Technology Governance
Smart, Sexy, and Simple in
Seven Steps

12NTCtechgov

 Johan Hammerstrom
   Community IT Innovators
Evaluate This Session!
Each entry is a chance to win an NTEN engraved iPad!




          or Online at www.nten.org/ntc/eval
Johan Hammerstrom
     Vice President
     Community IT Innovators

johan@citidc.com

     @JohanCITI




           12NTCtechgov        Slide 2
Disclaimer
Smart?
    I’ll do my best
Sexy?
    Don’t count on it
Simple?
    That’s my goal


                 12NTCtechgov   Slide 3
Alphabet Soup

             ISO-9000

                           ITGI



                           photo: Wikimedia Commons


            12NTCtechgov                        Slide 4
Take-aways
1. Why business objectives should drive all
   technology decisions
2. Why user adoption and support is critical to all
   technology management
3. A usable technology governance outline that can
   be used within your organization today




                      12NTCtechgov                Slide 5
the 7 Steps
    1. Planning
2. Implementation
  3. Deployment
 4. Management
     5. Support
 6. User adoption
     7. Training




    12NTCtechgov    Slide 6
Process
    1. Planning
2. Implementation
  3. Deployment
 4. Management
     5. Support
 6. User adoption
     7. Training




    12NTCtechgov    Slide 7
50,000 foot view




                    photo: Wikimedia Commons


     12NTCtechgov                        Slide 8
Purpose

 Organizations exist for a purpose.


              MISSION



                  12NTCtechgov        Slide 9
Corporate Governance

The system by which companies are directed
 and controlled…

                                  Cadbury Report, 1992


          to achieve their purpose.


                   12NTCtechgov                    Slide 10
IT Governance
The leadership and organizational structures
 and processes that ensure that the
 organization’s IT sustains and extends the
 organization’s strategies and objectives.

                                       ITGI, 2006




                    12NTCtechgov               Slide 11
IT Governance redux
The systems      d organizational structures
 and processes that ensure that the
 organization’s IT sustains and extends the
 organization’s strategies and mission.

                                   revised ITGI, 2012




                    12NTCtechgov                 Slide 12
essentials

    1. Leadership
    2. Organizational Structures
    3. Processes




              12NTCtechgov         Slide 13
Governance Maturity
                                       “optimized”

                               “managed”

                      “defined”

           “ad-hoc”

  “none”




                        12NTCtechgov                 Slide 14
COBIT



Control
Objectives
for IT

                            source: COBIT 5
             12NTCtechgov                     Slide 15
Control?

   Well-planned
       well-implemented
           well-maintained




             12NTCtechgov    Slide 16
source: COBIT 5

12NTCtechgov                     Slide 17
COBIT
Principles




                            source: COBIT 4.1 Executive Summary

             12NTCtechgov                               Slide 18
Strategic Alignment

                   Business
                    Goals
   Requirements                    Information

                    IT Goals
                  IT Processes
                                     source: COBIT 4.1 Executive Summary

                    12NTCtechgov                                 Slide 19
Strategic Alignment

                    Mission

   Requirements                    Information

                    IT Goals
                  IT Processes
                                     source: COBIT 4.1 Executive Summary

                    12NTCtechgov                                 Slide 20
Mission




  IT Goals
               Information
IT Processes




                •   Outcome measurements
                •   Performance Metrics
                •   Messaging
                •   Website
                •   Files
                •   Databases
                •   Internet Access

                          12NTCtechgov     Slide 21
Mission




             Requirements     IT Goals
                            IT Processes




•   Business Continuity
•   Reporting
•   Compliance
•   Automation/efficiency
•   Remote access
•   Support
• COST

           12NTCtechgov             Slide 22
Strategic Alignment Dialogue

                   Business
                    Goals
   Requirements                    Information

                    IT Goals
                  IT Processes
                                     source: COBIT 4.1 Executive Summary

                    12NTCtechgov                                 Slide 23
Strategic Alignment
                                     Business
                                      Goals




                                      IT Goals
                                    IT Processes




1. Leadership willing and able to have
   dialogue
2. Organizational Structures that
   enable the conversation
3. Processes that support it

                12NTCtechgov                       Slide 24
Process
                                 Business
                                  Goals




                                  IT Goals

  1.Planning                    IT Processes




  2.Implementation
  3.Deployment
  4.Management
  5.Support
  6.User adoption
  7.Training


                 12NTCtechgov                  Slide 25
Dialogue
around…




                          source: COBIT 4.1 Executive Summary

           12NTCtechgov                               Slide 26
Key Decisions
1. What resources are required?
2. What risks are tolerable?
3. What measurements are needed?




                                source: COBIT 4.1 Executive Summary

                 12NTCtechgov                               Slide 27
Required Resources
  1.   Specific systems
  2.   Support staff
  3.   Training
  4.   Hosting
  5.   Infrastructure




                                   source: COBIT 4.1 Executive Summary

                    12NTCtechgov                               Slide 28
Tolerable Risks
  1.   Business Continuity
  2.   Disaster Recovery
  3.   RPO
  4.   RTO
  5.   Hacking threats
  6.   Malware
  7.   Spam


                    12NTCtechgov   Slide 29
Measurements Needed
 1.   Reporting requirements
 2.   Compliance requirements
 3.   Management
 4.   Performance metrics
 5.   Project status




                  12NTCtechgov   Slide 30
Simple Risk Matrix

             Tape        Availability   Hosted
             Backup
 RTO         1-2 weeks   1 hr           n/a
 RPO         1-7 days    15 min         1 day
 Retention   6 months    3 months       3 weeks
 Reports     Custom      Custom         Limited
 Cost        $10,000     $20,000        $15,000


                    12NTCtechgov                  Slide 31
Simple Risk Matrix

            Tape       Availability   Hosted
            Backup
 Down for… 1-2 weeks   1 hr           n/a
 Lost data… 1-7 days   15 min         1 day
 Retention 6 months    3 months       3 weeks
 Reports    Custom     Custom         Limited
 Cost       $10,000    $20,000        $15,000


                  12NTCtechgov                  Slide 32
Accountability




                            source: COBIT 4.1 Executive Summary

             12NTCtechgov                               Slide 33
Value Delivery
                                     Business
                                      Goals




                                      IT Goals
                                    IT Processes




1. Leadership exercising oversight
2. Organizational Structures that
   enable the accountability
3. Processes that deliver value


                12NTCtechgov                       Slide 34
Process
                                 Business
                                  Goals




                                  IT Goals

  1.Planning                    IT Processes




  2.Implementation
  3.Deployment
  4.Management
  5.Support
  6.User adoption
  7.Training


                 12NTCtechgov                  Slide 35
lifecycle                             Key
                                    Decisions




                           source: COBIT 4.1 Executive Summary

            12NTCtechgov                               Slide 36
Accountability
1. How will leadership know if IT is
   delivering value?
   a) Metrics?
   b) Reports?
2. Is responsibility clearly defined?
   a) SLA
   b) Policy


                     12NTCtechgov       Slide 37
In closing…
1. Start with Strategic Alignment
2. Create Dialogue around…
   a) Resource Management
   b) Risk Management
   c) Performance Measurement
3. Identify Value Delivery through
   a) Accountability
   b) Regular reports?

                    12NTCtechgov     Slide 38
Resources

   •   www.isaca.org
   •   www.citidc.com/ntc2012
   •   johan@citidc.com
   •   @JohanCITI




                12NTCtechgov    Slide 39
Evaluate This Session!
Each entry is a chance to win an NTEN engraved iPad!




          or Online at www.nten.org/ntc/eval

Technology Governance: Smart, Sexy and Simple in Seven Steps

  • 1.
    Technology Governance Smart, Sexy,and Simple in Seven Steps 12NTCtechgov Johan Hammerstrom Community IT Innovators
  • 2.
    Evaluate This Session! Eachentry is a chance to win an NTEN engraved iPad! or Online at www.nten.org/ntc/eval
  • 3.
    Johan Hammerstrom Vice President Community IT Innovators johan@citidc.com @JohanCITI 12NTCtechgov Slide 2
  • 4.
    Disclaimer Smart? I’ll do my best Sexy? Don’t count on it Simple? That’s my goal 12NTCtechgov Slide 3
  • 5.
    Alphabet Soup ISO-9000 ITGI photo: Wikimedia Commons 12NTCtechgov Slide 4
  • 6.
    Take-aways 1. Why businessobjectives should drive all technology decisions 2. Why user adoption and support is critical to all technology management 3. A usable technology governance outline that can be used within your organization today 12NTCtechgov Slide 5
  • 7.
    the 7 Steps 1. Planning 2. Implementation 3. Deployment 4. Management 5. Support 6. User adoption 7. Training 12NTCtechgov Slide 6
  • 8.
    Process 1. Planning 2. Implementation 3. Deployment 4. Management 5. Support 6. User adoption 7. Training 12NTCtechgov Slide 7
  • 9.
    50,000 foot view photo: Wikimedia Commons 12NTCtechgov Slide 8
  • 10.
    Purpose Organizations existfor a purpose. MISSION 12NTCtechgov Slide 9
  • 11.
    Corporate Governance The systemby which companies are directed and controlled… Cadbury Report, 1992 to achieve their purpose. 12NTCtechgov Slide 10
  • 12.
    IT Governance The leadershipand organizational structures and processes that ensure that the organization’s IT sustains and extends the organization’s strategies and objectives. ITGI, 2006 12NTCtechgov Slide 11
  • 13.
    IT Governance redux Thesystems d organizational structures and processes that ensure that the organization’s IT sustains and extends the organization’s strategies and mission. revised ITGI, 2012 12NTCtechgov Slide 12
  • 14.
    essentials 1. Leadership 2. Organizational Structures 3. Processes 12NTCtechgov Slide 13
  • 15.
    Governance Maturity “optimized” “managed” “defined” “ad-hoc” “none” 12NTCtechgov Slide 14
  • 16.
    COBIT Control Objectives for IT source: COBIT 5 12NTCtechgov Slide 15
  • 17.
    Control? Well-planned well-implemented well-maintained 12NTCtechgov Slide 16
  • 18.
  • 19.
    COBIT Principles source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 18
  • 20.
    Strategic Alignment Business Goals Requirements Information IT Goals IT Processes source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 19
  • 21.
    Strategic Alignment Mission Requirements Information IT Goals IT Processes source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 20
  • 22.
    Mission ITGoals Information IT Processes • Outcome measurements • Performance Metrics • Messaging • Website • Files • Databases • Internet Access 12NTCtechgov Slide 21
  • 23.
    Mission Requirements IT Goals IT Processes • Business Continuity • Reporting • Compliance • Automation/efficiency • Remote access • Support • COST 12NTCtechgov Slide 22
  • 24.
    Strategic Alignment Dialogue Business Goals Requirements Information IT Goals IT Processes source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 23
  • 25.
    Strategic Alignment Business Goals IT Goals IT Processes 1. Leadership willing and able to have dialogue 2. Organizational Structures that enable the conversation 3. Processes that support it 12NTCtechgov Slide 24
  • 26.
    Process Business Goals IT Goals 1.Planning IT Processes 2.Implementation 3.Deployment 4.Management 5.Support 6.User adoption 7.Training 12NTCtechgov Slide 25
  • 27.
    Dialogue around… source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 26
  • 28.
    Key Decisions 1. Whatresources are required? 2. What risks are tolerable? 3. What measurements are needed? source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 27
  • 29.
    Required Resources 1. Specific systems 2. Support staff 3. Training 4. Hosting 5. Infrastructure source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 28
  • 30.
    Tolerable Risks 1. Business Continuity 2. Disaster Recovery 3. RPO 4. RTO 5. Hacking threats 6. Malware 7. Spam 12NTCtechgov Slide 29
  • 31.
    Measurements Needed 1. Reporting requirements 2. Compliance requirements 3. Management 4. Performance metrics 5. Project status 12NTCtechgov Slide 30
  • 32.
    Simple Risk Matrix Tape Availability Hosted Backup RTO 1-2 weeks 1 hr n/a RPO 1-7 days 15 min 1 day Retention 6 months 3 months 3 weeks Reports Custom Custom Limited Cost $10,000 $20,000 $15,000 12NTCtechgov Slide 31
  • 33.
    Simple Risk Matrix Tape Availability Hosted Backup Down for… 1-2 weeks 1 hr n/a Lost data… 1-7 days 15 min 1 day Retention 6 months 3 months 3 weeks Reports Custom Custom Limited Cost $10,000 $20,000 $15,000 12NTCtechgov Slide 32
  • 34.
    Accountability source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 33
  • 35.
    Value Delivery Business Goals IT Goals IT Processes 1. Leadership exercising oversight 2. Organizational Structures that enable the accountability 3. Processes that deliver value 12NTCtechgov Slide 34
  • 36.
    Process Business Goals IT Goals 1.Planning IT Processes 2.Implementation 3.Deployment 4.Management 5.Support 6.User adoption 7.Training 12NTCtechgov Slide 35
  • 37.
    lifecycle Key Decisions source: COBIT 4.1 Executive Summary 12NTCtechgov Slide 36
  • 38.
    Accountability 1. How willleadership know if IT is delivering value? a) Metrics? b) Reports? 2. Is responsibility clearly defined? a) SLA b) Policy 12NTCtechgov Slide 37
  • 39.
    In closing… 1. Startwith Strategic Alignment 2. Create Dialogue around… a) Resource Management b) Risk Management c) Performance Measurement 3. Identify Value Delivery through a) Accountability b) Regular reports? 12NTCtechgov Slide 38
  • 40.
    Resources • www.isaca.org • www.citidc.com/ntc2012 • johan@citidc.com • @JohanCITI 12NTCtechgov Slide 39
  • 41.
    Evaluate This Session! Eachentry is a chance to win an NTEN engraved iPad! or Online at www.nten.org/ntc/eval