COSO, 2007, Committee of Sponsoring Organizations of
the Treadway Commission.Gerenciamento de Riscos
Corporativos – Estrutura Integrada: Sumário Executivo
e Estrutura.
DSIC, 2013, Departamento de Segurança da Informação e
Comunicações.Diretrizes para o processo de Gestão de
Riscos de Segurança da Informação e Comunicações.
Norma Complementar nº 04/IN01/DSIC/GSIPR.
Available at: <http://dsic.planalto.gov.br/
documentos/nc_04_grsic.pdf>.
Elmaallam, M. K. A., 2011.Towards a model of maturity
for is risk management, International Journal of
Computer Science & Information Technology, vol. 3, nº
4.
Hillson, D., 1997. Towards a Risk Maturity Model, The
International Journal of Project & Business Risk
Management. Vol. I, nº I, pp. 35-45, Spring.
HM Treasury, 2004. Her majesty's Treasury. The Orange
Book, Norwich: Crown. p. 52.
Holanda, A., 2004. Novo Dicionário Eletrônico Aurélio.
POSITIVO.
Hopkinson, M., 2011.Improving Risk Management
Capability Using the Project Risk Maturity Model - a
Case Study Based on UK Defense Procurement
Projects, PM World Today., vol. XIII.
IBGC, 2009, Instituto Brasileiro de Governança
Corporativa.Código das melhores práticas da
governança corporativa. São Paulo.
ISACA, 2011, Information Systems Audit and Control
Association. COBIT Process Assessment Model
(PAM): using COBIT 4.1. Illinois - USA.
ISACA, 2011, Information Systems Audit and Control
Association. COBIT Self-assessment Guide: Using
COBIT 4.1, Illinois - USA.
ISO, 2004, International Organization for
Standardization.ISO/IEC 15504-1:2004. Information
technology – Process assessment - Part 1: Concepts
and vocabulary.
ISO, 2008, International Organization for
Standardization.ISO/IEC 38500:2008. Corporate
governance of information technology.
ISO, 2009, International Organization for Standardization.
Guide 73:2009. Risk Management- Vocabulary.
ISO, 2009, International Organization for Standardization.
ISO/IEC31000:2009. Risk management – Principles
and guidelines.
ITGI – IT, 2007, Governance Institute. COBIT 4.1, Illinois
- USA.
Koehler, J., Woodtly, R., Hofstetter, J., 2015. An impact
oriented maturity model for IT-based case
management. Information Systems. vol. 47, pp. 278–
291, Elsevier.
Moore, R., Lopes, J., 1999. Paper templates. In
TEMPLATE’06, 1st International Conference on
Template Production. SCITEPRESS.
OECD, 2004, Organization for Economic Co-operation and
Development. Principles of Corporate Governance
.
Available:
<http://www.oecd.org/corporate/corporateaffairs/corp
orategovernanceprinciples/31557724.pdf>. Accessed
(13.5.2013).
Oliva, Fabio L., 2016. A maturity model for enterprise risk
management. International Journal of Production
Economics 173, 66–79. Elsevier.
Ramos, A., 2008.Security Officer, Guia Oficial para
Formação de Gestores de Segurança da Informação,
Zouk. Porto Alegre.2 ed., vol. I.
Saaty, T. L., 2009.Extending the Measurement of Tangibles
to Intangibles, International Journal of Information
Technology & Decision Making, vol. 8, pp. 7-27.
SEI, 2010, Software Engineering Institute, CMMI for
Services, Carnegie Mellon, Pittsburgh.
SEI, 2011, Software Engineering Institute. Standard CMMI
Appraisal Method for Process Improvement (SCAMPI)
A Version 1.3: Method Definition Document, Carnegie
Mellon, Pittsburgh, PA, March,.
Shahzad, B., Safvi, S., 2010.Risk mitigation and
management scheme based on risk priority,Global
Journal of Computer Science and Technology.Vol. 10,
nº Issue 4, pp. 108-113, 2010.
Silva, J. M. d., 2012.Apostila de Formação de valor em
sistemas de atividades humanas, Faculdade de
Tecnologia, Núcleo de Engenharia de Produção, UnB.
Silveira, A., 2010. Governança Corporativa no Brasil e no
Mundo, Teoria e Prática, Elsevier.Rio de Janeiro.
Vargas, R. V., 2009.The History of Risk Management –
Based on the book Against the God. Available:
http://www.ricardo-vargas.com/slides/20. Accessed
(28.6.2016).
Weill, P., Ross, J., 2006.Governança de TI: Tecnologia da
Informação, M. Books. São Paulo.