600 likes | 948 Views
IT Governance: A Practical Guide. - J. Mark Sanman, CIA, CISA, CISSP-ISSMP November 2009 Greater Cincinnati ISACA Chapter Meeting. Procter & Gamble
E N D
IT Governance:A Practical Guide • - J. Mark Sanman, CIA, CISA, CISSP-ISSMP • November 2009 Greater Cincinnati ISACA Chapter Meeting
Procter & Gamble 32 years in various IT, IT Audit, and IT Governance roles. Current assignment is in IT Commercial Governance, with specific responsibilities involving supplier governance, risk management and governance audit coordination. Previous roles included IT infrastructure audit management, e-business and e-commerce infrastructure management, EDI (Electronic Data Interchange) for global customer business development, and implementation manager - global network. Work at one time or another has involved travel to 35 countries on 6 continents. Education MSEE - University of Cincinnati BSEE - University of Idaho Professional Certifications Certified Internal Auditor (CIA) - 2002 Certified Information Systems Auditor (CISA) - 2004 Certified Information Systems Security Professional (CISSP) - 2005 Information Systems Security Management Professional (ISSMP) - 2009 • Biography:
Disclaimer • The opinions contained in this presentation are those of the presenter, and do not necessarily reflect the views of The Procter & Gamble Company.
Agenda • Why is IT Governance a ‘Hot Topic’? • IT Governance Definitions • IT Governance Considerations in a Sourced Environment • An Audit Checklist for IT Governance 4
Why is IT Governance a ‘Hot Topic’? • Increased sensitivity to protecting stakeholder interests • Shareholders (see: Sarbanes Oxley) • Consumers (see: HIPAA) • Suppliers (see: PCI)
Why is IT Governance a ‘Hot Topic’? • Recognized need for tight business linkage • Strategic Alignment • Value Delivery • Resource Management • Risk Management • Performance Management
Why is IT Governance a ‘Hot Topic’? • Effective Management of Outsourced IT Suppliers • Relationship Management • Financial Management • Performance Management • Contract Management
IT GovernanceDefinitions IIA International Professional Practices Framework: [IT Governance] Consists of the leadership, organizational structures and processes that ensure that the enterprise’s information technology sustains and extends the organization’s strategies and objectives. [IT Controls] Controls that support business management and governance as well as provide general and technical controls over information technology infrastructures such as applications, information, infrastructure, and people. [Governance] The combination of processes and structures implemented by the board to inform, direct, manage, and monitor the activities of the organization toward the achievement of its objectives.
IT GovernanceDefinitions CobiT 4.1: IT Governance is the responsibility of executives and the board of directors, and consists of the leadership, organizational structures and processes that ensure that the enterprise’s IT sustains and extends the organization’s strategies and objectives.
IT GovernanceDefinitions (ISC)2 Ethics Preamble: Safety of the commonwealth, duty to our principals, and to each other requires that we adhere, and be seen to adhere, to the highest ethical standards of behavior.
The business of running IT vs. running the technology Setting the rules and assuring they are followed An ethical responsibility to stakeholders Principal - business Commonwealth - people Each other - reputation IT GovernanceHigh Level Summary
IT GovernanceCobiT Focus Areas • Strategic Alignment • Value Delivery • Resource Management • Risk Management • Performance Measurement
IT GovernancePractical Guidelines • Leadership and Clear Business Ownership • Aligned Business-Relevant Measures • Complete and Accurate Inventories • Linking Technical and Business Risk
Clear Business Ownership and Direction • Alignment of Business and IT Objectives (CobiT 4.1 ‘Framework’) • Enterprise Strategy • Business Goals for IT • IT Goals • Enterprise Architecture for IT • IT Scorecard
Business - RelevantMeasures • Requires translation of traditional IT measures • Performance against Financial goals, either Business or IT • Operational efficiency • Innovation
Complete and Accurate Inventories • IT-dependent Business Processes • Data Repositories and Information Flows • IT Infrastructure • IT Resources and Processes
Linking Technical and Business Risk • Risk is the ‘lingua franca’ of business. • Management needs to be able to compare IT Risks with other risks. • IT Governance must do an effective job of translating technical risks to business risks.
IT Governance Basics Questions?
NPS IT Governance in a Sourced Environment
IT Governance in aSourced Environment Business Strategy and Processes IT Governance Commercial Relationship Commercial Relationship Suppliers’ IT Strategy and Processes
Considerations in a Sourced Environment • Sourcing Strategy • Contract Management • Finance Management • Relationship Management • Performance Management
Sourcing Strategy • Part of IT Strategic Plan • Inventory of critical Supplier relationships • Update based on changes to Business, IT or Supplier Strategies • May contain intervention plans
Contract Management • Initial negotiation and in-life change management • Defines Services/Quality • Defines ownership of Intellectual Property • Compliance with Law and Policy • Audit Rights
Contract Change Management • Required by either changing business needs or to address ambiguity. • Should be viewed as a negotiation. • Each party will attempt to get concessions not previously obtained - value is at risk • Depend on Relationship Management for smaller changes to avoid this risk
Intellectual Property • Supplier IP may be used to deliver efficiencies ($) • However, use of Supplier IP may limit sourcing flexibility. • Who owns process ‘know-how’ and does this change over time? • What risk does this represent? NPS
Intellectual PropertyMitigations • Inventory, inventory, inventory • IT processes supporting the business • Materials (documents, rights, etc.) • Risk Management discussion with business • Seek legal help • Follow up!
Audit Rights • Business requirements drive specifics. • Must be in the initial contract • For supplier shared services, SAS70 Type II • Audit rights should be unlimited and at no cost. NPS
Finance Management • Deal financials reporting • Invoice Verification • Service receipt • Credits • Incentives • Internal cost recovery NPS
Finance Management • This is THE PLACE to receive an independent confirmation of IT value delivery. • Budgets are a very unforgiving reality check! NPS
Relationship Management • Overall Supplier management • Monitor business needs • Communication Forums • Issue Management • Risk Management • Project Management
Risk Management • IT Governance process to evaluate Supplier Financial, Service Delivery, Relationship and Information Security risks in total. • As before, there may be a translation here from technical risk to business risk. • Can use Probability x Business Impact as the metric. The business should supply the Impact. • This can be a powerful tool to use with Suppliers. They speak the lingua franca as well. NPS
Project Management • Good Project Management helps assure value delivery • Define ‘project’ vs. ‘daily work’ in the contract. • Has linkages to Finance Management (paying Project costs), Service Delivery (assuring Project deliverables) NPS
Performance Management • Aligning Service Delivery Requirements • Managing and Reporting against SLAs • Management of individual projects • Work prioritization
IT Governance in a Sourced Environment Questions?
IT GovernanceAudit Planning • Audit Team Composition • Audit Criteria • Learnings from the Balanced Scorecard Approach
Audit Team Composition • Leadership - Business or IT? • Audit Supervision and Auditor in Charge Independence is a must • Beware setting up an audit team that may reflect corporate IT Governance issues • Consider sourcing knowledgeable auditors
IT Governance AuditCriteria / Standards • IIA Governance Auditing Standards • ISACA / ITGI IT Governance Auditing Guidelines • ITGI Risk IT Framework • ITGI Val IT Framework • << Insert your Company business policies here >>
Learnings from the Balanced Scorecard • Consider IT Governance from various business points of view (1) • Corporate • Customer • Operational Excellence • Future / Sustainability 1. “Measuring and Improving IT Governance Through the Balanced Scorecard” Information Systems Control Journal, Volume 2, 2005
AuditingIT Governance Questions?
What We’ve Covered Tonight • Why is IT Governance a ‘Hot Topic’? • IT Governance Definitions • IT Governance Considerations in a Sourced Environment • An Audit Checklist for IT Governance 50