One of the first tasks in the development of an Information Technology (IT) Governance Policies and Procedures Manual is to map the business goals for the organization to the IT goals and make sure that they are in alignment. To perform this step, it is n
PMG IT GOVERNANCE AND PROCEDURES PLAN 8
Course Name
Course Number
PMG IT Governance Policies and Procedures Plan
Student Name
Date
Table of Contents The Project Outline 2 Company Description 2 Summary of the Company IT System 3 Governance Framework 4 Accountability IT Governance Framework 4 Why the Accountability Framework for PMG Company 5 Business and IT Goals 5 IT and Information Security Governance 6 Policy and Procedure Governance 6 Computer Use Policy 7 Examples 7 Enforcement 8
The Project Outline
Company Description
PMG is a privately held New Orleans, Louisiana-based enterprise that specializes in a number of IT-oriented services and products provided. Featuring prominently in the company’s product and services list is the development of financial management software, supply of Wi-Fi internet to rural communities, local area network design and management and online marketing services. The company was founded in 2008, and in 2009 raised $77 million from Oak Investment Partners in funding and has since penetrated the IT industry effectively to open branches in Baton Rouge, Lake Charles and Houma all in Louisiana. The company has also gained favorable expansion journey in the state of Mississippi has opened three branch offices located in Jackson, Tupelo, and Columbus respectively. The company’s current annual revenue stands at $175 million with a gross annual turnover value of $665 million. Key investment strategies are underway with the primary objective being an expansion to the northern states and finally the Canadian market as a gateway to the international market.
Summary of the Company IT System
The company’s IT infrastructure has exponentially expanded over the few years the company has been in active business. With a total of six branches located in six cities spread across two states, the company had to find an efficient way of installing and managing the massive IT infrastructure to their advantage. Currently, the company owns three most advanced routers by latest technology, the Asus ROG Rapture GT-AC5300, an infinite data center in the New Orleans headquarters, over 750 PCs spread across all the branches and offices, Wi-Fi ISP infrastructure, printers, sophisticated enterprise management system and other accompanying network devices such as printers, switches, intelligent hubs and many more.
Regarding data use, the company categorizes its data into three main categories: client data, third party data, and the company’s internally generated data. The data generally use in the company addresses activities such as access to the data, legal data manipulation for a specific goal and the storage of the same data. Inside the company, all employees have the freedom of using company data to make their own decisions. The relationship between the management and its employees is totally based on trust since there are no rules and regulations put in place to govern data use and liabilities in case of impropriety. There is one data center belonging to the company. Each and every employee has unrestricted access to the datacenter hence may access all kinds of data and manipulate them as they wish. The general belief shared by the management and the employees is that every decision made by an employee is guided by the principles of ethical correctness hence no bad characters can think of harming the firm in whatever way.
Governance Framework
The IT Governance Framework, which basically is a conceptual structure meant to issue guidance and controls to current and future use of the IT infrastructure inside PMG Company. Ordinarily, the main pillars of the IT Governance Framework are individual decision making and being accountable to the decisions made. There are different types of frameworks of IT Governance that a company can adopt. The most popular types include authorization framework, IT controls framework, accountability framework and process-based framework. Given the company’s background, which embraces freedom and trust to individual abilities to make the right decisions, the PMG Company chooses to adopt the Accountability IT Governance Framework.
Accountability IT Governance Framework
Good governance practice demands accountability for various outcomes of a process while at the same time maintain mutual respect for the decisions that were made to come up with such an outcome. The framework focuses on the clarification of the roles and responsibilities each member of a system played to deliver certain results. Going ahead, the framework issues guidance on who can be charged with the responsibilities of leading the process of achieving the next set of goals and objectives basing such undertakings on audit findings of the previous assignment. The same mechanism can be used in effecting value correction steps. In the most justifiable manner, the operating model helps in separating out responsibilities while identifying the so-called “touch-points” among processes and processes’ area responsibilities. Normally, numerous processes and process areas are usually caused to interact to offer necessary support to the operating model. In such circumstances, the objective of an excellent IT governance structure is to efficiently and effectively avail the IT resources towards the achievement of the strategic objectives set by the organization.
Why the Accountability Framework for PMG Company
As indicated earlier, the business strategy of the PMG Company is to decide on goals and objectives to be met, assign the available workforce responsibilities, give each employee the necessary freedom and resource support to work towards the achievement of such goals and objectives. The IT Governance Framework yet to be adopted by the organization exactly agrees with such a position. The only important business management element the framework adds is being accountable to decisions made during the process of operation. The accountability element silently activates the principles of controls and authorization in a kinder manner.
Business and IT Goals
In the current contemporary society, which is largely characterized by complexity and constantly changing ways of doing business, every business executive thinks of how best IT can be aligned to business to escalate the pace of achieving core business objectives (Murtagh et al., 2018). In view of the same, the PMG critically explores options of having its strategic plan reflect on the company’s business goals aligned to its IT goals for the sole purpose of achieving its mega expansion plans of going international. Being an IT based firm, its common knowledge that the biggest department in the company is that of IT. Putting the above into perspective, the company therefore, have had its IT department set goals such as eliminating all IT related redundancies by first quarter of the year, implement a pure One Shortest Path First (OSPF) and Enhanced Interior Gateway Routing Protocol (EIGRP)-based network to halve the cost of company network maintenance cost by the end of second fiscal quarter. The IT department goals go hand in hand with the general company business goals of cutting the cost of internal operations to save as much money as possible for the implementation of core business objective which is running aggressive marketing that would result to international market invasion.
IT and Information Security Governance
The IT information security management and IT information security governance is usually two different concepts mistakenly used interchangeably. The former concerns itself with decision making processes that result to addressing concerns of security to the organization’s IT infrastructure while the latter points to responsibilities of individuals mandated to ensure IT information security agenda are well undertaken (Pol, 2016). The PMG Company IT Department is headed by competent fellows with a wealth of experience in information system security matters. The mandate of the individuals concerned with such responsibilities is guided by old company information policy rules which details accountability framework and oversight to risk mitigations. However, the rules remain behind of time; therefore, a review exercise is long overdue.
Policy and Procedure Governance
Ideally, information governance details the step by step process through which company information can be handled. The policy particularly concerns itself with special category information like client data, employee data, and many others. Further, the policy and procedure provide a framework containing a provision of how confidential information can be dealt with both legally and securely. The purpose of policy and governance procedure document is to ensure the establishment of a governance framework where the company and its stakeholders’ engagement is properly defined and guided by policies known to all the parties with the intention of reinforcing the accountability and individual responsibility in making decisions.
Computer Use Policy
In support of the company’s mission of providing a solution to every human problem technologically, the company has in place an elaborate computer use policy that focuses on rights and responsibilities pegged on existing legal policies. Putting it into perspective, the application of this policy is largely based on the ethical spirit of doing what is universally accepted at all times (Maras, 2015). However, the policy cites common mistakes that people find themselves making almost on a daily basis which are in total contradiction of what is legally permissible as gross misconduct and may bear legal action or invite internal disciplinary action.
Examples of such include:
• A user is opting for a computer account that he or she is prohibited from using.
• Illegally acquiring a password of a computer account without the owner’s knowledge or authority.
• Using the PMG Company network to acquire illegal access to other computer systems within any of the branch offices.
• Intentionally indulging in an act with known capability of subverting normal operation of computers, terminals, peripherals, or networks.
• Deliberately running unauthentic programs on a computer system or network of the company, or granting access to another user, which can damage the company computer system or network.
• Attempting to circumvent data protection schemes or uncover security loopholes.
• Violating terms of applicable software licensing agreements or copyright laws.
• Intentionally damaging computing resources.
• Engaging in bullying or harassing others through the use of electronic mail or social media.
• Hiding the identity of an account or machine.
Enforcement
The policy also addresses itself adequately on matters of enforcing it which includes internal disciplinary mechanism with defined eventual possibilities depending on the outcomes and also a legal action if crime can be detected from the act.
References
Kam, H. J., Katerattanakul, P., & Hong, S. (2016). IT Governance Framework: One Size Fits All?.
Maras, M. H. (2015). Computer Forensics. Jones and Bartlett Learning.
Murtagh, M. J., Blell, M. T., Butters, O. W., Cowley, L., Dove, E. S., Goodman, A., ... & Mangino, M. (2018). Better governance, better access: practising responsible data sharing in the METADAC governance infrastructure. Human genomics, 12(1), 24.
Pol, B. H. T. (2016). Information Governance Policy. Assessment.