GB/T 20918-2007 in English
VALIDInformation technology—Software life cycle processes—Risk management
- Issued on:2007-04-30
- Implemented on:2007-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$233.00
《GB/T 20918-2007信息技术 软件生存周期过程 风险管理》由TC28(全国信息技术标准化技术委员会)归口,TC28SC7(全国信息技术标准化技术委员会软件与系统工程分会)执行,主管部门为国家标准化管理委员会。
本标准描述了软件获娶供应、开发、运作和维护过程中的风险管理过程。本标准适用于软件项目中的风险管理,也可用于系统级或组织级风险的管理。
1 Scope
1.1 Purpose
This standard describes the risk management process in the process of software acquisition, supply, development, operation and maintenance. It is recommended that technical and managerial personnel throughout the organization use this standard.
The purpose of this standard is to provide software suppliers, demanders, developers and managers with a set of process requirements suitable for managing a wide variety of risks. This standard does not provide detailed and clear risk management technology, but is committed to defining a risk management process to which any technology can be applied.
1.2 Field of application
This standard defines a risk management process that runs through the software life cycle. It is suitable for adoption by organizations and is used for all appropriate projects or individual projects. Although this standard is written for risk management in software projects, it may also be used for system-level or organization-level risk management.
This standard may be used in conjunction with GB/T 8566 or used alone.
1.2.1 Use in conjunction with GB/T 8566
GB/T 8566 describes the standard process of software acquisition, supply, development, operation and maintenance. It takes into account that active risk management is a key factor for successful software project management. It mentions risks and risk management in many places, but it does not give the process of risk management. While this standard gives this process. In order to support the views of managers, participants and other stakeholders, this standard can be used to manage organization-level or project-level risks in any field or in any life cycle phase.
In the framework for life cycle processes given in GB/T 8566, risk management is an "organizational life cycle process". In an organizational life cycle process, the organization using the process is responsible for the activities and tasks in the process. Therefore, the organization shall ensure that the process exists and functions.
When used in conjunction with GB/T 8566, this standard assumes that other management and technical processes of GB/T 8566 perform risk treatment, and also describes the correct relationship with these processes.
1.2.2 Use of this standard alone
This standard may be used independently of any specific software life cycle process standard. When used in this way, the additional clauses for risk treatment in this standard will apply.
1.3 Conformance
An organization or project can claim conformance with this standard if it lists in its plan and implements all requirements in the activities and tasks described in Clause 5 of this standard (the requirements with the word “shall” are mandatory).
In those instances where this standard is used independently of GB/T 8566, additional requirements for risk management are given in 5.1.4.2.
Foreword II
Introduction III
1 Scope
2 Normative references
3 Terms and definitions
4 Application of this standard
5 Risk management in software life cycle
Annex A (Informative) Risk management plan
Annex B (Informative) Risk action request
Annex C (Informative) Risk treatment plan
Bibliography

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 25000.1-2021 in English
Systems and software engineering-Systems and software quality requirements and evaluation (SQuaRE)-Part 1:Guide to SQuaRE
2021-04-30 -

GB/T 44601-2024 in English
Information technology service—Service life cycle processes
2024-09-29 -

GB/T 34960.1-2017 in English
Information technology service-Governance-Part 1:General requirements
2017-11-01 -

GB/T 30961-2014 in English
Embedded software quality metric
2014-07-08 -

GB/T 46900-2025 in English
Systems and software engineering—General technical requirements for low-code development platform
2025-12-31 -

GB/T 20157-2006 in English
Information technology—Software maintenance
2006-03-14 -

GB/T 34083-2017 in English
Specification of programming interface for Chinese speech recognition internet service
2017-07-31 -

GB/Z 31103-2014 in English
Systems engineering―A guide for the application of GB/T 22032(System life cycle processes)
2014-09-03 -

GB/T 42412-2023 in English
Technical requirements for the implementation of personalized customization based on industrial cloud platform
2023-03-17 -

GB/T 18234-2000 in English
Information technology--Guideline for the evaluation and selection of CASE tools
2000-10-17