SlideShare une entreprise Scribd logo
1  sur  27
INFORMATIONTECHNOLOGYGOVERNANCE
CSKSEMINAR
MONDAY 21 ST MARCH 2022
Peter Owenje B.Sc, MBA
AGENDA
• What is IT Governance
• Elements of IT Governance
• Benefits of IT Governance
• Frameworks for IT Governance
• Auditing IT Governance
• Role of Internal Audit
Objectives
• Overview of IT Governance and describe its importance
• An Approach to auditing IT Governance, including key
scope areas, involved parties/stakeholders, key questions
to answer
• Current trends in IT Governance and how they can be
incorporated into IT Governance audits
COBIT
• Definition of Control Objectives for Information and Related Technologies.
Control Objectives for Information and Related Technologies, more popularly
known as COBIT, is a framework that aims to help organizations that are looking
to develop, implement, monitor, and improve IT governance and information
management.
• Componets of COBIT : Framework. Organize and categorize IT governance objectives
and good practices by IT domains and processes before associating them with
their respective business requirements.
• Process descriptions. …
• Control objectives. …
• Management guidelines. …
• Maturity models.
Elements of IT Governance
Elements of IT Governance
• IT Strategic Alignment, such as formalized business
objectives, up to date IT strategy, linkage between business
objectives and IT initiatives;
• Value Delivery: IT tactical plans, clear benefits for each level
of the organization: infra-structure (systems uptime),
applications (degree of automation), operational (productivity),
financial (income);
• Risk Management: defined responsibilities for risk
management, risk analysis methodology, defined strategies for
addressing risks, continuous monitoring of threats,
occurrence and impact;
Elements of IT Governance
• Resource Management: sourcing strategies, human
management practices, user manuals, segregation of
duties, time reporting, infra-structure life cycle
management, acceptable usage policies.
• Performance Measurement: relevant and measurable
metrics, continuous monitoring and reporting, follow-up
policies, root cause analysis and problem management,
benchmarking against industry practices and proven
standards or frameworks.
Benefits of IT Governance
• Strengthens the relationship between the organization
and IT; Helps ensure limited IT resources are focused on
the right strategic and tactical activities at the right time
• Synergies with Enterprise Risk Management (ERM) and
other risk management activities; Helps ensure the
appropriate IT risk management processes and activities
are in place and operating effectively
Benefits of IT Governance
• Enhanced visibility into the IT Function’s ability to achieve
its both tactical and strategic objectives; Key
Performance Indicators (KPIs) for day-to-day activities
and longer-term/strategic initiatives
• Improved adaptability of the IT Function to organizational
and IT environment changes; Formality of Governance
structure, processes and activities enables more efficient
and effective response to change
Framework For IT
Governance
• Capability Maturity Modeling Integration (CMMI)- For Process
Improvement
• Information Technology Infrastructure Library (ITIL)- For IT Service
Management.
• Six Sigma- For Process Improvement especially security processes.
• Control Objectives for Information and Related Technology(COBIT)
For information technology (IT) management and IT governance
• The Balanced Score Card (BSC), Balanced Scorecard (BSC) -
method to assess an organization’s performance in different areas.
Framework For IT
Governance
Auditing IT Governance
Institutional Governance Structures
Auditing IT Governance
Executive Leadership and Support
Auditing IT Governance
Strategic and Operational Planning
IT Organization(s) and Risk Management
Auditing IT Governance
Auditing IT Governance
Service Delivery and Management
IT Governance Trends
• Cost Efficiencies (Outsourcing / The Cloud)
• Information Privacy and Security
• Virtualization
• Centralization vs. Decentralization
Information Security Governance Model
Information Security Governance with Stakeholders
Information Security Governance to Provide Customer Value
Information Security Governance Management Implementation Model
Information Security Governance for Mobile Devices
Information Security Governance to address cyber threats
Enterprise Information Security Governance Council
Business Information Security Governance Process
END

Contenu connexe

Similaire à IT Govenence.pptx

It goverence
It goverenceIt goverence
It goverence
Kiran_Kendre
 
Governance V3 (2)
Governance V3 (2)Governance V3 (2)
Governance V3 (2)
guestf73e68
 
It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013
James Sutter
 
It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013
Jim Sutter
 
IT Strategy Assessment & Optimization - Catallysts Approach
IT Strategy Assessment & Optimization - Catallysts ApproachIT Strategy Assessment & Optimization - Catallysts Approach
IT Strategy Assessment & Optimization - Catallysts Approach
Rajanish Dass
 
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docxCHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
bartholomeocoombs
 
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docxCHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
keturahhazelhurst
 

Similaire à IT Govenence.pptx (20)

20180530123152_PPT8-TOPIK8-R0-IT Governance Instruments.pptx
20180530123152_PPT8-TOPIK8-R0-IT Governance Instruments.pptx20180530123152_PPT8-TOPIK8-R0-IT Governance Instruments.pptx
20180530123152_PPT8-TOPIK8-R0-IT Governance Instruments.pptx
 
Critical Success Factors (CSFs) for Effective IT Governance Implementations
Critical Success Factors (CSFs) for Effective IT Governance ImplementationsCritical Success Factors (CSFs) for Effective IT Governance Implementations
Critical Success Factors (CSFs) for Effective IT Governance Implementations
 
CISA Training - Chapter 2 - 2016
CISA Training - Chapter 2 - 2016CISA Training - Chapter 2 - 2016
CISA Training - Chapter 2 - 2016
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance Framework
 
CIT 3122 IS Governance Lecture 3.pptx
CIT 3122 IS Governance Lecture 3.pptxCIT 3122 IS Governance Lecture 3.pptx
CIT 3122 IS Governance Lecture 3.pptx
 
Ch2 2009 cisa
Ch2 2009 cisaCh2 2009 cisa
Ch2 2009 cisa
 
IT Governance - COBIT Perspective
IT Governance - COBIT PerspectiveIT Governance - COBIT Perspective
IT Governance - COBIT Perspective
 
MAKING SENSE OF IT GOVERNANCE
MAKING SENSE OF IT GOVERNANCEMAKING SENSE OF IT GOVERNANCE
MAKING SENSE OF IT GOVERNANCE
 
It goverence
It goverenceIt goverence
It goverence
 
Accountability Corbit Overview 06262007
Accountability Corbit Overview 06262007Accountability Corbit Overview 06262007
Accountability Corbit Overview 06262007
 
IT Strategy Framework
IT Strategy FrameworkIT Strategy Framework
IT Strategy Framework
 
Executive's Handbook on IT Strategy and Governance
Executive's Handbook on IT Strategy and GovernanceExecutive's Handbook on IT Strategy and Governance
Executive's Handbook on IT Strategy and Governance
 
Governance V3 (2)
Governance V3 (2)Governance V3 (2)
Governance V3 (2)
 
It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013
 
It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013It Governance OC CIO Nov,2013
It Governance OC CIO Nov,2013
 
IT Strategy Assessment & Optimization - Catallysts Approach
IT Strategy Assessment & Optimization - Catallysts ApproachIT Strategy Assessment & Optimization - Catallysts Approach
IT Strategy Assessment & Optimization - Catallysts Approach
 
Cobit Training course
Cobit Training courseCobit Training course
Cobit Training course
 
ERP for IT
ERP for ITERP for IT
ERP for IT
 
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docxCHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
 
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docxCHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
CHAPTER 10INFORMATION GOVERNANCEInformation Governance a.docx
 

Plus de PeterOwenje1

Plus de PeterOwenje1 (13)

An Effective IT Staregy .pdf
An Effective IT Staregy .pdfAn Effective IT Staregy .pdf
An Effective IT Staregy .pdf
 
IT Alignment with Bus Strategy CSK IT Mgr Congress Pride inn 2022.pptx
IT Alignment with Bus Strategy CSK IT Mgr Congress Pride inn  2022.pptxIT Alignment with Bus Strategy CSK IT Mgr Congress Pride inn  2022.pptx
IT Alignment with Bus Strategy CSK IT Mgr Congress Pride inn 2022.pptx
 
Crafting a winning ICT Strategy .pptx
Crafting a winning ICT Strategy .pptxCrafting a winning ICT Strategy .pptx
Crafting a winning ICT Strategy .pptx
 
IT Networks and Vulnarabilities .pdf
IT Networks and Vulnarabilities .pdfIT Networks and Vulnarabilities .pdf
IT Networks and Vulnarabilities .pdf
 
Data Protection Subjects.pdf
Data Protection Subjects.pdfData Protection Subjects.pdf
Data Protection Subjects.pdf
 
Adaptive team leadrship.pptx
Adaptive team leadrship.pptxAdaptive team leadrship.pptx
Adaptive team leadrship.pptx
 
Digitalization of Goverment Services.pptx
Digitalization of Goverment Services.pptxDigitalization of Goverment Services.pptx
Digitalization of Goverment Services.pptx
 
Leadership Strategies.pptx
Leadership Strategies.pptxLeadership Strategies.pptx
Leadership Strategies.pptx
 
Mobile Device Management.pptx
Mobile Device Management.pptxMobile Device Management.pptx
Mobile Device Management.pptx
 
PIM Data Protection .pptx
PIM  Data Protection .pptxPIM  Data Protection .pptx
PIM Data Protection .pptx
 
PIM Data Protection .pptx
PIM  Data Protection .pptxPIM  Data Protection .pptx
PIM Data Protection .pptx
 
ERP Presentation .pptx
  ERP Presentation .pptx  ERP Presentation .pptx
ERP Presentation .pptx
 
ERP Implementation.pptx
  ERP Implementation.pptx  ERP Implementation.pptx
ERP Implementation.pptx
 

Dernier

Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Bertram Ludäscher
 
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
vexqp
 
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
vexqp
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
gajnagarg
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
ahmedjiabur940
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
nirzagarg
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
gajnagarg
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Klinik kandungan
 
Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1
ranjankumarbehera14
 
怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制
怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制
怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制
vexqp
 
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
nirzagarg
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
nirzagarg
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
wsppdmt
 
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
Health
 
Abortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get CytotecAbortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Riyadh +966572737505 get cytotec
 

Dernier (20)

Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
 
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
 
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
 
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
 
Sequential and reinforcement learning for demand side management by Margaux B...
Sequential and reinforcement learning for demand side management by Margaux B...Sequential and reinforcement learning for demand side management by Margaux B...
Sequential and reinforcement learning for demand side management by Margaux B...
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
 
Data Analyst Tasks to do the internship.pdf
Data Analyst Tasks to do the internship.pdfData Analyst Tasks to do the internship.pdf
Data Analyst Tasks to do the internship.pdf
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
 
Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1
 
Digital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham WareDigital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham Ware
 
怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制
怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制
怎样办理纽约州立大学宾汉姆顿分校毕业证(SUNY-Bin毕业证书)成绩单学校原版复制
 
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
 
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With OrangePredicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
 
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
 
Abortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get CytotecAbortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get Cytotec
 

IT Govenence.pptx

  • 2. AGENDA • What is IT Governance • Elements of IT Governance • Benefits of IT Governance • Frameworks for IT Governance • Auditing IT Governance • Role of Internal Audit
  • 3. Objectives • Overview of IT Governance and describe its importance • An Approach to auditing IT Governance, including key scope areas, involved parties/stakeholders, key questions to answer • Current trends in IT Governance and how they can be incorporated into IT Governance audits
  • 4.
  • 5. COBIT • Definition of Control Objectives for Information and Related Technologies. Control Objectives for Information and Related Technologies, more popularly known as COBIT, is a framework that aims to help organizations that are looking to develop, implement, monitor, and improve IT governance and information management. • Componets of COBIT : Framework. Organize and categorize IT governance objectives and good practices by IT domains and processes before associating them with their respective business requirements. • Process descriptions. … • Control objectives. … • Management guidelines. … • Maturity models.
  • 6. Elements of IT Governance
  • 7. Elements of IT Governance • IT Strategic Alignment, such as formalized business objectives, up to date IT strategy, linkage between business objectives and IT initiatives; • Value Delivery: IT tactical plans, clear benefits for each level of the organization: infra-structure (systems uptime), applications (degree of automation), operational (productivity), financial (income); • Risk Management: defined responsibilities for risk management, risk analysis methodology, defined strategies for addressing risks, continuous monitoring of threats, occurrence and impact;
  • 8. Elements of IT Governance • Resource Management: sourcing strategies, human management practices, user manuals, segregation of duties, time reporting, infra-structure life cycle management, acceptable usage policies. • Performance Measurement: relevant and measurable metrics, continuous monitoring and reporting, follow-up policies, root cause analysis and problem management, benchmarking against industry practices and proven standards or frameworks.
  • 9. Benefits of IT Governance • Strengthens the relationship between the organization and IT; Helps ensure limited IT resources are focused on the right strategic and tactical activities at the right time • Synergies with Enterprise Risk Management (ERM) and other risk management activities; Helps ensure the appropriate IT risk management processes and activities are in place and operating effectively
  • 10. Benefits of IT Governance • Enhanced visibility into the IT Function’s ability to achieve its both tactical and strategic objectives; Key Performance Indicators (KPIs) for day-to-day activities and longer-term/strategic initiatives • Improved adaptability of the IT Function to organizational and IT environment changes; Formality of Governance structure, processes and activities enables more efficient and effective response to change
  • 11. Framework For IT Governance • Capability Maturity Modeling Integration (CMMI)- For Process Improvement • Information Technology Infrastructure Library (ITIL)- For IT Service Management. • Six Sigma- For Process Improvement especially security processes. • Control Objectives for Information and Related Technology(COBIT) For information technology (IT) management and IT governance • The Balanced Score Card (BSC), Balanced Scorecard (BSC) - method to assess an organization’s performance in different areas.
  • 13. Auditing IT Governance Institutional Governance Structures
  • 14. Auditing IT Governance Executive Leadership and Support
  • 15. Auditing IT Governance Strategic and Operational Planning
  • 16. IT Organization(s) and Risk Management Auditing IT Governance
  • 17. Auditing IT Governance Service Delivery and Management
  • 18. IT Governance Trends • Cost Efficiencies (Outsourcing / The Cloud) • Information Privacy and Security • Virtualization • Centralization vs. Decentralization
  • 20. Information Security Governance with Stakeholders
  • 21. Information Security Governance to Provide Customer Value
  • 22. Information Security Governance Management Implementation Model
  • 23. Information Security Governance for Mobile Devices
  • 24. Information Security Governance to address cyber threats
  • 25. Enterprise Information Security Governance Council
  • 26. Business Information Security Governance Process
  • 27. END