IT Governance & Quality Management

Slides:



Advertisements
Similar presentations
Connecting Phoenix to Information IT Governance in a Decentralized Organization Charles T. Thompson Chief Information Officer City of Phoenix.
Advertisements

Ministry of Public Sector Development Public Sector Development Program Better Government Delivering Better Result.
Session No. 4 Implementing the State’s Safety Programme Implementing Service Providers SMS
Copyright The Info-Tech Research Group Inc. All Rights Reserved. D1-1 by James M. Dutcher Strategic IT Planning & Governance Creation H I G H.
A presentation for CIOs. What are the biggest challenges that face a modern CIO? (Lets list them…)
ISACA All rights reserved. Unlocking the Value of Technology Investments Speaker Name/Title Date.
Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
12 August 2004 Strategic Alignment By Maria Rojas.
Internal Control–Integrated Framework
CUPA-HR Strong – together!
Auditing Governance Functions
Information Technology Governance What? Why? How? What’s Next? Information Services Committee April 21, 2006.
Chapter 10 Accounting Information Systems and Internal Controls
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
©2006 OLC 1 Process Management: The Foundation for Achieving Organizational Excellence Process Management Implementation Worldwide.
Certified Business Process Professional (CBPP®) Study Session Part 4 Sept. 15, 2010.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
IT Governance and Management
IT Governance: Simultaneously Empowers and Controls Source: IT Governance, Chapter 1.
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
Aust. AM Collaborative Group (AAMCOG) An introduction to ISO “What to do” guide 20th October 2014.
COBIT Framework Introduction. Problems with IT? – Increasing pressure to leverage technology in business strategies – Growing complexity of IT environments.
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
How can projects be controlled?
Enterprise Architecture
Corporate Governance: Beyond Compliance at a time of Recession Prof. Ashley G. Frank BA(Econ)[Magna Cum Laude], MDPA (Cum Laude], MBA, MCom [Cum Laude],
COBIT® 5 for Risk Introduction
Information Technology Audit
Internal Auditing and Outsourcing
Strategy for Excellence Leadership Development & Succession Planning Carl L. Harshman & Associates.
INFORMATION SECURITY GOVERNANCE (ISG) Relates to the security of information systems Is an element of corporate governance.
Information Security Governance 25 th June 2007 Gordon Micallef Vice President – ISACA MALTA CHAPTER.
Leaders Facilitate the Planning Process
© 2011 Cengage Learning. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part.
Integrated Capability Maturity Model (CMMI)
Strategic Planning. Definitions & Concepts Planning: is a scientific approach for decision making. Planning: is a scientific approach for decision making.
Continual Service Improvement Process
Global Risk Management Solutions Risk Management and the Board of Director: Moving Beyond Concepts to Execution Anton VAN WYK Partner, Global Risk Management.
Professional Certificate – Managing Public Accounts Committees Ian “Ren” Rennie.
IT Governance
The Challenge of IT-Business Alignment
INTERNAL CONTROL OVER FINANCIAL REPORTING
Chapter 5 Internal Control over Financial Reporting
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Auditing services for assurance in evaluation of companies’ information systems (technologies) efficiency Kherson State University Samchynska Yaroslava.
Roles and Responsibilities
M A N A G E M E N T M A N A G E M E N T 1 st E D I T I O N 1 st E D I T I O N Gulati | Mayo | Nohria Gulati | Mayo | Nohria Chapter 10 Chapter 10 PERFORMANCE.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
DRAFT – For Discussion Only HHSC IT Governance Executive Briefing Materials DRAFT April 2013.
1 Information Technology (IT) Auditing & Control Instructor: Dr. Princely Ifinedo Cape Breton University (CBU)
Information Management at Information Management at Tim Brennan Data Administration Tim Brennan Data Administration DAMA-I Symposium & Wilshire Meta Data.
Environmental Management System Definitions
IT GOVERNANCE SIMULTANEOUSLY EMPOWERS AND CONTROLS Pertemuan ke-1 & 2 Matakuliah: Pengantar IT Governance Tahun: Feb
IT GOVERNANCE  Objective : The objective of this area is to ensure that the Certified Information Systems Auditor ( CISA ) candidate understands and can.
Samantha Schreiner University of Illinois at Urbana- Champaign BA 559 – Professor Michael Shaw December 15 th, 2008 A Survey of IT Governance Through COBIT,
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
SACS-CASI Accreditation and the Library Media Program in Public Schools Laura B. Page.
Kathy Corbiere Service Delivery and Performance Commission
Matakuliah : Pengantar IT Governance
12-CRS-0106 REVISED 8 FEB 2013 APO (Align, Plan and Organise)
2/20/2016 Leveraging IT Governance and COBIT Chip Council, PhD, CGEIT, CISM, CISA Matt Schmidt, MS, CISSP, CISA Adjunct Professors, University of Minnesota.
Page 1 Portfolio Committee on Water and Environmental Affairs 14 July 2009.
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
ForrTel: IT Governance Frameworks
IT ALIGNMENT: IT Governance
BIL 424 NETWORK ARCHITECTURE AND SERVICE PROVIDING.
Transforming IT Management
CORPORATE & ACADEMIC GOVERNANCE STRUCTURE
Presentation transcript:

IT Governance & Quality Management Lekture 1 Introduction 25/03/2017 IT-University of Copenhagen

IT-University of Copenhagen Learning opjective After the course the student should be able to: • Describe IT governance control structures and mechanisms in a company • Describe quality management structures and mechanisms in a company • Explain the value of IT governance and quality management • Describe industry standards for IT process models (e.g. CoBIT and ITIL) and development and test of IT systems (e.g. Agile, V-model) • Analyze the contents of quality related standards and compliance requirements. Reflect on the significance of quality standards and compliance requirements. • Recommend an IT governance setup for a given situation • Recommend an quality management approach in a given situation  25/03/2017 IT-University of Copenhagen 2

IT-Governance in a context Six key assets Human Financial Physical Intellectual property IT Relationships Ross & Weill Componets 25/03/2017 IT-University of Copenhagen

IT-Governance in a context 5 Key assets People, Portfolios and Processes: The 3P Model of IT Governance  http://www.isaca.org/Journal/Past-Issues/2008/Volume-2/Pages/People-Portfolios-and-Processes-The-3P-Model-of-IT-Governance1.aspx 25/03/2017 IT-University of Copenhagen

One definition of IT architecture ” The fundamental organization of a system represented by its components, their relationships to each other and to the environment, and the principles that govern the system design and development. " ANSI/IEEE Std 1471-2000 superseded by ISO/IEC/IEEE 42010:2011, Systems and software engineering — Architecture description. 25/03/2017 IT-University of Copenhagen

IT-University of Copenhagen Strategy IT Business In reality, e-government is a somewhat strange animal … We need to find ways to ride this animal. EA is seen as a way to go ahead 25/03/2017 IT-University of Copenhagen 6 6

In conclusion Conant-Ashby Theorem ”every good regulator of a system has to have a model of that system” Our ability to control a system depends on understanding that system This means that we need to understand all facets of The systems - not only the technical 25/03/2017

“Now! …. That should clear up a few things around here!” 25/03/2017 IT-University of Copenhagen 8

IT-University of Copenhagen What is IT-Governance For who by who The Goals of IT-Governance The importens of IT-Governance 25/03/2017 IT-University of Copenhagen

IT-University of Copenhagen What is IT-Governance Information technology governance is a subset discipline of corporate governance focused on information technology (IT) systems and their performance and risk management. The rising interest in IT governance is partly due to compliance initiatives, for instance Sarbanes-Oxley in the USA and Basel II in Europe, but more so because of the need for greater accountability for decision-making around the use of IT in the best interest of all stakeholders. 25/03/2017 IT-University of Copenhagen

IT-University of Copenhagen Definitions Specifying the decision rights and accountability framework to encourage desirable behavior in the use of IT.“ Weill and Ross "… the leadership and organizational structures and processes that ensure that the organization's IT sustains and extends the organization's strategies and objectives.” The IT Governance Institute "an integral part of corporate governance and addresses the definition and implementation of processes, structures and relational mechanisms in the organization that enable both business and IT people to execute their responsibilities in support of business/IT alignment and the creation of business value from IT enabled investments". Van Grembergen and De Haes (2009) "The system by which the current and future use of ICT is directed and controlled. It involves evaluating and directing the plans for the use of ICT to support the organization and monitoring this use to achieve plans. It includes the strategy and policies for using ICT within an organization.” the Australian Standard for Corporate Governance of Information and Communication Technology 25/03/2017 IT-University of Copenhagen

Key Players Involved with IT Governance IT governance occurs at different layers. Project Managers and Team leaders report to and receive direction from their managers; managers’ report up to the CIO’s; and the CIO’s report to executives, who report to the board of directors. Reporting includes descriptions of any activities that show signs of deviating from targeted objectives. Each level, when reporting these deviations, includes recommendations for action that must be endorsed by the governing bodies above. Stakeholders play a part in IT governance. At the heart of the governance responsibilities of setting strategy, managing risks, allocating resources, delivering value and measuring performance, are the stakeholder values, which drive the enterprise and IT strategy. Sustaining the current business and growing into new business models are certainly stakeholder expectations and are achieved with adequate governance of the IT infrastructure. 25/03/2017 IT-University of Copenhagen

The goals of IT-Governance The primary goals for information technology governance are to (1) assure that the investments in IT generate business value, and (2) mitigate the risks that are associated with IT. This can be done by implementing an organizational structure with well-defined roles for the responsibility of information, business processes, applications, ICT infrastructure, etc. Accountability is the key concern of IT governance. 25/03/2017 IT-University of Copenhagen

IT University of Copenhagen Desirable behaviors Embody the: Beliefs Culture Defined and enacted though: Strategy Corporate value statements Mission statements Business principles Rituals structures Det er mennesker der driver værket. Der er nogen der tror at det er strategy der driver værket men 3/25/2017 IT University of Copenhagen 14 14

Mechanisms for governance of the key assets Structures Processes Committee Procedures audits And more These key assets need mechanisms to be governed and used and it is the senior executive teams’ task. Many of these mechanisms are possible to use within several of the assets but within some of the areas it is necessary to have unique mechanisms. 3/25/2017 IT University of Copenhagen 15 15

IT Governance Effective IT governance must address three questions: What decisions must be made to ensure effective management of IT? Who should make these decisions? How will these decisions be made and monitored? But before that - Why A common answer to the second question “what”, is that IT Governance is the aligning of corporate and IT strategy. This is true but it is more complex than that. The third question “how” is even more difficult to answer than the “what” question. Among other things it has to ensure that IT Governance does not turn into IT segregation. Tools like portfolio management, risk management, balanced scorecard and change management could be used. Finally the “when” questions answer should be now! (Butler Group, 2003) 3/25/2017 IT University of Copenhagen 16 16

Why is IT Governance important? New information technologies bombard enterprises with new business opportunities IT is Pervasive IT is Expensive Looking ahead, the influence of IT on enterprise performance will continue to grow Leading Enterprises Govern IT differently - Find the right balance Senior Management has limited bandwidth 2 Ting: Hvis virksonheder skulle reagere på alle tendenser, skulle de skifte deres infrastructur hver dag  De bliver nød til at kunne beregne Cost/benefits. De skal være fleksible 3/25/2017 IT University of Copenhagen 17 17

Why is IT-Governance important? "IT-Governance is the most important factor in generating business value from IT” “IT-Governance can actually deliver on the longtime management paradox of encouraging and leveraging the ingenuity of all the enterprises people while ensuring compliance with the overall vision and principles” 3/25/2017 IT University of Copenhagen 18 18

Framework for the key IT Governance decisions Forklar at principper er styrende, men at der godt kan bubble behov/ønsker op fra business, der skaber behov/ønsker om ny it frastrukture. Der igen skaber bevægelse I de andre felter. 3/25/2017 IT University of Copenhagen 19 19

IT University of Copenhagen 3/25/2017 IT University of Copenhagen 20

Four IT Architecture Stages

Define Your Operating Model