SlideShare une entreprise Scribd logo
1  sur  27
Télécharger pour lire hors ligne
19-21 September Ghent Belgium




                IT Governance
         “How to deal with IT Value and IT Risk”


                                        Erik Guldentops
                                        Lecturer
                                        Antwerp Management School

   Erik
Guldentops   IT Governance Briefing                     eg_19092012 page 1 of 27
Enterprise Governance of IT
                                      Strategic alignment
                                      Defining with the
                                      businsess how to
                                      achieve value while
Five                                  mitigating risk

domains but                           Performance Mngnt
                                      Measuring how desired
really only                           value is achieved and
                                      risk contained
two subjects
                                      Resource Mngnt
                                      Acquiring and
                                      maintaining all that is
                                      necessary to achieve
                                      value and contain risk



   Erik
                Risk and Value
Guldentops   IT Governance Briefing            eg_19092012 page 2 of 27
Erik
Guldentops   IT Governance Briefing   eg_19092012 page 3 of 27
IT Governance vs. IT Management
                                IT GOVERNANCE
                    Set Objectives
                    • IT is aligned with the business
                    • IT enables the business and maximises benefits
                    • IT resources are used responsibly
     Evaluate       • IT-related risks are managed appropriately             Provide
   performance                                                              direction




   Measure and                                                              Translate
      report                                                              direction into
   performance      Translate strategy into action                           strategy
                    • Increase automation (make the business
                      effective)
                    • Decrease cost (make the enterprise efficient)
                    • Manage risks (security, reliability & compliance)
                               IT MANAGEMENT




   Erik
Guldentops   IT Governance Briefing                                          eg_&9092012 pg 4 of 27
Enterprise Governance of IT
        Board




   Executive




       Line
Management

    Erik
 Guldentops   IT Governance Briefing   eg_&9092012 pg 5 of 27
Implementing Enterprise
                Governance of IT
                          How do we know
     Where do we              we are             What are we
     want to be?           progressing?         doing about it?

                        •Delivery Performance    Portfolio
                        •Service Quality
                                                 • Programmes
     Objectives         •Resource Utilisation
                        •Benefits Realisation    • Services
                        •Risk Reduction          • Resources

       Strategy              Scorecards         Business Cases

                         Are the engines of IT Governance


   Erik
Guldentops   IT Governance Briefing                      eg_&9092012 pg 6 of 27
Implementing Enterprise
                                                Governance of IT
             Metrics
                                                   Inputs
                                                                   WHAT

               ?                                              Outputs



                       Responsibility &
    Goals                                     Activities
                        Accountability


               ?                                            Performance

                                                                    HOW

             Metrics
                                      needs a process structure
   Erik
Guldentops   IT Governance Briefing                                     eg_&9092012 pg 7 of 27
Implementing Enterprise Governance of IT
                                                       BUSINESS OBJECTIVES AND
                                                       GOVERNANCE OBJECTIVES

 COBIT
ME1   Monitor and evaluate IT
                                                                                                              PO1 Define a strategic IT plan.
      performance.
                                                                                                              PO2 Define the information
ME2   Monitor and evaluate internal                               INFORMATION                                      architecture.
      control.
                                                                                                              PO3 Determine technological direction.
ME3   Ensure compliance with external
      requirements.                                  Efficiency                       Integrity               PO4 Define the IT processes,
                                                                                                                   organization, and relationships.
ME4   Provide IT governance.                       Effectiveness                    Availability
                                                                                                              PO5 Manage the IT investment.
                                                           Compliance          Confidentiality
                                                                                                              PO6 Communicate management aims
                                                              Reliability                                          and direction.
                                        MONITOR                                                      PLAN     PO7 Manage IT human resources.
                                          AND                                                        AND      PO8 Manage quality.
                                        EVALUATE                                                   ORGANIZE
                                                                                                              PO9 Assess and manage IT risks.
DS1 Define and manage service levels.
                                                                       IT                                     PO10 Manage projects.
DS2 Manage third-party services.                                   RESOURCES
DS3 Manage performance and
     capacity.
DS4 Ensure continuous service.
DS5 Ensure systems security.
                                                                     Applications
DS6 Identify and allocate costs.                                                                              AI1 Identify automated solutions.
                                                                     Information
DS7 Educate and train users.                                        Infrastructure                            AI2 Acquire and maintain application
DS8 Manage the service desk and                                         People                                    software.
     incidents.                                    DELIVER                                                    AI3 Acquire and maintain technology
                                                                                          ACQUIRE
DS9 Manage the configuration.                        AND                                                          infrastructure.
                                                                                            AND
DS10 Manage problems.                              SUPPORT                               IMPLEMENT            AI4 Enable operation and use.
DS11 Manage data.                                                                                             AI5 Procure IT resources.
DS12 Manage the physical environment.                                                                         AI6 Manage changes.
DS13 Manage operations.                                                                                       AI7 Install and accredit solutions and
                                                                                                                  change.


     Erik
  Guldentops                 IT Governance Briefing                                                                           eg_&9092012 pg 8 of 27
Implementing Enterprise
                                     Governance of IT




                                        www.isaca.org
   Erik
Guldentops   IT Governance Briefing            eg_&9092012 pg 9 of 27
CobiT can be
               overwhelming


   Erik
Guldentops   IT Governance Briefing   eg_19092012 page 10 of 27
CobiT can be
               overwhelming


   Erik
Guldentops   IT Governance Briefing   eg_19092012 page 11 of 27
CobiT QuickStart
             for Small and Medium Sized Enterprised




                                      One objective
                                      Four practices
                                      Three critical success factors
                                      Two metrics
   Erik
Guldentops   IT Governance Briefing   A simple progress measure
                                                       eg_&9092012 pg 12 of 27
Suitability
CobiT QuickStart                                 Assessment
                       Span of control
                       Communications path
Applicable to          IT Sophistication
                       IT Strategic Importance
  whom?                IT Expenditure
                       Segregation


              Sanity
              Check
                                                                   Risk
                                                             Liabilities
                                                          Compliance
                                                        Past Problems
                                                         Future Needs
                                                    Required Expertise

    Erik
 Guldentops      IT Governance Briefing                                    eg_&9092012 pg 13 of 27
What did 70                                                        CISO



CIO’s say about                                                             CIO
IT Frameworks ?
                             IT Governance   Service Delivery   Information Security

   CIONet Survey, Sep 2011     CobiT              ITIL               ISO27001




   Erik
Guldentops      IT Governance Briefing                                    eg_&9092012 pg 14 of 27
Why implement
an IT
Governance
Framework?




                                      CIONet Survey, Sep 2011

   Erik
Guldentops   IT Governance Briefing                             eg_&9092012 pg 15 of 27
What were the expected and actual benefits?
                                     Improved




                     EFFICIENCY
                                     enterprise
                                     processes
                                     Extended staff
                                     capabilities

                                     Better service
                                     delivery
                     EFFECTIVENESS


                                     Faster solution
                                     delivery

                                     Increased
                                     innovation

  expected
                     RISK




                                     Reduced risk
    actual
                                                       CIONet Survey, Sep 2011

   Erik
Guldentops   IT Governance Briefing                                              eg_&9092012 pg 16 of 27
How did they
measure
benefits?




   CIONet Survey, Sep 2011

   Erik
Guldentops      IT Governance Briefing   eg_&9092012 pg 17 of 27
Relationship IT Governance Practices and Benefits
                                     Clustered Correlations
        PROCESS
                     • Define a strategic IT plan
                     • Manage the IT investment
                     • Communicate management aims and direction
           IT

                     • Assess and manage IT risks
                     • Identify automated solutions
                     • Acquire & maintain applications and infrastructure
                     • Portfolio and investment management


                     • Align the IT strategy to the business strategy
        GOAL




                     • Provide service offerings and service levels in line with business
         IT




                       reqrmnts
                     • Acquire, develop and maintain IT skills that respond to the IT strategy
                     • Ensure that IT demonstrates continuous improvement and readiness for
                       future change



                     • Cost optimisation of service delivery and business processes
       BUSINESS




                     • Obtain reliable and useful information for strategic decision-making
         GOAL




                     • Improve and maintain business process functionality and operational
                       productivity
                     • Enable and manage business change


                                                            IT Governance Institue, Sep 2008

   Erik
Guldentops        IT Governance Briefing                                                 eg_&9092012 pg 18 of 27
IT Governance Implementation: Lessons Learned

             •   Common language and common framework
             •   Higher maturity
             •   Better organisation
             •   More useful management information
             •   “IT really works”


             •   Complexity
             •   Less results than expected
             •   High learning curve managers
             •   Bogged down in details/paperwork
             •   High level of senior management support required
                                          CIONet Survey, Sep 2011

   Erik
Guldentops   IT Governance Briefing                                 eg_&9092012 pg 19 of 27
IT Governance Implementation: Lessons Learned


          Adoption of frameworks is not a
          simple nor self-contained project
         with measured costs. It is a gradual
          shift and inter-relates with many
                   other initiatives.



   Erik
Guldentops   IT Governance Briefing       eg_&9092012 pg 20 of 27
Some notes on Risk and Value




                                      CIONet Survey, Sep 2012

   Erik
Guldentops   IT Governance Briefing                             eg_&9092012 pg 21 of 27
Some notes on Risk and Value




       For both riskand value, accept uncertainty and deal with it!
   Erik
Guldentops   IT Governance Briefing                       eg_&9092012 pg 22 of 27
IT Value
                                      Research

   Erik
Guldentops   IT Governance Briefing       eg_&9092012 pg 23 of 27
IT Value
               Research

   Erik
Guldentops   IT Governance Briefing   eg_&9092012 pg 24 of 27
www.isaca.org
   Erik
Guldentops   IT Governance Briefing   eg_&9092012 pg 25 of 27
So what is the ROI on IT Governance Practices?

  In October 2006 Mc Kinsey and the London School of Economics
   measured the increase in productivity from investments in IT
  versus investments in management practices in 100 enterprises.




                               +
                               Management Practices Score
             75th percentile                                     +8%               +20%1
                  and above




             25th percentile                                       0                +2%
                  and above




                                         -                      Intensity of IT deployment        +

                                                            25th percentile     75th percentile
                                                              and above           and above




   Erik
Guldentops   IT Governance Briefing                                                                   eg_&9092012 pg 26 of 27
19-21 September Ghent Belgium




                IT Governance
         “How to deal with IT Value and IT Risk”


                                        Erik Guldentops
                                        Lecturer
                                        Antwerp Management School

   Erik
Guldentops   IT Governance Briefing                     eg_19092012 page 27 of 27

Contenu connexe

Tendances

IT Metrics Presentation
IT Metrics PresentationIT Metrics Presentation
IT Metrics Presentation
jmcarden
 
IT governance and bal
IT governance and balIT governance and bal
IT governance and bal
sourov_das
 
Improve IT Business Alignment With An Infrastructure Roadmap
Improve IT Business Alignment With An Infrastructure RoadmapImprove IT Business Alignment With An Infrastructure Roadmap
Improve IT Business Alignment With An Infrastructure Roadmap
Info-Tech Research Group
 
Optimize Change Management
Optimize Change ManagementOptimize Change Management
Optimize Change Management
Info-Tech Research Group
 
Create a Winning BPI Playbook
Create a Winning BPI PlaybookCreate a Winning BPI Playbook
Create a Winning BPI Playbook
Info-Tech Research Group
 
What Is It Governance Introduction
What Is It Governance   IntroductionWhat Is It Governance   Introduction
What Is It Governance Introduction
nicxenos
 

Tendances (20)

Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
 
What is IT Governance?
What is IT Governance?What is IT Governance?
What is IT Governance?
 
IT Governance Introduction
IT Governance  IntroductionIT Governance  Introduction
IT Governance Introduction
 
IT Governance Vs IT Management Presentation V0.1
IT Governance Vs IT Management   Presentation V0.1IT Governance Vs IT Management   Presentation V0.1
IT Governance Vs IT Management Presentation V0.1
 
IT Metrics Presentation
IT Metrics PresentationIT Metrics Presentation
IT Metrics Presentation
 
IT governance and bal
IT governance and balIT governance and bal
IT governance and bal
 
Stateofthecio2008 1210987739793979 8
Stateofthecio2008 1210987739793979 8Stateofthecio2008 1210987739793979 8
Stateofthecio2008 1210987739793979 8
 
Improve IT Business Alignment With An Infrastructure Roadmap
Improve IT Business Alignment With An Infrastructure RoadmapImprove IT Business Alignment With An Infrastructure Roadmap
Improve IT Business Alignment With An Infrastructure Roadmap
 
Build a Business-Driven IT Risk Management Program
Build a Business-Driven IT Risk Management ProgramBuild a Business-Driven IT Risk Management Program
Build a Business-Driven IT Risk Management Program
 
Optimize Change Management
Optimize Change ManagementOptimize Change Management
Optimize Change Management
 
IT Governance – The missing compass in a technology changing world
 IT Governance – The missing compass in a technology changing world IT Governance – The missing compass in a technology changing world
IT Governance – The missing compass in a technology changing world
 
Create a Winning BPI Playbook
Create a Winning BPI PlaybookCreate a Winning BPI Playbook
Create a Winning BPI Playbook
 
It governance
It governanceIt governance
It governance
 
Info-Tech Membership Overview
Info-Tech Membership OverviewInfo-Tech Membership Overview
Info-Tech Membership Overview
 
IT Governances
IT GovernancesIT Governances
IT Governances
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance Framework
 
IT Performance Measurement using IT Governance Metric
IT Performance Measurement using IT Governance MetricIT Performance Measurement using IT Governance Metric
IT Performance Measurement using IT Governance Metric
 
IT Governance Presentation
IT Governance PresentationIT Governance Presentation
IT Governance Presentation
 
What Is It Governance Introduction
What Is It Governance   IntroductionWhat Is It Governance   Introduction
What Is It Governance Introduction
 
Governance Of Enterprise Information Technology V3
Governance Of Enterprise Information Technology V3Governance Of Enterprise Information Technology V3
Governance Of Enterprise Information Technology V3
 

Similaire à IT governance by Erik Guldentops

Isys40051 12 is suppliers & outsourcing v2
Isys40051 12 is suppliers & outsourcing v2Isys40051 12 is suppliers & outsourcing v2
Isys40051 12 is suppliers & outsourcing v2
Grenville Lannon
 
Irish Government Cloud Strategy Perspective
Irish Government Cloud Strategy PerspectiveIrish Government Cloud Strategy Perspective
Irish Government Cloud Strategy Perspective
Gar Mac Críosta
 
4. it governance a compass without a map v.2.6 pink elephant
4. it governance a compass without a map v.2.6   pink elephant4. it governance a compass without a map v.2.6   pink elephant
4. it governance a compass without a map v.2.6 pink elephant
aventia
 
Microsoft Dynamics Academic Alliance: Job Roles
Microsoft Dynamics Academic Alliance: Job RolesMicrosoft Dynamics Academic Alliance: Job Roles
Microsoft Dynamics Academic Alliance: Job Roles
Frederik De Bruyne
 
From Value Governance To Benefits Realization In A Controlled Environment
From Value Governance To Benefits Realization In A Controlled EnvironmentFrom Value Governance To Benefits Realization In A Controlled Environment
From Value Governance To Benefits Realization In A Controlled Environment
George Papoulias
 

Similaire à IT governance by Erik Guldentops (20)

IT Governance - OpenThinking Day
IT Governance - OpenThinking DayIT Governance - OpenThinking Day
IT Governance - OpenThinking Day
 
SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
 
Isys40051 12 is suppliers & outsourcing v2
Isys40051 12 is suppliers & outsourcing v2Isys40051 12 is suppliers & outsourcing v2
Isys40051 12 is suppliers & outsourcing v2
 
Benefits Identification, Assessment, Validation and Realisation for Informati...
Benefits Identification, Assessment, Validation and Realisation for Informati...Benefits Identification, Assessment, Validation and Realisation for Informati...
Benefits Identification, Assessment, Validation and Realisation for Informati...
 
Company presentation Morgan Clark & Company
Company presentation Morgan Clark & CompanyCompany presentation Morgan Clark & Company
Company presentation Morgan Clark & Company
 
Irish Government Cloud Strategy Perspective
Irish Government Cloud Strategy PerspectiveIrish Government Cloud Strategy Perspective
Irish Government Cloud Strategy Perspective
 
Cobi t riskmanagementframework_iac
Cobi t riskmanagementframework_iacCobi t riskmanagementframework_iac
Cobi t riskmanagementframework_iac
 
Gestión de Gobierno, Riesgos y Reglamentaciones (GRC)
Gestión de Gobierno, Riesgos y Reglamentaciones (GRC)Gestión de Gobierno, Riesgos y Reglamentaciones (GRC)
Gestión de Gobierno, Riesgos y Reglamentaciones (GRC)
 
4. it governance a compass without a map v.2.6 pink elephant
4. it governance a compass without a map v.2.6   pink elephant4. it governance a compass without a map v.2.6   pink elephant
4. it governance a compass without a map v.2.6 pink elephant
 
Enpower Process Consulting Profile
Enpower Process Consulting ProfileEnpower Process Consulting Profile
Enpower Process Consulting Profile
 
How to implement measurements to drive value
How to implement measurements to drive valueHow to implement measurements to drive value
How to implement measurements to drive value
 
ITSM Conference, Dubai, UAE 2009
ITSM Conference, Dubai, UAE   2009ITSM Conference, Dubai, UAE   2009
ITSM Conference, Dubai, UAE 2009
 
IS Unified "Digital Enterprise Management System" (ERP for IT, ITIL, CMMI,PMI...
IS Unified "Digital Enterprise Management System" (ERP for IT, ITIL, CMMI,PMI...IS Unified "Digital Enterprise Management System" (ERP for IT, ITIL, CMMI,PMI...
IS Unified "Digital Enterprise Management System" (ERP for IT, ITIL, CMMI,PMI...
 
Strategic governance performance_management_systems
Strategic governance performance_management_systemsStrategic governance performance_management_systems
Strategic governance performance_management_systems
 
The Relationship Between ITG and ITSM Lifecycles
The Relationship Between ITG and ITSM Lifecycles  The Relationship Between ITG and ITSM Lifecycles
The Relationship Between ITG and ITSM Lifecycles
 
2012 CIO Perspectives: From Operations to the Executive Suite
2012 CIO Perspectives: From Operations to the Executive Suite2012 CIO Perspectives: From Operations to the Executive Suite
2012 CIO Perspectives: From Operations to the Executive Suite
 
Convergence Of Technology And Core Business Strategy
Convergence Of Technology And Core Business StrategyConvergence Of Technology And Core Business Strategy
Convergence Of Technology And Core Business Strategy
 
Microsoft Dynamics Academic Alliance: Job Roles
Microsoft Dynamics Academic Alliance: Job RolesMicrosoft Dynamics Academic Alliance: Job Roles
Microsoft Dynamics Academic Alliance: Job Roles
 
Removing silos
Removing silosRemoving silos
Removing silos
 
From Value Governance To Benefits Realization In A Controlled Environment
From Value Governance To Benefits Realization In A Controlled EnvironmentFrom Value Governance To Benefits Realization In A Controlled Environment
From Value Governance To Benefits Realization In A Controlled Environment
 

Plus de CONFENIS 2012

Plus de CONFENIS 2012 (20)

Enterprise systems in healthcare: leveraging what we know from other industr...
 Enterprise systems in healthcare: leveraging what we know from other industr... Enterprise systems in healthcare: leveraging what we know from other industr...
Enterprise systems in healthcare: leveraging what we know from other industr...
 
[Dutch] GeOS, het informatiehart van het dienstverleningscentrum Heilig Hart
[Dutch] GeOS, het informatiehart van het dienstverleningscentrum Heilig Hart [Dutch] GeOS, het informatiehart van het dienstverleningscentrum Heilig Hart
[Dutch] GeOS, het informatiehart van het dienstverleningscentrum Heilig Hart
 
Understanding the role of knowledge management during the ERP implementation ...
Understanding the role of knowledge management during the ERP implementation ...Understanding the role of knowledge management during the ERP implementation ...
Understanding the role of knowledge management during the ERP implementation ...
 
Effect of ERP implementation on the company efficiency - A Macedonian case
Effect of ERP implementation on the company efficiency - A Macedonian caseEffect of ERP implementation on the company efficiency - A Macedonian case
Effect of ERP implementation on the company efficiency - A Macedonian case
 
User perceptions, motivations and implications on ERP usage: An Indian Higher...
User perceptions, motivations and implications on ERP usage: An Indian Higher...User perceptions, motivations and implications on ERP usage: An Indian Higher...
User perceptions, motivations and implications on ERP usage: An Indian Higher...
 
Enterprise Information Systems Security: A Case Study in the Banking Sector
Enterprise Information Systems Security: A Case Study in the Banking SectorEnterprise Information Systems Security: A Case Study in the Banking Sector
Enterprise Information Systems Security: A Case Study in the Banking Sector
 
[Dutch] ICT & Ryhove: een geslaagd huwelijk?
[Dutch] ICT & Ryhove: een geslaagd huwelijk?[Dutch] ICT & Ryhove: een geslaagd huwelijk?
[Dutch] ICT & Ryhove: een geslaagd huwelijk?
 
[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?
[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?
[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?
 
[Dutch] E-commerce en ERP
[Dutch] E-commerce en ERP[Dutch] E-commerce en ERP
[Dutch] E-commerce en ERP
 
[Dutch] Sociale media en crisiscommunicatie
[Dutch] Sociale media en crisiscommunicatie[Dutch] Sociale media en crisiscommunicatie
[Dutch] Sociale media en crisiscommunicatie
 
[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...
[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...
[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...
 
[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012
[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012
[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012
 
[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...
[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...
[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...
 
[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...
[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...
[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...
 
[Dutch] Software is een middel, geen doel!
[Dutch] Software is een middel, geen doel![Dutch] Software is een middel, geen doel!
[Dutch] Software is een middel, geen doel!
 
What's beyond ERP? New normal ERP? by Ludo Van den Kerckhove
What's beyond ERP? New normal ERP? by Ludo Van den KerckhoveWhat's beyond ERP? New normal ERP? by Ludo Van den Kerckhove
What's beyond ERP? New normal ERP? by Ludo Van den Kerckhove
 
[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...
[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...
[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...
 
Group preference aggregation based on ELECTRE methods for ERP system selection
Group preference aggregation based on ELECTRE methods for ERP system selectionGroup preference aggregation based on ELECTRE methods for ERP system selection
Group preference aggregation based on ELECTRE methods for ERP system selection
 
A Multicriteria Model for Strategic Implementation of Business Process Manage...
A Multicriteria Model for Strategic Implementation of Business Process Manage...A Multicriteria Model for Strategic Implementation of Business Process Manage...
A Multicriteria Model for Strategic Implementation of Business Process Manage...
 
Some Considerations on Contracts ERP Buyer-Seller perspective
Some Considerations on Contracts ERP Buyer-Seller perspectiveSome Considerations on Contracts ERP Buyer-Seller perspective
Some Considerations on Contracts ERP Buyer-Seller perspective
 

Dernier

Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
Matteo Carbone
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 

Dernier (20)

Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 

IT governance by Erik Guldentops

  • 1. 19-21 September Ghent Belgium IT Governance “How to deal with IT Value and IT Risk” Erik Guldentops Lecturer Antwerp Management School Erik Guldentops IT Governance Briefing eg_19092012 page 1 of 27
  • 2. Enterprise Governance of IT Strategic alignment Defining with the businsess how to achieve value while Five mitigating risk domains but Performance Mngnt Measuring how desired really only value is achieved and risk contained two subjects Resource Mngnt Acquiring and maintaining all that is necessary to achieve value and contain risk Erik Risk and Value Guldentops IT Governance Briefing eg_19092012 page 2 of 27
  • 3. Erik Guldentops IT Governance Briefing eg_19092012 page 3 of 27
  • 4. IT Governance vs. IT Management IT GOVERNANCE Set Objectives • IT is aligned with the business • IT enables the business and maximises benefits • IT resources are used responsibly Evaluate • IT-related risks are managed appropriately Provide performance direction Measure and Translate report direction into performance Translate strategy into action strategy • Increase automation (make the business effective) • Decrease cost (make the enterprise efficient) • Manage risks (security, reliability & compliance) IT MANAGEMENT Erik Guldentops IT Governance Briefing eg_&9092012 pg 4 of 27
  • 5. Enterprise Governance of IT Board Executive Line Management Erik Guldentops IT Governance Briefing eg_&9092012 pg 5 of 27
  • 6. Implementing Enterprise Governance of IT How do we know Where do we we are What are we want to be? progressing? doing about it? •Delivery Performance Portfolio •Service Quality • Programmes Objectives •Resource Utilisation •Benefits Realisation • Services •Risk Reduction • Resources Strategy Scorecards Business Cases Are the engines of IT Governance Erik Guldentops IT Governance Briefing eg_&9092012 pg 6 of 27
  • 7. Implementing Enterprise Governance of IT Metrics Inputs WHAT ? Outputs Responsibility & Goals Activities Accountability ? Performance HOW Metrics needs a process structure Erik Guldentops IT Governance Briefing eg_&9092012 pg 7 of 27
  • 8. Implementing Enterprise Governance of IT BUSINESS OBJECTIVES AND GOVERNANCE OBJECTIVES COBIT ME1 Monitor and evaluate IT PO1 Define a strategic IT plan. performance. PO2 Define the information ME2 Monitor and evaluate internal INFORMATION architecture. control. PO3 Determine technological direction. ME3 Ensure compliance with external requirements. Efficiency Integrity PO4 Define the IT processes, organization, and relationships. ME4 Provide IT governance. Effectiveness Availability PO5 Manage the IT investment. Compliance Confidentiality PO6 Communicate management aims Reliability and direction. MONITOR PLAN PO7 Manage IT human resources. AND AND PO8 Manage quality. EVALUATE ORGANIZE PO9 Assess and manage IT risks. DS1 Define and manage service levels. IT PO10 Manage projects. DS2 Manage third-party services. RESOURCES DS3 Manage performance and capacity. DS4 Ensure continuous service. DS5 Ensure systems security. Applications DS6 Identify and allocate costs. AI1 Identify automated solutions. Information DS7 Educate and train users. Infrastructure AI2 Acquire and maintain application DS8 Manage the service desk and People software. incidents. DELIVER AI3 Acquire and maintain technology ACQUIRE DS9 Manage the configuration. AND infrastructure. AND DS10 Manage problems. SUPPORT IMPLEMENT AI4 Enable operation and use. DS11 Manage data. AI5 Procure IT resources. DS12 Manage the physical environment. AI6 Manage changes. DS13 Manage operations. AI7 Install and accredit solutions and change. Erik Guldentops IT Governance Briefing eg_&9092012 pg 8 of 27
  • 9. Implementing Enterprise Governance of IT www.isaca.org Erik Guldentops IT Governance Briefing eg_&9092012 pg 9 of 27
  • 10. CobiT can be overwhelming Erik Guldentops IT Governance Briefing eg_19092012 page 10 of 27
  • 11. CobiT can be overwhelming Erik Guldentops IT Governance Briefing eg_19092012 page 11 of 27
  • 12. CobiT QuickStart for Small and Medium Sized Enterprised One objective Four practices Three critical success factors Two metrics Erik Guldentops IT Governance Briefing A simple progress measure eg_&9092012 pg 12 of 27
  • 13. Suitability CobiT QuickStart Assessment Span of control Communications path Applicable to IT Sophistication IT Strategic Importance whom? IT Expenditure Segregation Sanity Check Risk Liabilities Compliance Past Problems Future Needs Required Expertise Erik Guldentops IT Governance Briefing eg_&9092012 pg 13 of 27
  • 14. What did 70 CISO CIO’s say about CIO IT Frameworks ? IT Governance Service Delivery Information Security CIONet Survey, Sep 2011 CobiT ITIL ISO27001 Erik Guldentops IT Governance Briefing eg_&9092012 pg 14 of 27
  • 15. Why implement an IT Governance Framework? CIONet Survey, Sep 2011 Erik Guldentops IT Governance Briefing eg_&9092012 pg 15 of 27
  • 16. What were the expected and actual benefits? Improved EFFICIENCY enterprise processes Extended staff capabilities Better service delivery EFFECTIVENESS Faster solution delivery Increased innovation expected RISK Reduced risk actual CIONet Survey, Sep 2011 Erik Guldentops IT Governance Briefing eg_&9092012 pg 16 of 27
  • 17. How did they measure benefits? CIONet Survey, Sep 2011 Erik Guldentops IT Governance Briefing eg_&9092012 pg 17 of 27
  • 18. Relationship IT Governance Practices and Benefits Clustered Correlations PROCESS • Define a strategic IT plan • Manage the IT investment • Communicate management aims and direction IT • Assess and manage IT risks • Identify automated solutions • Acquire & maintain applications and infrastructure • Portfolio and investment management • Align the IT strategy to the business strategy GOAL • Provide service offerings and service levels in line with business IT reqrmnts • Acquire, develop and maintain IT skills that respond to the IT strategy • Ensure that IT demonstrates continuous improvement and readiness for future change • Cost optimisation of service delivery and business processes BUSINESS • Obtain reliable and useful information for strategic decision-making GOAL • Improve and maintain business process functionality and operational productivity • Enable and manage business change IT Governance Institue, Sep 2008 Erik Guldentops IT Governance Briefing eg_&9092012 pg 18 of 27
  • 19. IT Governance Implementation: Lessons Learned • Common language and common framework • Higher maturity • Better organisation • More useful management information • “IT really works” • Complexity • Less results than expected • High learning curve managers • Bogged down in details/paperwork • High level of senior management support required CIONet Survey, Sep 2011 Erik Guldentops IT Governance Briefing eg_&9092012 pg 19 of 27
  • 20. IT Governance Implementation: Lessons Learned Adoption of frameworks is not a simple nor self-contained project with measured costs. It is a gradual shift and inter-relates with many other initiatives. Erik Guldentops IT Governance Briefing eg_&9092012 pg 20 of 27
  • 21. Some notes on Risk and Value CIONet Survey, Sep 2012 Erik Guldentops IT Governance Briefing eg_&9092012 pg 21 of 27
  • 22. Some notes on Risk and Value For both riskand value, accept uncertainty and deal with it! Erik Guldentops IT Governance Briefing eg_&9092012 pg 22 of 27
  • 23. IT Value Research Erik Guldentops IT Governance Briefing eg_&9092012 pg 23 of 27
  • 24. IT Value Research Erik Guldentops IT Governance Briefing eg_&9092012 pg 24 of 27
  • 25. www.isaca.org Erik Guldentops IT Governance Briefing eg_&9092012 pg 25 of 27
  • 26. So what is the ROI on IT Governance Practices? In October 2006 Mc Kinsey and the London School of Economics measured the increase in productivity from investments in IT versus investments in management practices in 100 enterprises. + Management Practices Score 75th percentile +8% +20%1 and above 25th percentile 0 +2% and above - Intensity of IT deployment + 25th percentile 75th percentile and above and above Erik Guldentops IT Governance Briefing eg_&9092012 pg 26 of 27
  • 27. 19-21 September Ghent Belgium IT Governance “How to deal with IT Value and IT Risk” Erik Guldentops Lecturer Antwerp Management School Erik Guldentops IT Governance Briefing eg_19092012 page 27 of 27