IT Governance Infocom India Presentation December 6, 2006.

Slides:



Advertisements
Similar presentations
1 NameMatrix Number Francis YeeHT036029M George Goh Alex LimHT052467E Hoe Swee SimHT052560I Vijay.
Advertisements

Module N° 4 – ICAO SSP framework
IBM Corporate Environmental Affairs and Product Safety
EMS Checklist (ISO model)
Configuration Management
[Organisation’s Title] Environmental Management System
Alignment of COBIT to Botswana IT Audit Methodology
ITIL v3 Overview Rob Goodwin-Davey.
Service Delivery – your ticket to play
ITIL: Service Transition
A Presentation for the Enterprise Architect © 2008 IBM Corporation IBM Technology Day - SOA SOA Governance Miroslav Petrek IT Software Architect
Security Controls – What Works
Information Security Governance and Risk Chapter 2 Part 1 Pages 21 to 69.
Aust. AM Collaborative Group (AAMCOG) An introduction to ISO “What to do” guide 20th October 2014.
QMS, ISO and Six Sigma It’s all related….. QMS Any Quality Management System must satisfy four requirements: Processes must be defined and their procedures.
ITIL: Why Your IT Organization Should Care Service Support
Information Technology Service Management
Space and Airborne Systems NDIA/SEI CMMI Technology Conference Presented by N. Fleischer 1 Raytheon’s Six Sigma Process and Its Application for CMMI By.
Change Advisory Board COIN v1.ppt Change Advisory Board ITIL COIN June 20, 2007.
Release & Deployment ITIL Version 3
Consultancy.
A NASSCOM ® Initiative Security and Quality Kamlesh Bajaj CEO, DSCI May 23, 2009 NASSCOM Quality Summit Hyderabad 1.
The Evergreen, Background, Methodology and IT Service Management Model
Continual Service Improvement Process
Don Von Dollen Senior Program Manager, Data Integration & Communications Grid Interop December 4, 2012 A Utility Standards and Technology Adoption Framework.
Collin County’s Doing More with Less How Collin County’s ITIL Framework has worked to do more with less.
Network Security Policy Anna Nash MBA 737. Agenda Overview Goals Components Success Factors Common Barriers Importance Questions.
Transitioning to the COSO 2013 Update.  Released on May 14, 2013  Designed to build upon the foundation of the 1992 Framework  Will supersede the 1992.
Doing More with TeamTrack May 1, /17/2015 6:14 PM Goals and Objectives Increased Reuse of Critical Assets Increased Productivity and Effectiveness.
Organize to improve Data Quality Data Quality?. © 2012 GS1 To fully exploit and utilize the data available, a strategic approach to data governance at.
Introduction to ISO 9001:2000.
GRC - Governance, Risk MANAGEMENT, and Compliance
The Challenge of IT-Business Alignment
Roles and Responsibilities
Deakin Richard Tan Head, Information Technology Services Division DEAKIN UNIVERSITY 14 th October 2003.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
CERTIFICATION In the Electronics Recycling Industry © 2007 IAER Web Site - -
Service Transition & Planning Service Validation & Testing
ISO17799 Maturity. Confidentiality Confidentiality relates to the protection of sensitive data from unauthorized use and distribution. Examples include:
Roadmap to Maturity FISMA and ISO 2700x. Technical Controls Data IntegritySDLC & Change Management Operations Management Authentication, Authorization.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
DRAFT – For Discussion Only HHSC IT Governance Executive Briefing Materials DRAFT April 2013.
Holistic Approach to Security
IT Governance: COBIT, ISO17799 & ITIL. Introduction COBIT ITIL ISO17799Others.
Assessment Workshop Title of the Project (date). Project Title Assessment Workshop October 25, 2015© Company Name All rights reserved2 Agenda Purpose.
IT SERVICE MANAGEMENT (ITSM). ITIL\ITSM OVERVIEW  ITIL Framework.
Example Incident Mgmt Initiation No recording of Incidents Users can approach different departments Solutions of previous incidents are not available.
Samantha Schreiner University of Illinois at Urbana- Champaign BA 559 – Professor Michael Shaw December 15 th, 2008 A Survey of IT Governance Through COBIT,
Kathy Corbiere Service Delivery and Performance Commission
TMS - Cooperation partner of TÜV SÜD EFFECTIVE SERVICE MANAGEMENT based on ISO/IEC & ISO/IEC
ITIL Awareness UC JDCMG Discussion 4/26/2017.
CSI - Principles ITIL v3. CSI & Organizational Change © Crown Copyright 2007 Reproduced under license from OGC.
The Service Monitoring and Control Toolkit 1 Protect your business with an effective alert management system and high service availability.
Sustainable Community EMS Design Including Pollution Prevention Michelle M. Wyman Reed Smith Shaw & McClay LLP EMS Models and Strategies: ISO & Beyond.
2/20/2016 Leveraging IT Governance and COBIT Chip Council, PhD, CGEIT, CISM, CISA Matt Schmidt, MS, CISSP, CISA Adjunct Professors, University of Minnesota.
Accounting and Information Systems: a powerful combination.
ITIL ♥ PM ITIL and Project Management: Friends Throughout the Lifecycle.
H UMAN R ESOURCES M ANAGEMENT August 18, O UTLINE Key Results Ensure all stakeholders are well informed of cybersecurity and its financial impact.
© | Hansan Global | All Rights Reserved 1 INTRODUCTION TO IT SERVICE MANAGEMENT Hansan Global Pte Ltd.
Alex Ezrakhovich Process Approach for an Integrated Management System Change driven.
Introduction to ITIL IT Service Management Collin Smith
ITIL: Service Transition
BIL 424 NETWORK ARCHITECTURE AND SERVICE PROVIDING.
What Is ISO ISO 27001, titled "Information Security Management - Specification With Guidance for Use", is the replacement for BS It is intended.
EITS Planning & Decision Support
CIGFARO ANNUAL CONFERENCE – 11 OCTOBER 2017
Information Technology Service Management
INTRODUCTION TO ISO 9001:2015 FOR IMPLEMENTATION Varinder Kumar CISA, ISO27001 LA, ISO 9001 LA, ITIL, CEH, MEPGP IT, Certificate course in PII & Privacy.
Alignment of COBIT to Botswana IT Audit Methodology
Engineering Processes
Presentation transcript:

IT Governance Infocom India Presentation December 6, 2006

Agenda n Why have IT Governance? n What is IT Governance? n Various elements of IT Governance n Frameworks for IT Governance n How Frameworks interact n How IT processes underpin IT Governance n Example of Framework integration n Metrics to measure IT process health

Why Bother About IT Governance? Decline of Business Readiness Lack of Effective Governance Can Lead to Catastrophic Failures!! Desired Level Major Effort for Recovery Catastrophic Failure!! IT Readiness Time

This is not a Rhetorical Conjecture! n Some Examples: n Largest Asian Stock Exchange suspended trading in November, 2005 due to incorrect software patch n Payroll of millions of customers of a major North American bank was affected in June, 2004 due to incorrect system update n Erroneous changes to Airline Ticketing system caused hundreds of international travel tickets being sold for less than $100

IT Governance – The Definition n IT Governance is a system that: n Directs and controls to administer necessary IT services to its clients n Specifies rights and responsibilities of parties* involved n Defines the policies and procedures; n Provides the structure to achieve the above * Customers, Regulators and Stakeholders The above closely follows corporate governance definition outlined by OECD (Organization for Economic Cooperation and Development) located in Paris, France.

IT Governance – Differing Viewpoints n Three Parties & Three Areas of Interest n Regulators – in Regulatory Compliance n Regulators are Government Agencies n Customers – in Effectiveness of IT Services and somewhat in Regulatory Compliance n Customers are recipients of IT Services n Stakeholders – in Efficiency and Effectiveness of IT Services and Regulatory Compliance n Stakeholders are managers and employees of an IT organization

Interest Areas of the Three Parties Efficiency, Effectiveness and Compliance are only possible through Deployment and Management of a Process Environment of Best Practices

Elements of Governance n Standard against which Governance can be assessed n Proven Set of Practices for the processes of an organization n Compliance for government regulations n Continuous Improvement to address Efficiency Governance is NOT just compliance of Government Regulations for Financial Disclosure

Frameworks impacting IT Governance – The Alphabet Soup n Standards Frameworks n ISO (Int. Org. for Standardization) – for Quality n Adoption for competitive reason and is optional n SOXA (Sarbanes-Oxley Act) – for Compliance n Regulatory requirements make adoption mandatory n Compliance Framework n COBIT (Control Objectives for Information and Related Technology) – for Controls

Frameworks impacting IT Governance – The Alphabet Soup n Best Practices Frameworks n CMMI (Capability Maturity Modeling Integration) – for IT Development n ITIL (Information Technology Infrastructure Library) – for IT Infrastructure Support n Continuous Improvement Framework n Six Sigma

Governance Elements - Also Underpinned by Best Practices

Processes Underpin Governance Elements n ITIL processes are necessary for ISO certification n ITIL helps to provide controls for COBIT n ITIL processes underpin CMMI for support and maintenance n Continuous Improvement & Six Sigma is only possible through deployment of ITIL best practices n ITIL Best Practices allow addressing of Effectiveness, Efficiency and Compliance

Users Difficulties, Inquiries Service Requests Change Requests Service Support Change Management Communication, Updates, Workarounds Incidents Releases Incident Management Problem Management Release Management Service Desk The Business, Customers Service Level Management Queries, Inquiries Communication` Service Delivery Availability Management Capacity Management Financial Management for IT Services IT Service Continuity Management Requirements, Targets, Achievements Availability Management Capacity Management Financial Management for IT Services IT Service Continuity Management Requirements, Targets, Achievements Configuration Management ITIL (IT Infrastructure Library)

ITIL and ISO - Achieving ISO Certification

Necessary Tasks for SOXA* Compliance 1. Display the Business Process 2. Define Control Objectives 3. Identify Risks (or “what-can-go- wrong”) in the process 4. Define specific Controls that are in place to mitigate the above Risks, and, 5. Produce Evidence to prove that the above Controls are effective ITIL Best Practices ITIL Best Practices *Sarbanes-Oxley Act – enacted by US Congress in 2002

ITIL and COBIT n While ITIL is about process best practice, COBIT is about control points n Procedures are mapped by ITIL best practices n Risks can be defined through Metrics n Software tool for ITIL management provide Control Evidence and Audit Logs

Integration of Development and Support Best Practices Application Management Lifecycle Elegantly Integrates ITIL and CMMI

ITIL and Six Sigma n ITIL Best Practice allows rapid adoption n No need to develop from scratch n ITIL defines metrics used as Six Sigma CTQs (“y”) and also for causes (“x”) n ITIL process management software tool provides data for necessary analyses n Application of Six Sigma require mature environment CTQ – “Critical to Quality” (as defined by customer)

Deployment of Frameworks n Parts of Frameworks can be applied as needed and incrementally n Even partial implementations of Frameworks can provide major benefits for superior Governance n Business goals decide what to adopt n Any Framework implementation is a major effort n Strong and committed leadership is not just crucial, it is absolutely mandatory to achieve superior governance

Support Infrastructure is a Must for Deployed Frameworks n Successful deployments require that the processes be: n Aligned – ensuring process objectives address business needs n Streamlined – through adoption of best practice n Mapped – through mapping of tasks for workflows and role assignments n Verified – by various organizational functions to meet their business requirements n Owned – by assigning formal roles for accountability n Documented – for consistency of implementation throughout the organization n Measured – to ensure that the process is effective and efficient while meeting compliance A support infrastructure essentially includes a number of formal roles such as the champions, process owners, process managers and others – depending on the nature of the framework and the organization

Integration of Frameworks – An Example in an ITIL Process

Metrics – Crucial to Manage Processes and Frameworks n Metrics Determine Process Health or Framework Maturity n 3M Principle – Measure-to-Monitor-to- Manage n To manage, one needs to monitor n To monitor, one needs to measure n ITIL Best Practices also provide relevant and well-defined Metrics for IT processes Continuous improvement is NOT possible without appropriate metrics

Examples of Applying 6σ Based Metrics Traditional Chart for Outage

Examples of Applying 6σ Based Metrics Statistical Chart (Boxplot) for Outage

Examples of Applying 6σ Based Metrics Traditional Outage Chart by Platform

Examples of Applying 6σ Based Metrics Outage Boxplot by Platform

Examples of Applying 6σ Based Metrics Xbar-R Control Chart – Internal Outages Weeks

Examples of Applying 6σ Based Metrics Xbar-R Control Chart – Int. & Ext. Outages Weeks

Agenda n Why have IT Governance? n What is IT Governance? n Various elements of IT Governance n Frameworks for IT Governance n How Frameworks interact n How IT processes underpin IT Governance n Example of Framework integration n Metrics to measure IT process health

Questions?