Wednesday, October 10, 2012

ITIL Processes

     SERVICE STRATEGY
·   Strategy Management for IT Services
·   Service Portfolio Management
·   Financial Management
·   Business Relationship Management
·   Demand Management for IT Services
     SERVICE DESIGN
·   Design Coordination
·   Service Level Management
·   Service Catalog Management
·   Supplier Management
·   Availability Management
·   IT Service Continuity Management
·   Capacity Management
·   Information Security Management
     SERVICE TRANSITION
·   Transition Planning & Support
·   Change Management
·   Service Asset Management
·   Configuration Management
·   Release & Deployment Mgmnt
·   Service Validation & Testing
·   Change Evaluation
·   Service Knowledge Management
     SERVICE OPERATION
·   Service Desk Function
·   IT Operations Management Function
·   Technical Management Function
·   Applications Management Function
·   Event Management
·   Incident Management
·   Request Fulfillment
·   Problem Management
·   Access Management
     CONTINUAL SERVICE IMPROVEMENT
·   Service Measurement & Reporting
·   Service Improvement

Tuesday, October 9, 2012

Physical Security Controls

  • Close security events monitoring
  • Computerized access-controlled doors
  • Fire detection system for IT offices
  • Locked IT storerooms and offices
  • Locked offices for personal computer locations
  • Restricted access to valuable records, files, facilities and systems
  • Safety and fire-proof vaults for IT assets (back-ups, original vendor software)
  • Security guards, especially for computer rooms and data centres
  • Television and microwave surveillance for sensitive IT areas
  • Visitor entry and exit controls
  • Waste management for all reports, correspondence, digital media, diskettes, tapes, DVDs, ribbons, special forms, etc. via the use of paper shredders, incinerators, media crunchers, software degaussing and binary zero creation for all destroyed computerized data files.

IT Administrative Controls

  • IT administration performance measures
  • IT asset controls
  • IT budget
  • IT office administration controls
  • IT personnel management controls
  • IT purchasing controls
  • IT standards, policies and procedures
  • Monitoring and review controls

IT Governance Framework - Why ?

  • Aligning the IT strategy to corporate strategy within the framework of the Enterprise Architecture of the organization
  • IT standards, policies, procedures, practices and methods for the safe, efficient, effective and cost-beneficial running of all ITC systems and infrastructural components
  • Managing human and other resources
  • Performance management
  • Quality management

IT Organizational Controls

  • IT department functional description controls
  • IT governance and control frameworks
  • IT organization controls
  • IT organization performance measures.
  • IT vision, mission and values statements
  • Monitoring and review controls

Sunday, October 7, 2012

COSO Update - Key Links



Current COSO

 Presentation on COSO changes

Direct link to download proposed COSO draft (zipped files, checkout coso_illustrative_tool.pdf--super)


Coming COSO Update - 17 Principles


1. Demonstrates Commitment to Integrity and Ethical Values—The organization demonstrates a commitment to integrity and ethical values.

2. Exercises Oversight Responsibility—The board of directors demonstrates independence from management and exercises oversight for the development and performance of internal control.

3. Establishes Structure, Authority, and Responsibility—Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.

4. Demonstrates Commitment to Competence—The organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

5. Enforces Accountability—The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.

6. Specifies Suitable Objectives—The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.

7. Identifies and Analyzes Risk—The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.

8. Assess Fraud Risk—The organization considers the potential for fraud in assessing risks to the achievement of objectives.

9. Identifies and Analyzes Significant Change—The organization identifies and assesses changes that could significantly impact the system of internal control.

10. Selects and Develops Control Activities—The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

11. Selects and Develops General Controls over Technology—The organization selects and develops general control activities over technology to support the achievement of objectives.

12. Deploys through Policies and Procedures—The organization deploys control activities through policies that establish what is expected and procedures that put the policies into action.

13. Uses Relevant Information—The organization obtains or generates and uses relevant, quality information to support the functioning of other components of internal control.

14. Communicates Internally—The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of other components of internal control.

15. Communicates Externally—The organization communicates with external parties regarding matters affecting the functioning of other
components of internal control.

16. Conducts Ongoing and/or Separate Evaluations—The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

17. Evaluates and Communicates Deficiencies—The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.

Get Really Free Stuff


Couchsurfing.org  for free lodging

LibriVox.org  free books on tape, mp3
Volition.com get free recording software to read books

TheFreeSite.com

 freechannel.net.

MyKidsEatFree.com

OpenOffice.org.

Lear languages free at BBC

AnnualCreditReport.com

Free phone from Skype or Google voice

Also check out FREEE STUFF category on Craigslist, and don’t limit  yourself only to your town


Glad to See You Visiting Again: Welcome.


Saturday, October 6, 2012

Four Rules for Every Meeting

FOCUS Turn off cell phones, laptops, iPads, and point your brain toward the meeting's goals.

PARTICIPATE  Share your input, question others, bring up ideas and comments, get involved.

MOVE  Decisions need to be made to make the meeting productive

CLOSE Get done what you set out so that everyone has the feeling of accomplishment.

YOUR EYES  Always turn toward whoever is speaking.  Most people look at others only when they disagree and are building a rebuttal.


Must Define When Developing Recommendation


  • Assumptions and constraints for the solution
  • Business objectives of the proposed solution based on the identified problem or business
  • Definition of the expected effort to create the expected deliverable
  • Description of the deliverable  this may be products, services, environment, profits, problems solved, and other outcomes

 Note  A constraint is anything that limits your option. Time and cost limits are examples of constraints.

When Creating Effective Survey


  • Confirm the survey length (ten questions or fewer is ideal).
  • Determine how respondents will receive, complete, and return the survey; consider paper-based, telephone-based, or web-based surveys.
  • Determine the acceptable level of response rate and what incentives might be offered to help reach the response rate.
  • Determine the need for pre- and post-survey interviews to formulate the survey and to review its findings.
  • Determine which types of questions, closed or open, are most appropriate for the survey type.
  • Document the survey purpose and which stakeholders should participate.
  • Refine the survey questions so they're clear, easy to answer, and don't put the participant in a defensive stance.
  • Test the survey and make any modifications to the survey if necessary.
  • Write the most appropriate survey questions in consideration of the participants' backgrounds, values, and interest in the survey purpose.

Do Before Your Workshop


- Communicate requirements workshop to the key stakeholders
- Complete interviews of stakeholders to help facilitate the workshop
- Create an agenda for the workshop
- Document what the business problem or opportunity is
- Schedule a scribe or recorder to do the minutes and conversations for future reference

Why Brainstorm?


  • Encourages stakeholder participation
  • Explores solutions to business opportunities
  • Explores solutions to problems within the project
  • Fosters team building
  • Helps determine constraints on the project team, the project, or the organization and how they might be removed
  • Promotes diverse thinking for multiple options for a solution
  • Reveals options that are available for the current issue



Friday, October 5, 2012

Risk Management Principles

  1. Risk management creates and protects value
  2. Risk management is an integral part of all organizational processes
  3. Risk management is part of decision making
  4. Risk management explicitly addresses uncertainty
  5. Risk management is systematic, structured, and timely
  6. Risk management is based on the best available information
  7. Risk management is tailored
  8. Risk management takes human and cultural factors into account
  9. Risk management is transparent and inclusive
10. Risk management is dynamic, iterative, and responsive to change
11. Risk management facilitates continual improvement of the organization

Key Risk Documents To Review

  • Risk Management Policy
  • Risk Management Process and Strategy
  • Risk Identification and Assessment Tools and Templates
  • Risk Management Training Program and Materials
  • Risk Tolerance documentation, including likelihood, consequence, and overall risk level criteria
  • Risk Registers
  • Risk Reports

Thursday, October 4, 2012

Risk Management Policy

  • Accountabilities and responsibilities for managing risk
  • Commitment to the periodic review and verification of the risk management policy and framework, and its continual improvement
  • Links between this policy and the strategies and objectives
  • The risk appetite
  • The rationale for managing risk
  • Processes and methods to be used for managing risk
  • Resources available to assist those accountable or responsible for managing risk
  • The way in which risk management performance will be measured and reported

Risk Framework Documentation

  • Objectives and rationale for managing risk
  • The overall appetite/tolerance for risks
  • The strategic objectives and the strategies deployed to achieve these objectives
  • Key risks associated with these strategies within a one to three year time frame
  • The high-level approach to managing these risks
  • A plan for progressive enhancement of risk management practices and competencies and initiatives

Why Document Risk Framework and Steps Performed

  • Demonstrate to stakeholders that the process has been conducted properly
  • Provide evidence of a systematic approach to risk identification and analysis
  • Enable decisions or processes to be reviewed
  • Provide a record of risks and to develop the organization’s knowledge database
  • Provide decision makers with a risk management plan for approval and subsequent implementation
  • Provide an accountability mechanism and tool
  • Facilitate ongoing monitoring, review and continuous improvement
  • Provide an audit trail
  • Share and communicating information

Risks in Imbedding Risk Mngmt in Organizations

  • Better defining risk descriptions
  • Improved identification of departmental or divisional risk management
  • Aligning risk committee and boards with what's happening on the ground
  • Linking internal audit and risk management
  • Improving the quality and content of risk registers
  • Embedding operational risk management
  • Identifying controls and their effectiveness
  • Allocating accountability for risk
  • Improving risk reporting and measurement
  • Enhancing project risk management


Tuesday, October 2, 2012

Organizational Operating Model


Organization Chart
•     Units and scope of each
•     Virtual matrix groups and alignments
•     Reporting levels and spans of control

Roles and Boundaries
•     Boundaries of each unit and what are shared tasks
•     Information that is available across boundaries
•     Responsibility for tasks
•     Special boundary spanning roles

Programs and Services
•     Common and special programs in each unit
•     Interface with customers and other departments
•     Standards of service levels

Decision Process
•     Key decisions and who makes them
•     Who makes decision, advices, consults, approves
•     Process for evaluating results of decisions

Meeting Schedule and Design
•     Who is invited and what are the key topics?
•     What are the roles in meetings?
•     What practices are used to make meetings effective?

Objectives, Tasks, and Measurement
•     Key performance indicators and measurements
•     Setting of team and staff personnel goals
•     Benchmarks used for evaluations

Key Organizational Dimensions


Decisions & Norms – Who makes decision?  What are the unwritten rules of how we do things?.

Information & Culture - How performance is measured, activities are coordinated, and knowledge is transferred?   What people expect based on how they process and define information about issues and problems?

Motivators & Commitments - Motivators are the goals, incentives and career alternatives available to employees within an organization. Commitments are the unwritten hopes that drive and motivate people for the organization and themselves.

Operational Model & Inter-departmental interactions – Models represents the formal organizational structure. Connections are how people communicate and execute processes together.

Office Behavior Strategies

  • "Hi-lite" your shoes. Tell people that you haven’t lost your shoes since you did this.
  • Agree to organize the company Christmas party. Hold it at McDonald’s Playland. Charge everyone $15 each.
  • Come to work in your pajamas.
  • Compose all your e-mail in the form of a Haiku.
  • Decorate your office with pictures of Cindy Brady and Danny Partridge. Try to pass them off as your children.
  • Determine how many cups of coffee is "too many."
  • Develop an unnatural fear of staplers.
  • dont use any punctuation either
  • Every time someone asks you to do something, ask them if they want fries with that.
  • Hum songs that will remain lodged in co-workers brains, such as "Feliz Navidad", the Archies "Sugar" or the Mr. Rogers theme song.
  • Leave the copy machine set to reduce 200%, extra dark, 17 inch paper, 99 copies.
  • Make up nicknames for all your coworkers and refer to them only by these names. "That’s a good point, Sparky." "No I’m sorry I’m going to have to disagree with you there, Chachi."
  • Organize a carpool. Then go to pick everyone up in a taxi.
  • Pretend your computers mouse is a CB radio, and talk to it.
  • Put a chair facing a printer, sit there all day and tell people you’re waiting for your document.
  • Put decaf in the coffeemaker for 3 weeks. Once everyone has gotten over their caffeine addictions, switch to espresso.
  • Put up mosquito netting around your cubicle.
  • Put your garbage can on your desk. Label it "IN."
  • Reply to everything someone says with "that’s what YOU think."
  • Schedule meetings for 4:14 pm.
  • Send e-mail messages saying free pizza, free donuts etc… in the lunchroom, when people complain that there was none… Just lean back, pat your stomach, and say, "Oh you’ve got to be faster than that."
  • Send email to the rest of the company telling them what you’re doing. For example "If anyone needs me, I’ll be in the bathroom."
  • Send out flyers to your entire department/division announcing a required staff development program. When everyone arrives, show them slides from your vacation.
  • Staple papers in the middle of the page.
  • Take a picture of your boss and have it framed. Display it in a prominent location on your desk.
  • type only in lowercase.
  • When answering your phone, talk in a fake British accent.
  • When in conversation, no matter where you are in the office, mutter, "I think my phone is ringing," and leave.
  • While sitting in your cube, yodel.


Project Portfolio Maturity Factors

  • Opportunity Assessment for Projects
  • Portfolio Governance
  • Portfolio Resource Management
  • Prioritization and Selection of Projects
  • Communications regarding Project Portfolio Performance Management

Monday, October 1, 2012

Why To-Do Lists Sometimes Don't


  • Too many potential items to go on the list
  • Choosing easier and shorter tasks over those of importance
  • Getting done only top items from the list
  • All tasks look alike on a list, may not correspond to current relevance
  • It is difficult to find motivation and commitment 

How to Fall into Groupthink

  • Common incentives that penalize alternative viewpoints
  • Foster conformity, preventing originality
  • Homophily, or tendency to select and prefer to be with people who are likeminded
  • Radom drift due to lack of monitoring developments

Accounting Equation

Project Selection Factors


Business factors
§  Expected return on investment,
§  Payback period,
§  Potential market share,
§  Ability to generate future business or new markets

Internal operating factors,
§  Need to train employees,
§  Change in workforce size,
§  Change in physical environment,
§  Change in manufacturing process

Risk factors
§  Technical,
§  Financial,
§  Safety,
§  Quality,
§  Compliance
§  Legal exposure

Other factors
§  Intellectual property rights,
§  Impact on company’s image,
§  Strategic fit,
§  Brand perception

Causes and Results of Inefficiencies

Causes
  • Defects from normal operation
  • Excessive Inventory
  • Excessive Transportation
  • Over Processing
  • Overproduction
  • Unnecessary Motion
  • Unneeded Waiting
Results 
  • Redundant Processes
  • Manual Processes
  • Duplication of Controls
  • Poor Information Flow
  • Short-term focused Management