LEGORisk: Risk-Centric Guidelines for Managing Legacy Systems
收藏资源简介:
Context: Modernizing legacy systems exposes organizations to technical, operational, and organizational risks that directly shape decision making. Yet, practice is fragmented and managers lack a structured, evidence-informed set of directives to identify, analyze, and compare these risks across maintenance, migration, and modernization scenarios. Objective: This study proposes LEGORisk, a guide that systematizes risk directives for legacy systems to support decisions on whether and how to maintain, migrate, or modernize. Method: We conducted a protocol-driven Systematic Literature Review (SLR) followed by Bardin’s thematic content analysis. From 545 records, 18 primary studies passed quality assessment and were fully coded and categorized. Results: We synthesized 89 risk directives organized into 4 categories and 12 subcategories, covering migration (e.g., cloud and target-system transitions), modernization (e.g., reengineering, rejuvenation, compatibility), and maintenance (e.g., recertification, industrial control systems (ICS)/security). A concept map and tabular structure make the guide actionable and traceable. Across studies, early ISO 31000 phases (context establishment and risk identification) were common, but risk treatment was underreported, revealing a notable gap between analysis and mitigation planning. LEGORisk links technical risks to business concerns and aligns with ISO 31000/31010 to facilitate adoption within governance processes. Conclusion: LEGORisk advances the state of practice by providing an evidence-based, structured vocabulary and checklist for legacy-system risk management, and it offers a reusable taxonomy and corpus-backed coding that can ground future empirical research and tool support.



