Biotech Company Situational Analysis
Harrisburg University ISEM 547
IT Governance
Objectives
What is IT Governance
Key Stakeholders & Respective Concerns
Importance of IT Governance
Benefits of IT Governance
Best Practices
IT Governance Areas (High-level Frameworks)
Governing Entities in an Organization
Defining Charters for Governing Entities
2
IT Governance
3
What is IT Governance?
4
IT Principles (Alignment & Value Delivery)
Data/Information Governance
Application Governance
IT Architecture Governance
IT Financial Governance
Project Portfolio Governance
Infrastructure Governance
Process Governance
Contract & Procurement
Governance
Vendor/Supplier Governance
Service Governance
Security
Risk Management
Audits & Compliance
Continuity
Sustainability
Ethics
Performance
Capabilities
Legal Regulatory
IT Governance
IT Decisions & Outcomes
What is IT Governance?
IT Governance is a subset discipline of Corporate Governance
IT Governance covers the culture, organization, policies, and practices that provide the proper due diligence, controls, oversight, and transparency of IT
Ultimately it is the responsibility of the Board of Directors to ensure that IT is adequately governed
5
What is IT Governance?
IT Governance is not a one-time exercise or something achieved by a mandate or setting of rules.
It requires a commitment from the top of the organization
IT Governance is an ongoing activity that requires a continuous improvement in responses to the fast-changing business and IT environments
IT Governance can be integrated within a wider Enterprise Governance approach, and support the increasing legal and regulatory requirements of Corporate Governance
6
IT Governance Framework (Key Areas)
Data/Information Governance
Application Governance
Architecture Governance
Service Governance
Infrastructure Governance
Vendor/Supplier Governance
Financial Governance
Project & Portfolio Governance
Process Governance
Contracts & Procurements Governance
7
What is IT Governance?
Definitions:
IT Principles are a related set of high-level statements about how IT is used in the business to achieve its goals and objectives.
IT Infrastructure refers to an enterprise's entire collection of hardware, software, networks, data centers, facilities and related equipment used to develop, test, operate, monitor, manage and/or support business and IT services.
IT Architecture is an organized set of consensus decisions on policies & principles, services & common solutions, standards & guidelines as well as specific vendor products used by IT providers both inside and outside the organization to support business and IT services.
IT Services A set of related functions provided or facilitated by the IT organization in support of one or more business areas. IT technical and professional services enable organizations in the creation, management and optimization of or access to information and business processes.
IT service management (ITSM) refers to the entirety of activities – directed by policies, organized and structured in processes and supporting procedures – that are performed by an organization or part of an organization to plan, design, build, deliver, operate and control IT services offered to customers.
8
IT Governance
Purpose & Importance of IT Governance
9
What is Purpose of IT Governance?
In every organization, IT governance must address eight interrelated IT decisions:
IT Principals & Controls
IT Services
IT Architecture
IT Infrastructure
Business Applications
Data/Information
Cybersecurity
IT Investment & Prioritization
These decisions are critical to the success of the digital enterprise
10
What is Purpose of IT Governance?
IT Governance purpose is to ensure that the proper processes, controls, procedures, polices, legal, and management practices are in place.
Key areas auditor’s look at regarding IT governance:
Alignment (all areas)
Risk Management
IS/IT Management
Financial Management
Vendor/Supplier Management
Data/Information Security
Resource Management
Compliance
11
Importance of IT Governance?
Increased corporate awareness of cyber security and other IT related risks
Validate protection, acquisition, or replacement strategies of IT assets
Improve the management and control of IT activities (indirect or direct impact on business outcomes)
Improve clarity and transparency regarding significant IT decisions
Ensure accountability, ownership, and clarity of responsibilities for IT services, projects, and investments
Promote consistent architecture and utilization of industry standards
Better understanding of the value delivered by IT, both internally and from external suppliers
Cost controls and operational efficiency
Proper management of IT assets and investments
Compliance with internal and external auditors and regulators
12
IT Governance
Stakeholders of IT Governance
13
Stakeholders of IT Governance?
Top level business leaders
Investors and public relations
Internal and external auditors and regulators
Middle level business and IT management
Business partners and suppliers
Shareholders
Customers/Citizens
Auditors
14
Concerns of Stakeholders
Availability, security and continuity of Business and IT services
Costs and measurable returns on investments
Quality and reliability of services
IT inability to respond to business needs
Identification and management of IT related risks to the business
Compliance to legal, regulatory and contractual requirements
Responsiveness and nimbleness to changing conditions
Use and protection of customer data, information, and other corporate computing assets
15
IT Governance
Benefits of IT Governance
16
Benefits of Governance
IT Governance Specialist Development Group (SDG) has outlined some key benefits associated with IT Governance:
Transparency and Accountability
Return on Investment/Stakeholder Value
Enhancement and protection of reputation and image
Improved outcomes regarding key IT governance decisions
17
Benefits of Governance
Enhancement and protection of reputation and image
Improved transparency and outcomes regarding key IT governance decisions
Expansion of Business Opportunities & Partnerships
Performance Improvement
Ensure Compliance (Internal & External)
18
IT Governance
Best Practices of IT Governance
19
Best Practices of IT Governance
An enterprise wide approach should be adopted
Top level commitment backed up by clear accountability is a necessity
An agreed IT Governance and control framework is required
20
Best Practices of IT Governance
Trust needs to be gained for the IT function (in house and/or external)
Stakeholder Management
Establish Process Governance & Assessment Method
21
Process Governance and Assessments?
22
Best Practices of IT Governance
Creating IT Governance Program
Secure executive sponsorship with clear direction, goals, and objectives for establishing an enterprise IT governance program
Establish IT Governance Steering Committee (Cross-functional representation)
Define the strategy for establishing the enterprise IT governance program with CFS (e.g., governing bodies and frameworks, IT policy lifecycle management, risk management, and key IT areas)
Coordinate with key stakeholders to define an executable transition roadmap and timeframes
Establish a deliverables based project plan using a phased approach
Celebrate accomplishments and leverage lessons learned for course corrections and continuous improvement
23
Benefits of Corporate Governance
What key areas should be incorporated into your organization’s IT governance framework?
Has anyone been a part of a IT governing body (e.g., board, committee, workgroup)?
What was the purpose of the IT governing body and what decisions did they make?
Outline some key areas auditor’s look at regarding IT governance?
Why is IT Governance important?
What are some of the key benefits that can be derived from IT Governance?
24
Group Discussion Questions
IT Governance Frameworks
Governing Bodies
25
IT Governance Framework
IT governance framework should have defined governing entities specific to IT domain and governance decision areas
Membership will be based on organizational positions, roles, and subject matter expertise
Purpose, objectives, membership, decision authority, interrelationship, meeting frequency should all be defined in a charter for each governing body
Each governing body should have a designated Chair Person or Coe-Chairs appointed
Charters should be reviewed and signed by executive management
It is not uncommon to have IT managers serve on multiple governing bodies or participate on a needs be bases for matters that cross domain boundaries
Arbitration and final decision authority rests with an executive steering committee or board
IT governance frameworks should be structured to push decisions to the lowest level possible based on the predefined criteria (e.g., thresholds, policy, authority, type, elevation conditions, etc.)
Alignment of IT portfolios and change management processes are vital for effective IT governance frameworks (e.g., services, applications, security, policy, infrastructure, architecture)
26
IT Governance Framework
27
Information Technology Executive Board
Data/Information Committee
Enterprise Security Committee
Architecture & Infrastructure Committee
Enterprise IT Services Committee
Enterprise Application Committee
Business & IT Strategic Plans
IT Portfolios
IT Finance & Budget
IT Contracts & Procurements
Recommending bodies with limited delegated decision authority
Decision Making Body
Senior Executive Team
IT Service Governance Framework?
28
Data Governance Framework?
29
IT Governance Framework - Matrix
30
| Governing Entity | Purpose | Scope/Jurisdiction | Responsibilities | Decisions | Deliverables | Membership | Inter-Relationship |
| Business & IT Executive Board | |||||||
| Data/Information Committee | |||||||
| Enterprise Application Committee | |||||||
| Architecture & Infrastructure Committee | |||||||
| Enterprise Security Committee | |||||||
| Enterprise IT Services Committee |
IT Governance Matrix
Creating Governance Entity Charters
31
What is a Charter ?
A formal document that defines a governing entity granting certain rights, privileges, and authority to monitoring the actions, policies, practices, and decisions of organizations.
Defines its purpose, responsibilities, composition, and mandates its function(s) and lays down rules for its conduct and delegation of authority.
Charters are usually authorized or revoked by corporate executives
32
Charter Elements
Each governance entity within and organization should have a charter document with executive approval
IT Governance charter document contains the following sections:
Governance Entity Name
Purpose
Scope/Jurisdiction
Objectives
Responsibilities
Decision Authority
Membership Chair Person(s) & Members (appointments and rotation)
Deliverables
Structure (meeting frequency and location)
Relationships (Other governing entities)
Executive Signatures (CEO, CIO, COO, etc.) & Dates
Version Control
The organization who is responsible for policy lifecycle management usually facilitate the creation and maintenance of the IT Governance Charters
33
Benefits of Corporate Governance
What happens when there is a lack of collaboration and synergy between these governing entities?
Why is it important to have a governance matrix and charters defined for your IT governance framework?
34
Group Discussion
Assignments
Chapter 8 (IT Managers Handbook)
Homework 3: Corporate & IT Governance Frameworks
Project 2:
Part A: Create an IT Governance Matrix
Part B: Create a Governance Charter for Enterprise Security Committee
Part C: Write a Information Security Policy for Data Classifications
35