iT Governance discussion on LinkedIn

I asked a question about IT governance on linked in as a lead-up to my presentation at the last sungard summit. Here’s a the full trasncript from linkedin Question/Answer:

What is IT Governance ?

I am aware that this same question was asked over a year ago, and that there were some responses to it. However, as we all know, one year is a long time and so many things have changes. So I am asking the question all over again. 
What is IT Governance and how is it done in your environment (Business, School, your clients etc). What future do you see for IT Governance and what is the place of IT Governance in overall Enterprise Governance? 
Which of the following would you consider as a governance framework : 
COBIT, ITIL/Prince / ISO 27000 series etc (any others?) 
Would you/your company pay for an IT Governance Consultant/Professional etc?

Sorry, there are no polls available at the moment.

Answers

A1There is a good and concise article on Wikipedia that explains the IT governance in a short and snappy way: 

Information Technology Governance, IT Governance or ICT (Information & Communications Technology) Governance, is a subset discipline of Corporate Governance focused on information technology (IT) systems and their performance and risk management. The rising interest in IT governance is partly due to compliance initiatives, for instance Sarbanes-Oxley in the USA and Basel II in Europe, as well as the acknowledgment that IT projects can easily get out of control and profoundly affect the performance of an organization. 

- The IT Infrastructure Library (ITIL) is a detailed framework with hands-on information on how to achieve a successful operational Service management of IT, developed and maintained by the United Kingdom’s Office of Government Commerce, in partnership with the IT Service Management Forum. 
- Control Objectives for Information and related Technology (COBIT) is another approach to standardize good information technology security and control practices. This is done by providing tools to assess and measure the performance of 34 IT processes of an organization. The ITGI (IT Governance Institute) is responsible for COBIT 
- The ISO/IEC 27001 (ISO 27001) is a set of best practices for organizations to follow to implement and maintain a security program. It started out as British Standard 7799 ([BS7799]), which was published in the United Kingdom and became a well known standard in the industry that was used to provide guidance to organizations in the practice of information security. 
- The IT Baseline Protection Catalogs, or IT-Grundschutz Catalogs, (“IT Baseline Protection Manual” before 2005) are a collection of documents from the German Federal Office for Security in Information Technology (FSI), useful for detecting and combating security-relevant weak points in the IT environment. The collection encompasses over 3000 pages with the introduction and catalogs. 
- The Information Security Management Maturity Model ISM3 is a process based ISM maturity model for security. 
- AS8015-2005 Australian Standard for Corporate Governance of Information and Communication Technology. AS8015 was adopted as ISO/IEC 38500 in May 2008 
- ISO/IEC 38500:2008 Corporate governance of information technology, (very closely based on AS8015-2005) provides a framework for effective governance of IT to assist those at the highest level of organizations to understand and fulfill their legal, regulatory, and ethical obligations in respect of their organizations’ use of IT. ISO/IEC 38500 is applicable to organizations from all sizes, including public and private companies, government entities, and not-for-profit organizations. This standard provides guiding principles for directors of organizations on the effective, efficient, and acceptable use of Information Technology (IT) within their organizations. 

Hope this helps 
Samer Karawi (G&K)

 


A2“IT Governance, is a subset discipline of Enterprise Governance focused on Information Technology and their performance and risk management”. It can be also define as “the leadership and organisational structures and processes that ensure that the organisation’s IT sustains and extends the organisation’s strategies and objectives”. Proper IT Governance is required for compliance. 

The characteristic theme of IT governance discussions are - 
1. IT capability can no longer be a black box. 
2. Traditional involvement of board-level executives in IT issues was to defer all key decisions to the company’s IT professionals. 
3. IT governance implies a system in which all stakeholders, including the board, internal customers, and in particular departments such as finance, have the necessary input into the decision making process. 

Major advantages of IT Governance are - 
1. This prevents IT from independently making and later being held solely responsible for poor decisions. 
2. It also prevents critical users from later complaining that the system does not behave or perform as expected, as explained in the Business Requirement. 

It should align properly with the business and act as a positive catalyst. This is the right way to do it. 

Since today IT is the backbone of any business it is equally important as Enterprise Governance. IT Governance is an undividable part of Enterprise Governance. With the time it’s become more and more mature. 

I consider CobiT as an IT Governance Framework. 

The question of paying consultant \professional for IT Governance completely depends on company strategy. You can always take the help from third party consultants but it is highly recommended to have an in-house dedicated team which is the key factor for the success. Team includes champion (i.e. leader), board members, implementers, responsible managers, internal auditors and others as required.

Messages from Lopa Mudra Basu (1):


A3The is a much shorter and simpler answer: 

Enterprise IT Architecture Framework is (or should be) responsible for who is doing what, why, when, where and how. 

Enterprise IT Governance Framework is (or should be) responsible that all this is really happening as planned.

Messages from Wolf Rivkin (1):


A4Governance is the body of rules, agreements and standards that defines the interaction between people, departments, roles and functions with your organisation. 
The frameworks you mention all deal with specific areas or levels of governance within an organisation. For instance ITIL focuses on IT Operations and Prince on project management. 
An IT governance consultant (who might actually be an IT Strategist or Enterprise Architect) would be able to select and situate the most useful existing frameworks within an overall governance framework that reflects your business environment.

A5don’t pay through the nose for expensive stuff you don’t need. I can teach you simple ways to do “IT governance” with slightly modified existing forum and wiki. The heart of the matter is smart methodology, not expensive software. 

Then, if you got more money, I can design and project manage building of a custom system for $5K that will be lightyears ahead of anything that’s on the market. Then we sell this system to other people and you/your company gets half the profits. How does that sound?

Messages from Michael Lyubomirskiy (1):


A6Check out the definition by Weill & Ross, who emphasize that IT governance is about the framework to ensure the proper use of IT, explicitly naming culture as important. 

Also: check ISO38.500 (ISO standard for IT Governance). 

Regards, 

Michiel

Links:

 

A7The definition of governance has not changed. It is the actions you take and the associated ability to demonstrate that you are exercising control over your activities, that all your activities are directed towards achieving the goals of your organization and that all your resources are being used for that purpose. 

There is no one single governance framework that I know of. To achieve good governance you have to put together the different components in different areas that will allow you achieve governance. COBIT, ITIL/ISO:IEC 2000, CMMI, SOX, ISO9000, SIX SIGMA TQM, EFQM, etc. those are all frameworks and methodologies that bring one or more aspects of governance to your organization. Once you know what targets you need to achieve to maintain governance, you pick the frameworks and methodologies you need based on your requirements.

Messages from Juan Jimenez (1):

 

A8Look at ISO38500 which was released in 2008, as a high level standard. 

38500 defines governance overall, building upon the seminal defintion in Cadbury, a UK report from the early 1990s. 

In my opinion 38500 provides an excellent overall framework within which a number of other tools/frameworks can be utilised such as COBIT, etc 

Critical though to my mind is that none of these approaches work unless there a a culture of ethics and integrity within an organization. The frameworks and processes must be accompanied by a values based approach, else the desired objectives may well not be achieved, or if achieved not be as successful as they might. 

You may find this link to an ISACA presentation I made on this subject helpful. 

Happy to help at anytime

Links:

Clarification added 2 months ago:

There are useful resources at the IT Governance Institute website

Post to Twitter Tweet This Post Post to Plurk Plurk This Post Post to Yahoo Buzz Buzz This Post Post to Delicious Delicious Post to Digg Digg This Post Post to Facebook Facebook Post to MySpace MySpace Post to Ping.fm Ping This Post Post to Reddit Reddit Post to StumbleUpon Stumble This Post

6 Responses to “iT Governance discussion on LinkedIn”

  1. LilSnoop says:

    I didn’t understand the concluding part of your article, could you please explain it more?

  2. The article is really a discussion from my question on linkedin. Which part exactly would you like me to explain. I will be very happy to oblige. You may quote the section you need additional clarification on. Thanks :)

  3. vemma says:

    I just book marked your blog on Digg and StumbleUpon.I enjoy reading your commentaries.

  4. lcd reviews says:

    I just sent this post to a bunch of my friends as I agree with most of what you’re saying here and the way you’ve presented it is awesome.

  5. scuba diving says:

    You certainly deserve a round of applause for your post and more specifically, your blog in general. Very high quality material

  6. ownsahi says:

    cool site
    http://needman.ru сайты знакомств американские мужчины
    Брак сайте

Sorry, the comment form is closed at this time.

  • © 2010 LAGBAJA (sombody) - akowe Suffusion WordPress theme by Sayontan Sinha
    This blog is monetized using Are-PayPal WP Plugin SEO Powered by Platinum SEO from Techblissonline