IT GOVERNANCE GSI 615 Carmen R. Cintrón Ferrer © 2014-2015.

Slides:



Advertisements
Similar presentations
IT Governance & Quality Management
Advertisements

Chapter 3 E-Strategy.
Module N° 4 – ICAO SSP framework
Life Science Services and Solutions
First create and sign up for a blue host account Through the help of Blue Host create a WordPress website for the business After you created WordPress.
12 August 2004 Strategic Alignment By Maria Rojas.
Auditing Governance Functions
BENEFITS OF SUCCESSFUL IT MODERNIZATION
Chapter 10 Accounting Information Systems and Internal Controls
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
V i s i o n ACCOMPLISHED ™ Portfolio Management Breakthroughs Shelley Gaddie President Project Corps Pacific Northwest Portfolio Management Roundtable.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Connecting People With Information DoD Net-Centric Services Strategy Frank Petroski October 31, 2006.
IT Governance Navigating for Value Michael Vitale 6 May 2003 CIO Conference Steering the Enterprise Through Stormy Seas Image source: Access2000.
By Collin Smith COBIT Introduction By Collin Smith
Interoperability. Martin Sykes Information architecture programs suffer from EA's worst problem: They have a strategic and enterprisewide focus that.
IT Governance: Simultaneously Empowers and Controls Source: IT Governance, Chapter 1.
Information Security Governance and Risk Chapter 2 Part 1 Pages 21 to 69.
Managing the Information Technology Resource Course Introduction.
Click to add text © 2010 IBM Corporation OpenPages Solution Overview Mark Dinning Principal Solutions Consultant.
Competency Models Impact on Talent Management
Control environment and control activities. Day II Session III and IV.
Information Technology Audit
Getting Smarter with Information An Information Agenda Approach
Developing Enterprise Architecture
Reinventing with Outsourcing YES BANK Experience Balaji V Vice President, Business Services July 4, 2005.
© 2010 Plexent – All rights reserved. 1 Change –The addition, modification or removal of approved, supported or baselined CIs Request for Change –Record.
Carmen R. Cintrón Ferrer © 2014
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Information Security Governance 25 th June 2007 Gordon Micallef Vice President – ISACA MALTA CHAPTER.
The Evergreen, Background, Methodology and IT Service Management Model
TTBIZLINK PROJECT MINISTRY OF TRADE, INDUSTRY, INVESTMENT & COMMUNICATIONS.
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
Continual Service Improvement Process
Project Portfolio Management as a Form of Collaborative Value Management Apply Rules IT Budget Allocation Collaborative Decision Making Manage Cost, Risk.
“Business Performance Management” Corporate Performance Management “The Importance of Integrity” Facilitated by: Warren White VP – Change Acceleration.
Organize to improve Data Quality Data Quality?. © 2012 GS1 To fully exploit and utilize the data available, a strategic approach to data governance at.
IT Governance
The Challenge of IT-Business Alignment
Operational Excellence and Sustainable Performance Improvement Date: 9 June, 2009.
Roles and Responsibilities
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
Overview of COBIT5 and Impact on Local Content for IT By Mrs Tokunbo Martins Director Banking Supervision (Central Bank of Nigeria)
ISO17799 Maturity. Confidentiality Confidentiality relates to the protection of sensitive data from unauthorized use and distribution. Examples include:
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
Introduction to the Continual Service Improvement Toolkit Welcome.
EPA Geospatial Segment United States Environmental Protection Agency Office of Environmental Information Enterprise Architecture Program Segment Architecture.
IT GOVERNANCE  Objective : The objective of this area is to ensure that the Certified Information Systems Auditor ( CISA ) candidate understands and can.
Align Business and Information Technology – with SOA Pradeep Nair Director – Software Group (IBM India/SA)
Kathy Corbiere Service Delivery and Performance Commission
Matakuliah : Pengantar IT Governance
12-CRS-0106 REVISED 8 FEB 2013 APO (Align, Plan and Organise)
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
CSI - Introduction ITIL v3.
Info-Tech Research Group1 Manage the IT Portfolio World Class Operations - Impact Workshop.
© | Hansan Global | All Rights Reserved 1 INTRODUCTION TO IT SERVICE MANAGEMENT Hansan Global Pte Ltd.
Current risk and compliance priorities for law firms PETER SCOTT CONSULTING.
1 Patricia Alafaireet, PhD  After completing this section of the course, students will be able to Understand the role and value of committed organizational.
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
MEASURING BPM SOFTWARE ROI AND ITS BENEFITS IN RISK MANAGEMENT PROCESS AUTOMATION Contact us at | Web : | Tel: 1.
ForrTel: IT Governance Frameworks
LECTURE 5 Nangwonvuma M/ Byansi D. Components, interfaces and integration Infrastructure, Middleware and Platforms Techniques – Data warehouses, extending.
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
Building Business Transformation Capabilities Our perspective on the building blocks, structure and critical success factors to impact change Gillian.
Strategic Information Systems Planning
Challenges and opportunities for the CFO
Integrated Management System and Certification
IT Governance at the SCO
IT Governance CIS 9002 Kannan Mohan Department of CIS
Enterprise Architecture at Penn State
Presentation transcript:

IT GOVERNANCE GSI 615 Carmen R. Cintrón Ferrer ©

IT Governance Wrap-up Carmen R. Cintrón Ferrer, , Reserved Rights

IT Governance - ¿Mi problema?Mi problema Carmen R. Cintrón Ferrer, , Reserved Rights  Basic IT Governance (Video)Video  IT Governance Models:  Weill & Ross Model (Video)Video  ITGi - ISACA  ITIL (Simplified) (Simple Explanation)SimplifiedSimple Explanation  COSO (Templates)Templates  Business IT Alignment (Video) (6-Reasons it may be impossible to do)Video6-Reasons it may be impossible to do

IT Governance – ISACA/ITGi ISACA/ITGI - Cobit ® IT Governance Model Carmen R. Cintrón Ferrer, , Reserved Rights

IT Governance Components IT Value Delivery Risk Management Performance Management IT Strategic Alignment Stakeholder Value Drivers ISACA/ITGI - Cobit ® IT Governance Model Carmen R. Cintrón Ferrer, , Reserved Rights

IT Business Alignment – Principles The Technology Garden, Collins et als. Carmen R. Cintrón Ferrer, , Reserved Rights  Get the Basics Right – Sound IT Delivery and Trust  Create a common Language – Build a Business Model & Avoid “Technobabble”  Establish a peer relationship – engage IT in business & drive the business through change and transformation  Coordinate goals and objectives  Manage IT as business driven portfolio  Foster relationships with key suppliers

Carmen R. Cintrón Ferrer, , Reserved Rights Gain Trust from the Business Understand and Reflect the Business Engage the Business Drive the Business IT Business Alignment – Goals The Technology Garden, Collins et als.

Carmen R. Cintrón Ferrer, , Reserved Rights IT Business Alignment – Achieving Aligment The Technology Garden, Collins et als. Vision/MissionBusiness Model Business/IT Model Business Strategy Division Strategies IT Capability Investments IT Supported Changes IT Services Expectations

Carmen R. Cintrón Ferrer, , Reserved Rights  Is IT management doing the right things?  Are they doing them the right way?  Are they being done well?  Are we getting benefits?  Has IT become a business enabler?  I s the IT infrastructure secure/reliable? IT Governance issues

IT Expectations vs. Reality Carmen R. Cintrón Ferrer, , Reserved Rights  Expectations:  Exploit IT for Business value  Fast development with quality and security  IT investment provides ROI – does mores with less  Increase efficiency and productivity with value and effectiveness  Reality:  Failure to bring innovation  Unmet deadlines and/or higher costs  Inadequate technology or fast obsolence  Poor support to Business and/or damaged reputation, losses  Negative impact on effectiveness and upon competitive position

How to assure and measure IT Value Carmen R. Cintrón Ferrer, , Reserved Rights  Adopt an IT Governance Framework:  Structures that contribute to strategy implementation  Control measures for IT investment, opportunity, benefits and risks  Sustains current operation and builds for the future  Align IT with business goals:  Stakeholder value drivers  Value delivery  Risk Management – embed responsibilities within the organization to achieve risk transparency  Measure Results:  Focus on core IT Competencies  IT Processes  Performance measurement (Balanced Business Scorecard)

IT governance model IT Principles High level statements about how IT is used in the business (against which all IT initiatives should be judged – does initiative A support the articulated principles?) IT Architecture Organizing logic for data, applications and infrastructure captured in a set of policies and relationships, and technical choices to achieve desired business and technical standardization and integration (deviations from standards should be fully justified and implications fully understood). IT Infrastructure Decisions Centrally coordinated, shared IT services that provide the foundation for the enterprises IT capability (promoting reuse of components) Business Application Needs Specifying the business need for purchased or internally developed IT applications (adhering to IT architecture where appropriate) IT Investment & Prioritization Decisions about how much and where to invest in IT, including project approvals and justification techniques (ensuring that all projects that have a technology implication are fully considered, and to ensure that the portfolio is appropriately balanced [applications, technology, large - small, low -high risk]) © MIT Sloan School Centre for Information Systems Research Carmen R. Cintrón Ferrer, , Reserved Rights

Department and IT Alignment Carmen R. Cintrón Ferrer, , Reserved Rights IT – Business Team

IT Architecture Carmen R. Cintrón Ferrer, , Reserved Rights Infrastructure Integration Technologies Customer Interfaces Web & Customer Management Business Intelligence & Dashboards Applications Network & Devices Security Enterprise Resources Planning Customer Services Platforms

IT Performance Alignment Carmen R. Cintrón Ferrer, , Reserved Rights Business Strategy Alignment Activities IT Operations IT Strategy Business Operations

IT Resources Management Carmen R. Cintrón Ferrer, , Reserved Rights  Balance the cost of Infrastructure with the quality of service required for successful value delivery  Optimizing Knowledge and Infrastructure:  Staffing, Skills, Training – IT Personnel  Assets – Reuse/Buy/Make: Enterprise Resources Planning (ERP) Provider/Vendor /Partner Management  IT Project Management

IT Controls Carmen R. Cintrón Ferrer, , Reserved Rights  Internal Controls:  Control objectives and activities to comply with Laws, Regulations and Internal Policies  Controls Automation is when internal controls are automated (are integral part of systems)  Compliance Testing:  Procedures (manual or automated) used to verify and/or demonstrate that controls and activities are operating as intended  Compliance automation:  Automated measures of internal controls effectiveness  Automatic Reporting  External Controls integration  Remediation planning

IT Value Delivery Carmen R. Cintrón Ferrer, , Reserved Rights

 Risk Allocation:  Contracts  Service Level Agreements  Cloud and Hosting  Risk Mitigation - security & control practices  Risk Transfer - insurance & liability  Risk Assurance - audit & certification  Risk Acceptance:  Formal  Transparent IT Risk Management

IT Metrics Carmen R. Cintrón Ferrer, , Reserved Rights Financial PerformanceProject Performance Operational Performance User Satisfaction Strategic Links

IT Governance Carmen R. Cintrón Ferrer, , Reserved Rights

IT Governance Scenario A national retail bank in India, with hundreds of subsidiaries and branches, decided to automate its operations and move its services online. Since most of its services are common across all its branches, the bank decided to implement a Service Oriented Architecture (SOA) to increase the interoperability. It was decided that the corporate IT group would be in charge of execution of the complete project, including the implementation of SOA and definition of its services. Needless to say, the project started with much optimism and excitement. However six months into the project, it ran into roadblocks. Cracks started to become visible. There were frequent disagreements among the various business units on who is responsible for defining and administering the SOA services. Who is responsible for the overall governance of the project? Some groups have also questioned corporate IT’s shortsightedness of not carefully considering the complexity of integrating existing applications built across diverse platforms and technologies. The need for a clear IT strategy and technology roadmap was clearly felt. A year later, the project was scrapped. It became impossible to execute the project without a well-defined IT Roadmap, Enterprise Architecture and IT Governance mechanisms. What went wrong? A national retail bank in India, with hundreds of subsidiaries and branches, decided to automate its operations and move its services online. Since most of its services are common across all its branches, the bank decided to implement a Service Oriented Architecture (SOA) to increase the interoperability. It was decided that the corporate IT group would be in charge of execution of the complete project, including the implementation of SOA and definition of its services. Needless to say, the project started with much optimism and excitement. However six months into the project, it ran into roadblocks. Cracks started to become visible. There were frequent disagreements among the various business units on who is responsible for defining and administering the SOA services. Who is responsible for the overall governance of the project? Some groups have also questioned corporate IT’s shortsightedness of not carefully considering the complexity of integrating existing applications built across diverse platforms and technologies. The need for a clear IT strategy and technology roadmap was clearly felt. A year later, the project was scrapped. It became impossible to execute the project without a well-defined IT Roadmap, Enterprise Architecture and IT Governance mechanisms. What went wrong? Pritam Dey, using Technology Transformation Effectively to Improve Business – IT Alignment, 2009

IT Governance Scenario IT Roadmap A technology roadmap was not clearly defined. How would the existing applications be integrated/upgraded? How would the bank stay attuned with constantly evolving technology? Service Oriented Architecture (SOA) Was the decision to implement SOA carefully considered by taking into account the interoperability and a need for a federation of resources? Was an SOA Governance Structure created to resolve trust issues across teams? How would the SOA security issues be handled? IT Governance Was a clearly defined Governance structure established to ensure that the organization’s IT sustains the organization’s strategies and objectives? Did the board understand the overall architecture of its company’s IT applications portfolio? IT - Business Alignment Did the organization take a broader view of the business strategies and objectives and realize how IT is going to sustain and extend them ? Was there a sincere effort to increase the value of IT projects and reduce the gap between IT and business? Pritam Dey, using Technology Transformation Effectively to Improve Business – IT Alignment, 2009 Carmen R. Cintrón Ferrer, , Reserved Rights