CSA ISO/IEC/IEEE 16085:21
1 Scope
1.1 Overview
This document:
— provides risk management elaborations for the processes described in ISO/IEC/IEEE 15288 and
ISO/IEC/IEEE 12207,
— provides the users of ISO/IEC/IEEE 15288, ISO/IEC/IEEE 12207 and their associated elaboration
standards with common terminology and specialized guidance for performing risk management
within the context of systems and software engineering projects,
— specifies the required information items that are to be produced through the implementation of
risk management process for claiming conformance, and
— specifies the required contents of the information items.
This document provides a universally applicable standard for practitioners responsible for managing
risks associated with systems and software over their life cycle. This document is suitable for the
management of all risks encountered in any organization or project appropriate to the systems or
software projects regardless of context, type of industry, technologies utilized, or organizational
structures involved.
This document does not provide detailed information about risk management practices, techniques, or
tools which are widely available in other publications. Instead this document focuses on providing a
comprehensive reference for integrating the large and wide variety of processes, practices, techniques,
and tools encountered in systems and software engineering projects and other lifecycle activities
into a unified approach for risk management, with the purpose of providing effective and efficient
risk management while meeting the expectations and requirements of organization and project
stakeholders.
1.2 Purpose
This document provides information on how to design, develop, implement, and continually improve
risk management in a systems and software engineering project throughout its life cycle.
1.3 Field of application
This document is compatible with risk management as described in ISO/IEC/IEEE 15288 and
ISO/IEC/IEEE 12207 and can also be applied in conjunction with ISO 31000. Depending on the scope
and context of the systems or software engineering project of interest, there are a number of additional
International Standards that can be applicable to the risk management effort including ISO 9001. This
document is intended to provide additional information useful in implementing a system for integrated
risk management for systems and software engineering projects. 5.2 discusses in more detail how this
document can be applied with other standards.
This document is applicable to:
— project teams which use ISO/IEC/IEEE 15288 and ISO/IEC/IEEE 12207 on projects dealing with
man-made systems, software-intensive systems, software and hardware products, and services
related to those systems and products, regardless of organization or project scope, product(s),
methodology, size, or complexity;
— project teams performing risk management activities to aid in ensuring that their application of risk
management conforms to ISO/IEC/IEEE 15288 and/or ISO/IEC/IEEE 12207;
— project teams using ISO/IEC/IEEE 15289 on projects dealing with human-made systems,
software-intensive systems, software and hardware products, and services related to those
systems and products, regardless of organization or project scope, product(s), methodology, size,
or complexity; and
— project teams generating information items developed during the application of risk management
processes to conform to ISO/IEC/IEEE 15289.
This document can be applied in conjunction with ISO 31000 and IEC 31010 to augment risk management
performed within the context of ISO/IEC/IEEE 15288 and/or ISO/IEC/IEEE 12207.
OEN:
CSA
Langue:
English
Code(s) de l'ICS:
35.080
Statut:
Norme
Date de Publication:
2021-06-30
Numéro Standard:
CSA ISO/IEC/IEEE 16085:21