Showing posts with label Ch4. Show all posts
Showing posts with label Ch4. Show all posts

Friday, January 11, 2013

IT Strategy

Establishing a strategy involves assessing where you are, where you want to be and planning how to bridge the gap.

An overview of an IT strategy framework is described below.

External Biz Environment + External IT environment = Org Strategy (Note 1)

Org Strategy leads into Biz Process & Systems (Note 2)

Current IT Assessment leads into Implementation Programmes which interacts with strategic justification.

Org Strategy + Biz Process & Systems + Current IT Assessment (Note 3)  = IT Strategy and the Strategic Justification (Note 4) interacts with the IT Strategy (Note 5)

IT Strategy leads into Implementation Programme (Note 6)

Note 1 - Org strategy (Organisational objectives, KPIs, critical sucess factors)

Note 2 - Biz Process & Systems (A structured representation of departments and workflows

Note 3 - Current IT assessment (position, processes, people, tools, governance, control environment and an indication as to what extent IT systems support the organisational needs)

Note 4 - Strategic Justification - The business case. Would include a top-down review, cost/benefit analyses and responsibility assignments for benefit realisation.

Note 5 - IT Strategy - Physical and logical application and data architecture, IT management, IT organisation and IT policies.

Note 6 - Implementations Programmes - Description of key projects to realise IT strategy. Possibly groupings of projects into programmes. Resources required.



Sunday, January 6, 2013

Governance Strategy

Strategically, the board should be providing the governance framework for the IT function.

Surveys have shown that Boards and Audit Committees may not have the skills required to understand and challenge IT risk and that the means of communicating IT risks to the Board may not be effective.

However, there are some high level considerations. Firstly is the aspirations of the function. There are three levels. These are
  • Basic
  • Central
  • World Class
Within IT governance is the development of an IT strategy.



ISO 38500

ISO 38500 relates to Corporate Governance Of IT. It sets out 6 principles for good corporate governance.
  • Strategy
  • Performance
  • Responsibility
  • Acquisition
  • Conformance
  • Human Behaviour

ValIT

ValIT which was issued by ISACA attempts to align IT governance with wider business objectives. It attempts to
  • define the relationship between information technology and the business and those functions in the organisation with governance responsibilities.
  • manage an organisation’s portfolio of information technology-enabled business investments.
  • maximise the quality of business cases for information technology-enabledbusiness investments with particular emphasis on the definition of key financial indicators, the quantification of soft benefits and the comprehensive appraisal of the downside risk.
Publications, tools and guidance are provided to support this standard.

CobiT

CobiT has four main elements to it
  • Plan & Organise (e.g. system architecture, governance)
  • Acquire & Implement (e.g. maintenance plan, execution)
  • Deliver & Support (e.g. security and training)
  • Monitor & Evaluate (e.g. Independent assessments)
CobiT has 34 processes and 210 control objectives.

Governance

IT governance is about the management of IT systems. The following are critical elements of good IT governance.
  • Monitoring and enforcement of IT policies and procedures
  • Organisational culture which encourages good behaviour
  • Assessment of performance
  • Tone at the top
To support the above, suitable organisational and management structures are required as are clear performance goals. A major governance challenge that is faced by many organisations is the lack of IT knowledge or understanding at board level. This can lead to ineffective management of IT. An organisation might wish to consider having IT report at board level, provide the board themselves with IT training and involve them in the formation of the IT audit plan.

There are three notable codes and standards related to IT governance.
A number of further points can be made about governance strategy.





Policies & Procedures

The benefits of IT policies and procedures are that it -
  • shows that management take these matters seriously
  • helps staff to take appropriate actions to manage IT risks effectively
  • helps management take suitable disciplinary or legal action if wrong-doing has occurred in relation to the use of company IT systems.
Here are some policies and procedures you might expect in an organisation;
  • Acceptable use (incl email)
  • Electronic connectivity
  • Monitoring and control
  • Software (including system development)
  • Retention
  • ISMS
  • IS security (includes a number of other elements such as cryptography, computer forensics, access control, clear desk and third party)
  • Business Continuity
All policies should be owned by an individual within the organisation. They are responsible for
  • writing the policy
  • making updates &
  • communicating updates
It is generally best policy to ensure that policies are updated regularly (usually at least annually) and that users of the policy provide written confirmation to confirm they have read and understood policy updates when they happen. These policies and procedures can be backed up with terms and conditions to employment.