Establishing a strategy involves assessing where you are, where you want to be and planning how to bridge the gap.
An overview of an IT strategy framework is described below.
External Biz Environment + External IT environment = Org Strategy (Note 1)
Org Strategy leads into Biz Process & Systems (Note 2)
Current IT Assessment leads into Implementation Programmes which interacts with strategic justification.
Org Strategy + Biz Process & Systems + Current IT Assessment (Note 3) = IT Strategy and the Strategic Justification (Note 4) interacts with the IT Strategy (Note 5)
IT Strategy leads into Implementation Programme (Note 6)
Note 1 - Org strategy (Organisational objectives, KPIs, critical sucess factors)
Note 2 - Biz Process & Systems (A structured representation of departments and workflows
Note 3 - Current IT assessment (position, processes, people, tools, governance, control environment and an indication as to what extent IT systems support the organisational needs)
Note 4 - Strategic Justification - The business case. Would include a top-down review, cost/benefit analyses and responsibility assignments for benefit realisation.
Note 5 - IT Strategy - Physical and logical application and data architecture, IT management, IT organisation and IT policies.
Note 6 - Implementations Programmes - Description of key projects to realise IT strategy. Possibly groupings of projects into programmes. Resources required.
Showing posts with label Ch4. Show all posts
Showing posts with label Ch4. Show all posts
Friday, January 11, 2013
Sunday, January 6, 2013
Governance Strategy
Strategically, the board should be providing the governance framework for the IT function.
Surveys have shown that Boards and Audit Committees may not have the skills required to understand and challenge IT risk and that the means of communicating IT risks to the Board may not be effective.
However, there are some high level considerations. Firstly is the aspirations of the function. There are three levels. These are
Surveys have shown that Boards and Audit Committees may not have the skills required to understand and challenge IT risk and that the means of communicating IT risks to the Board may not be effective.
However, there are some high level considerations. Firstly is the aspirations of the function. There are three levels. These are
- Basic
- Central
- World Class
ValIT
ValIT which was issued by ISACA attempts to align IT governance with wider business objectives. It attempts to
- define the relationship between information technology and the business and those functions in the organisation with governance responsibilities.
- manage an organisation’s portfolio of information technology-enabled business investments.
- maximise the quality of business cases for information technology-enabledbusiness investments with particular emphasis on the definition of key financial indicators, the quantification of soft benefits and the comprehensive appraisal of the downside risk.
CobiT
CobiT has four main elements to it
- Plan & Organise (e.g. system architecture, governance)
- Acquire & Implement (e.g. maintenance plan, execution)
- Deliver & Support (e.g. security and training)
- Monitor & Evaluate (e.g. Independent assessments)
Governance
IT governance is about the management of IT systems. The following are critical elements of good IT governance.
There are three notable codes and standards related to IT governance.
- Monitoring and enforcement of IT policies and procedures
- Organisational culture which encourages good behaviour
- Assessment of performance
- Tone at the top
There are three notable codes and standards related to IT governance.
| A number of further points can be made about governance strategy. |
Policies & Procedures
The benefits of IT policies and procedures are that it
-
- shows that management take these matters seriously
- helps staff to take appropriate actions to manage IT risks effectively
- helps management take suitable disciplinary or legal action if wrong-doing has occurred in relation to the use of company IT systems.
- Acceptable use (incl email)
- Electronic connectivity
- Monitoring and control
- Software (including system development)
- Retention
- ISMS
- IS security (includes a number of other elements such as cryptography, computer forensics, access control, clear desk and third party)
- Business Continuity
- writing the policy
- making updates &
- communicating updates
Subscribe to:
Posts (Atom)