based on Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy)
- ITGC: IT General Controls
Certifications
- CISM: Certified Information Security Manager
- CIPM: Certified Information Privacy Manager
- PMP: Project Management Professional
- CRISC: Certified in Risk and Information Systems Control
This knowledge of the above can serve as a guideline for practitioners to understand and implement various standards and methodologies in their work effectively. Each standard or methodology can be explored further for detailed guidance on its application and benefits.
No comments:
Post a Comment