Monday, November 19, 2012

Reports from Monitoring and Review of Controls

·        Back-up and recovery issues
·    Changes, problems, errors, security incidents and backlog of requests
·    Compliance issues
·    Critical performance measures per IT area
·    Development issues of new applications
·    Help desk related issues
·    Industry trends and developments
·    IT project milestones
·    Online access issues
·    Post-implementation review issues
·    Project actual costs (against budgets)
·    Technical performance issues
·    Transactions and jobs processed

ISO/IEC 38500:2008: Corporate governance of information technology

·  Acquire IT acquisitions and investments in a proper and valid way.
·  Corporate and IT strategy should be clearly aligned.
·  Ensure compliance with rules for all IT activities.
·  Ensure performance of IT is delivered when required.
·  Ensure respect and consideration for human factors in IT policies and practices.
·  Ensure that IT responsibilities are clearly established.
 

Main Types of IT Application Controls

·  End-user computing controls
    ·  Input, processing and output controls
    ·  IT application database, operation, change and testing controls
·  Monitoring and review controls

Main Types of Systems Software Controls

·    Audit trail log file controls
·    Data communications controls
·    Database controls
·    Monitoring and review controls.
·    Systems software operating environment controls

Main Types of Data Center Operational and Support Controls

·      Computer hardware management controls
·      Data center design and infrastructural controls
·      Data center physical access controls
·       IT contingency planning and disaster recovery controls
·       IT operational performance measures
·      Monitoring and review controls

Main Types of System Development Controls

·         Application systems development process controls
·         System development quality controls
·         Change management controls
·         Systems development personnel controls
·         Monitoring and review controls.

Main Types of Enterprise Architecture Controls

·         Enterprise Architecture (EA) description controls
·         Enterprise Architecture business related controls
·         Enterprise Architecture development roles
·         Enterprise Architecture IT-related controls
·         Enterprise Architecture performance measures
·         Designing and implementing plan for an Enterprise Architecture (EA) framework
·         Monitoring and review controls
·         Organizational Structure

Main Types Of IT Administration Controls

  • IT administration performance measures.
  • IT asset controls
  • IT budget
  • IT office administration controls
  • IT personnel management controls
  • IT purchasing controls
  • IT standards, policies and procedures
  • Monitoring and review controls

IT Department Functional Description Controls

  • Detailed IT department terms of reference
  • IT department job description controls
  • IT department overall objectives
  • IT department overall terms of reference
  • Other IT roles at the senior management level

Main Types Of IT Organization Controls

·         IT department functional description controls
·         IT governance and control frameworks
·         IT organization controls
·         IT organization performance measures.
·         IT vision, mission and values statements
·         Monitoring and review controls

IT Governance Responsibilities

Strategy and structure – including the formulation of IT strategy, enterprise architecture and IT standards

Multi-year planning of initiatives, product and service plans, and the IT sourcing plan for the enterprise

Annual planning of priorities, initiatives, the operating plan/budget and capital plan/budget

Execution – which includes implementation, variations to the plan, performance targets and plans, and benefits realization.

Accenture’s IT strategy includes seven key elements:

·     Creating strong, central IT governance

·     Aligning the IT operating model with Accenture’s go-to- market strategy

·    Running IT like a business based on a managed-services approach

·    Consolidating, standardizing and centralizing operations

·    Focusing the workforce strategy on variable resources and low-cost locations

·    Strengthening IT performance measurement processes

·    Communicating successes and benefits realization at every opportunity.

Friday, November 16, 2012

Why we make bad decisions?

How to Clean Up Your Online Reputation

http://news.yahoo.com/blogs/upgrade-your-life/clean-online-reputation-135856619.html

When there is IT-based competitive advantage

·    A concern for information content exists
·  A consensus between senior managers and IS managers is present
·  Alignment of IS with organizational infrastructure is in force
·  Business literate IS managers are the norm 
·  IS literate business managers constitute majority
·  Maximum interaction between IS and business managers happens regularly
·  Strategic processes which were well documented are used appropriately
·  Strong well-established planning approach which involved staff at all levels is executed regularly

IT Audit Socialite

IT Leadership Roles

CHIEF OPERATING STRATEGIST: The chief operating strategist invents the future with senior management. The chief operating strategist is the top IS executive who is focused on the future agenda of the IS organization. The strategist has parallel responsibilities related to helping the business design the future, and then delivering it.
CHANGE LEADER: The change leader orchestrates resources to achieve optimal implementation of the future. The essential role of the change leader is to orchestrate all those resources that will be needed to execute the change program.
CHIEF ARCHITECT: The chief architect designs future possibilities for the business. The primary work of the chief architect is to design and evolve the IT infrastructure so that it will expand the range of future possibilities for the business, not define specific business outcomes.
PRODUCT DEVELOPER: The product developer helps define the company's place in the emerging digital economy. For example, a product developer might recognize the potential for performing key business processes (perhaps order fulfillment, purchasing or delivering customer support) over electronic linkages such as the Internet.
TECHNOLOGY PROVOCATEUR: The technology provocateur embeds IT into the business strategy. The technology provocateur works with senior business executives to bring IT and realities of the IT marketplace to bear on the formation of strategy for the business.
COACH: The coach teaches people to acquire the skillsets they will need for the future. Coaches have two basic responsibilities: teaching people how to learn, so that they can become self-sufficient, and providing team leaders with staff able to do the IT-related work of the business

IT Vision Characteristics

  • Stage of development
  • Degree of change implied
  • Alignment with organizational strategic vision
  • Degree of formality, and
  • Source Legitimacy.

Human Resources Forecasting Model

Formal rule structure
Rules governing allocation decisions
Employee model
Autonomous developments of the employees over time-- an inflow and outflow sub -model are part of the employee model
Function model
Job structure and changes
Matching model
Algorithms to match job vacancies and their requirements with the employees and their qualifications

A 'function' contains the following attributes:
·    The minimum number of employees needed in the function for the organization to operate at all
·   The optimal number of employees needed in the function for the organization to operate properly
·   The maximum number of employees that can be allowed because of resource constraints
·    The function requirements, i.e., the competencies that employees must have to enter the function. Examples are age, rank, education, training and experience.

Several outcomes can be immediately observed from the simulation, for any wanted timeframe or point in time:
·  functions that are fulfilled
·  functions with a shortage of employees
·  employees who hold a function
·  employees who do not hold a function
·  competencies of employees that are not needed by the organization

Wednesday, November 14, 2012

Your body language shapes who you are

Standing in a posture of confidence, even when we don’t feel confident -- can affect testosterone and cortisol levels in the brain, and might even have an impact on our chances for success.

Degrees of Cross-Functional Integration

STRONG Degree of Cross-Functional Integration

Effective Partnerships:  Effective cross-functional integration, seamless interaction, sophisticated systems, effective use of information technology to achieve goals of another area, strong and transparent communication structures.

Data and Needs Resolution:  Developing more proactive participation and collaboration mechanisms, efforts focused on developing a shared understanding of data and support needs, access to data, and resolving data quality issues.

Communication Development:  Working toward better inter-department understanding and developing quality communication, begin getting ore inter-department input in planning and decision-making processes, basic participation and collaboration occur.

Understanding:  Trust, basic understanding and appreciation are all issues to be resolved, interaction begins to focus on communication of basic information such as priorities and rationales for decision making, as well as the medium and frequency of communication.

Dis-Integration:  Integration does not exist, open hostility or complete lack of understanding or trust might be present, there is little to no effective interaction related to the work relationship.

NO Cross-Functional Integration

Strategic Alignment - Level 5 Optimized process

COMMUNICATIONS:  Informal, pervasive
COMPETENCY/VALUE:  Extended to external partners
GOVERNANCE:  Integrated across the org & parters
PARTNERSHIP:  IT-business co-adaptive
SCOPE & ARCHITECTURE:  Evolving with partners
SKILLS:  Education/careers/rewards across the organization

Strategic Alignment - Level 4 Improved/managed process

COMMUNICATIONS:  Relaxed, informaln
COMPETENCY/VALUE:  Cost effective; Sompe partners
GOVERNANCE:  Managed across the organizations
PARTNERSHIP:  IT enables/drives business strategy
SCOPE & ARCHITECTURE:  Integrated with partners
SKILLS:  Shared risk and rewards

Strategic Alignment - Level 3 Established focussed process

COMMUNICATIONS:  Good understanding; Emerging relaxed
COMPETENCY/VALUE:  Some cost effective
GOVERNANCE:  Relevant process across the org; mostly responsive
PARTNERSHIP:  IT seen as an asset; process driver
SCOPE & ARCHITECTURE:  Integrated across the organization
SKILLS:  Emerging value service provider

Strategic Alignment - Level 2 Committed process

COMMUNICATIONS:  Limited business/IT understanding of each other
COMPETENCY/VALUE:  Cost efficiency at thefunctionalorganization
GOVERNANCE:  Tactical at Functional level; Occasional responsive
PARTNERSHIP:  IT emerging as an asset; process enabler
SCOPE & ARCHITECTURE:  Transactinos (ESS, DSS)
SKILLS:  Differs across functional organizations

Strategic Alignment - Level 1 Initial/Ad Hoc process


COMMUNICATIONS:  Business/IT lacks understanding of each other
COMPETENCY/VALUE:  Some technical measurements
GOVERNANCE:  No formal process; Cost center; Reactive priorities
PARTNERSHIP:  Conflict; IT a cost of doing business
SCOPE & ARCHITECTURE:  Tranditional (such as accounting, email)
SKILLS:  IT takes risk, little reward; Technical training

Strategic Components of Alignment Maturity

1.  Communications Maturity
2.  Competency/Value Measurement Maturity
3.  Governance Maturity
4.  Partnership Maturity
5.  Scope & Architecture Maturity
6.  Skills Maturity

IT and Business Alignment Factors

ENABLERS
·    Senior executive support for IT
·    IT involved in strategy development
·    IT understands the business
·    Business - IT partnership
·    Well-prioritized IT projects
·    IT demonstrates leadership

INHIBITORS
·    IT/business lack close relationships
·    IT does not prioritize well
·    IT fails to meet commitments
·    IT does not understand business
·    Senior executives do not support IT
·    IT management lacks leadership

Tuesday, November 13, 2012

How to spot a liar?

Lying in Digital Age

ITIL Access Management

The management of, and provision of expert advice on, the selection, design, justification, implementation and operation of information security controls and management strategies to maintain the confidentiality, integrity, availability, accountability and relevant compliance of information systems with legislation, regulation and relevant standards.

Level 2 Assist
Applies and maintains specific security controls as required by organizational policy and local risk assessments to maintain confidentiality, integrity and availability of business information systems and to enhance resilience to unauthorized access. Contributes to vulnerability assessments. Recognizes when an IT network/system has been attacked internally, by a remote host, or by malicious code, such as virus, worm or Trojan etc., or when a breach of security has occurred. Takes immediate action to limit damage, according to the organization’s security policy, which may include escalation to next level, and records the incident and action taken. Demonstrates effective communication of security issues to business managers and others. Performs basic risk assessments for small information systems.
Level 3 Apply
Conducts security risk and vulnerability assessments for defined business applications or IT installations in defined areas, and provides advice and guidance on the application and operation of elementary physical, procedural and technical security controls (e.g. the key controls defined in ISO27001). Performs risk and vulnerability assessments, and business impact analysis for medium size information systems. Investigates suspected attacks and manages security incidents.
Level 4 Enable
Obtains and acts on vulnerability information and conducts security risk assessments for business applications and computer installations; provides authoritative advice and guidance on security strategies to manage the identified risk. Investigates major breaches of security, and recommends appropriate control improvements. Interprets security policy and contributes to development of standards and guidelines that comply with this. Performs risk assessment, business impact analysis and accreditation for all major information systems within the organization. Ensures proportionate response to vulnerability information, including appropriate use of forensics.
Level 5 Ensure, Advise
Provides leadership and guidelines on information assurance security expertise for the organization, working effectively with strategic organizational functions such as legal experts and technical support to provide authoritative advice and guidance on the requirements for security controls. Provides for restoration of information systems by ensuring that protection, detection, and reaction capabilities are incorporated.

ITIL IT Operations Management

The operation and control of the IT infrastructure (typically hardware, software, data stored on various media, and all equipment within wide and local area networks) required to deliver and support IT services and products to meet the needs of a business. Includes preparation for new or changed services, operation of the change process, the maintenance of regulatory, legal and professional standards, and the monitoring of performance of systems and services in relation to their contribution to business performance, their security and their sustainability.  Contributes, under instruction, to system operation.
Level 1 Follow
Carries out agreed operational procedures of a routine nature. Contributes to maintenance, installation and problem resolution.
Level 2 Assist
Carries out agreed operational procedures, including network configuration, installation and maintenance. Uses network management tools to collect and report on network load and performance statistics. Contributes to the implementation of maintenance and installation work. Uses standard procedures and tools to carry out defined system backups, restoring data where necessary. Identifies operational problems and contributes to their resolution.
Level 3 Apply
Provides technical expertise to enable the correct application of operational procedures. Uses network management tools to determine network load and performance statistics. Contributes to the planning and implementation of maintenance and installation work. Implements agreed network changes and maintenance routines. Identifies operational problems and contributes to their resolution, checking that they are managed in accordance with agreed standards and procedures. Provides reports and proposals for improvement to specialists, users and managers.

ITIL Application Management

The provision of application maintenance and support services, either directly to users of the systems or to service delivery functions. Support typically includes investigation and resolution of issues and may also include performance monitoring. Issues may be resolved by providing advice or training to users, by devising corrections (permanent or temporary) for faults, making general or site-specific modifications, updating documentation, manipulating data, or defining enhancements Support often involves close collaboration with the system's developers and/or with colleagues specializing in different areas, such as Database administration or Network support.
Level 1 Follow
Assists in the investigation and resolution of issues relating to applications. Assists with specified maintenance procedures.
Level 2 Assist
Identifies and resolves issues with applications, following agreed procedures. Uses application management software and tools to collect agreed performance statistics. Carries out agreed applications maintenance tasks.
Level 3 Apply
Maintains application support processes, and checks that all requests for support are dealt with according to agreed procedures. Uses application management software and tools to investigate issues, collect performance statistics and create reports.
Level 4 Enable
Drafts and maintains procedures and documentation for applications support. Manages application enhancements to improve business performance. Ensures that all requests for support are dealt with according to set standards and procedures.

ITIL Technical Management

The provision of specialist expertise to facilitate and execute the installation and maintenance of system software such as operating systems, data management products, office automation products and other utility software.

Level 2 Assist
Uses system management software and tools to collect agreed performance statistics. Carries out agreed system software maintenance tasks.
Level 3 Apply
Reviews system software updates and identifies those that merit action. Tailors system software to maximize hardware functionality. Installs and tests new versions of system software. Investigates and coordinates the resolution of potential and actual service problems. Prepares and maintains operational documentation for system software. Advises on the correct and effective use of system software.
Level 4 Enable
Evaluates new system software, reviews system software updates and identifies those that merit action. Ensures that system software is tailored to facilitate the achievement of service objectives. Plans the installation and testing of new versions of system software. Investigates and coordinates the resolution of potential and actual service problems. Ensures that operational documentation for system software is fit for purpose and current. Advises on the correct and effective use of system software.

Monday, November 12, 2012

ITIL Request Management

The management and control of one or more client service functions, including strategy, support for business development, quality of service and operations.
Level 2 Assist
Acts as the routine contact point. Assists with the development of and applies client services standards to resolve or escalate clients’ service problems.
Level 3 Apply
Monitors client services function and collects performance data. Assists with the specification, development, research and evaluation of client services standards. Applies these standards to resolve or escalate clients’ service problems and gives technical briefings to staff members.
Level 4 Enable
Carries out day-to-day management of the client services function. Defines service levels for client services staff and monitors performance. Takes responsibility for specification, agreement and application of client services standards and for the resolution of clients’ service problems.
Level 5 Ensure, Advise
Sets the strategic direction and takes responsibility for the full range of client service functions, including organizational frameworks for complaints, service standards and operational agreements. Defines service levels, standards and the monitoring process for client service staff. Gives technical leadership to operational staff, and takes responsibility for business continuity and legal compliance.

ITIL Event Management

The resolution (both reactive and proactive) of problems throughout the information system lifecycle, including classification, prioritization and initiation of action, documentation of root causes and implementation of remedies to prevent future incidents.
Level 3 Apply
Investigates Events in systems and services. Assists with the implementation of agreed remedies and preventative measures.
Level 4 Enable
Initiates and monitors actions to investigate and resolve Events in systems and services. Assists with the implementation of agreed remedies and preventative measures.
Level 5 Ensure, Advise
Ensures that appropriate action is taken to anticipate, investigate and resolve Events in systems and services. Ensures that such Events are fully documented within the relevant reporting system(s). Coordinates the implementation of agreed remedies and preventative measures. Analyzes patterns and trends.

ITIL Incident Management

The processing and coordination of appropriate and timely responses to incident reports, including channeling requests for help to appropriate functions for resolution, monitoring resolution activity, and keeping clients appraised of progress towards service restoration.  Receives and handles requests for support following agreed procedures. Promptly allocates calls as appropriate.  Maintains relevant records.
Level 1 Follow
Receives and handles requests for support following agreed procedures. Responds to common requests for support by providing information to enable resolution and promptly allocates unresolved calls as appropriate. Maintains records and advises relevant persons of actions taken.
Level 2 Assist
Receives and handles requests for support following agreed procedures. Responds to requests for support by providing information to enable incident resolution and promptly allocates unresolved calls as appropriate. Maintains records and advises relevant persons of actions taken.
Level 3 Apply
Ensures that incidents and requests are handled according to agreed procedures. Ensures that documentation of the supported components is available and in an appropriate form for those providing support. Creates and maintains support documentation.
Level 4 Enable
Ensures that the inventory of components to be supported is complete and current. Drafts and maintains policy, standards and procedures for the service desk and incident management. Schedules the work of service desk staff to meet agreed service levels.   

ITIL Problem Management

The resolution (both reactive and proactive) of problems throughout the information system lifecycle, including classification, prioritization and initiation of action, documentation of root causes and implementation of remedies to prevent future incidents.
Level 2 Assist
Investigates problems in systems and services. Assists with the implementation of agreed remedies and preventative measures.
Level 3 Apply
Initiates and monitors actions to investigate and resolve problems in systems and services. Assists with the implementation of agreed remedies and preventative measures.
Level 4 Enable
Ensures that appropriate action is taken to anticipate, investigate and resolve problems in systems and services. Ensures that such problems are fully documented within the relevant reporting system(s). Coordinates the implementation of agreed remedies and preventative measures. Analyzes patterns and trends.

ITIL Continual Service Improvement

The capability to recognize and exploit business opportunities provided by IT, (for example, the Internet), to ensure more efficient and effective performance of organizations, to explore possibilities for new ways of conducting business and organizational processes, and to establish new businesses.
Level 4 Enable
Actively monitors for, and seeks, opportunities, new methods and trends in IT capabilities and products to the advancement of the organization. Clearly articulates, and formally reports their benefits.
Level 5 Ensure, Advise
Recognizes potential strategic application of IT, and initiates investigation and development of innovative methods of exploiting IT assets, to the benefit of organizations and the community. Plays an active role in improving the interface between the business and IT.