Comparison and Integration of IT Governance Frameworks to support IT Management

Author(s):  
S. Looso ◽  
M. Goeken ◽  
W. Johannsen

Recent years have seen an unprecedented consolidation of best practice know-how in various areas of IT management. With it came a certain popularity of standards and reference models (COBIT, ITIL, CMMI, ISO/IEC 27000 family etc.) commonly classified as frameworks for IT governance. Each of these frameworks aims to support certain parts of IT management with best practice knowledge and enhances the quality of the delivered IT Services. But now we are facing a situation characterised by an abundance of these IT governance frameworks. In particular their combined or parallel usage increasingly creates redundancies and issues of complexity. To organise an efficient interaction between frameworks and to cope with their heterogeneity; e.g. in process semantics and description techniques; the application of these frameworks has become a lively issue of research. In this contribution the authors will reflect on the state of the art in comparing and integrating IT governance frameworks, analyse pros and cons of various approaches, and present their own approach based on metamodelling. The authors consider metamodelling a promising approach to close the gap between high-level comparison and detailed mapping as it allows an identification of redundancies and incoherent semantics on a framework-independent level. Promising an increasing return on investment, harmonisation is an important topic within IT departments (Siviy et al., 2007). This approach is a first step toward an integrated and harmonised handling of the meanwhile mandatory frameworks for IT management.

Author(s):  
Martin Fröhlich ◽  
Wolfgang Johannsen ◽  
Karsten Wilop

Strategic IT management is increasingly concerned with requirements from regulatory bodies. This conformance part of IT management complements the classic performance side. Ideally both are integrated into IT Governance of an enterprise or organization. With the need to prove compliance with a wide diversity of laws and rules for IT systems (technology, processes, rules) the demand for proven support methods grows. Specifically best practice models are beginning to gain awareness and acceptance for IT Audits and for the less formal IT Assurance projects. The Control Objectives for Information and Related Technology (CobiT) reference model is increasingly being discussed as a framework of choice for IT Audits and IT Assurance. This chapter introduces requirements for IT Audits and IT Assurance projects and discuss the boundaries of applying the CobiT IT Assurance Guide in such environments.


POPULATION ◽  
2021 ◽  
Vol 24 (2) ◽  
pp. 66-75
Author(s):  
Elena Skvortsova

The article discusses the indicators of digitalization and quality of life, and their relationship. An overall assessment of the digitalization in Russia is given on the basis of statistical data from the Federal State Statistics Service and the Network Readiness Index (NRI-2020), which consists of 62 different indicators, including indicators of the quality of life. A number of statistical indicators in the field of ICT, published by the Federal State Statistics Service annually, characterize the digitalization process in dynamics. The Network Readiness Index demonstrates the ability of national economy to develop in the context of the digital transformation. Russia ranks 48th out of 134 countries in the NRI. Based on the Index, the points of Russia's lagging behind the leading countries and the points of growth of network readiness are identified. The mutual influence of digitalization and quality of life is analysed at a quantitative level, and its interpretation is given at a qualitative level. Separate indicators of the NRI in the overall rating of countries characterize Russia's network readiness as being at a fairly high level, especially in the area of possessing resources and skills for effective use of the Internet by the population, business and government. This conclusion can be confirmed by the facts that Russia has its own national IT-services, competing with global foreign ones. Russia needs to make certain adjustments related to the lag in network readiness: to intensify investments in the digital infrastructure of the 5th generation, in the latest technologies, to improve the regulatory framework, the legislation on e-commerce. It is concluded that the relatively slow pace of the digitalization of Russian society, with the account of its possible negative socio-economic consequences, may rather be an advantage in adapting the population to the digital transformation.


Author(s):  
Aileen Cater-Steel

IT service management best practice frameworks such as the IT Infrastructure Library® (ITIL®) aim to improve the quality of service to customers. This study reports on recent surveys and case studies of organizations which have embarked on IT service management improvement. It highlights specific difficulties experienced by organizations in changing the orientation of staff to customer service rather than technology. Six factors were found to be critical in achieving an effective service-oriented philosophy. The factors are support from senior management; the threat or opportunity to outsource IT services; integration of processes to provide end-to-end service; involvement of business stakeholders; culture change of IT staff to service excellence; and the redesign of processes prior to investing in tools.


2015 ◽  
Vol 2 (1) ◽  
pp. 53-62
Author(s):  
Doni Luanda

COBIT (Control Objectives for Information and related Technology) developed by ISACA(Information Systems and Control Association) and ITGI (Information Technology GovernanceInstitute) in 1992 and then used as a model of IT governance started from planning to evaluation.COBIT will always be synchronized with the standards, best practice and guidance within anorganization / company.COBIT is an IT governance framework good practice applicable International which is useful forunderstanding how a Manager managing and bridging the gap within an organization / companybetween requirements, technical issues, business risks that may arise and control to be delivered to thestakeholders. COBIT 5 is divided into 5 domains and the 37 IT process, they are:1. Evaluate, Direct and Monitor (EDM). è 5 IT process.2. Align, Plan and Organize (APO). è 13 IT process.3. Build, Acquire and Implement (BAI). è10 IT process4. Deliver, Service and Support (DSS). è 6 IT process5. Monitor, Evaluate and Assess (MEA). è 3 IT processIn the discussion of this paper author will discuss about Assessment COBIT 5 to support timeefficiency in IT services at PT.XYZ in area domain Align, Plan and Organize (APO) especially in“Manage business agreements – APO09” at the company where the author works.


Computers ◽  
2021 ◽  
Vol 10 (1) ◽  
pp. 8
Author(s):  
Juan Luis Rubio Sánchez

Educational centers (schools, academies, high schools, etc.) are usually small companies, which make them special in terms of management. The management of IT services is far from standard and based in home solutions. The disadvantage of this approach is clear, as it happened during the COVID-19 pandemic period. The solution to properly managing IT services is based on the use of the ITIL (Information Technology Infrastructure Library). The question is how to apply this standard that only defines the processes to implement, but does not describe the way or the order to implement them. In this article it is shown which IT processes are really needed in any educational center and the order in which they should be implemented. The method used consists of fulfilling a knowledge database with extensive information from schools, academies, and other educational centers. After that, an existing optimization model is adopted and a representative learning center is defined, which is used to propose the IT processes sequence; finally, a set of optimal IT processes and the order to implement them is defined. These ordered processes optimize the quality of IT for learning services. The main result is an ordered set of IT processes that best fit the needs of IT departments in small educational centers.


2018 ◽  
Vol 6 (2) ◽  
pp. 97-102
Author(s):  
Anita Febriani ◽  
Anita Febriani

Success in providing information services can provide a positive impact to the organization that is in accordance with the expectations of stakeholders. Therefore, the application of IT governance, especially for academic information systems need to be monitored and evaluated to ensure that the entire mechanism of IT management goes according to plan, objectives and business processes. The evaluation also should not only be done in the early stages of a system implemented, but should also be done regularly. The methodology in this study using the COBIT 5 framework that begins with those identified and mapped to the COBIT 5 processes selected. We then measured against these processes to determine the level of the current process capability and also carried out targeting the expected level of capability. Process capability level gap analysis of current and expected conducted to determine the extent to which improvements should be made to these processes. Recommendations for improvement of these processes is based on the COBIT framework 5. Results of this research is assessment and targeting capability level 5 COBIT 5 process were selected as well as recommendations for improvement of IT services activities.


2021 ◽  
Vol 20 (1) ◽  
pp. e17117
Author(s):  
Claudia Marcia Vasconcelos e Mello Dias ◽  
Jorge Ferreira da Silva ◽  
Augusto Cesar Arenaro e Mello Dias

Objective of the study: Evaluate, according to the Resource-based View (RBV) perspective, the impact IT governance and management have on the finalistic performance of Brazilian public-sector organizations in terms of the provision of high-quality processes and products.Methodology: Application of multivariate analysis techniques and a two-step cluster analysis (hierarchical method and K-means) in the iGov2017 Survey database which includes 482 organizations and is made available by the Federal Court of Accounts (TCU).Relevance: The research contributes to reducing the lack of academic publications that analyze the integration of the concepts of strategy, value creation, and governance and IT management within the scope of the Brazilian public sector.Main results: The data showed that 47.7% of the organizations presented incipient levels of IT governance and management. In contrast, 19% of the organizations analyzed presented satisfactory results in terms of performance and IT governance maturity. Evidence indicates that there is a positive correlation between governance quality, IT governance and management, and the finalistic performance of organizations.Theoretical contributions: Results suggest, in accordance with the RBV perspective, that a multifaceted, harmonic, and complex orchestration that ensures consistent alignment of strategic decision making, IT strategies, risk management, and IT governance and management has a direct effect on the performance of Brazilian organizations.Management contributions: Learning more about the profile of the organizations in every cluster selected for analysis could be useful for public managers in adopting measures that enhance the quality of public service provision for the benefit of all Brazilian citizens with reasonable risks and costs.


2010 ◽  
pp. 1447-1455 ◽  
Author(s):  
Aileen Cater-Steel

Many IT service departments are adopting IT service management best practice frameworks such as the IT Infrastructure Library (ITIL) to improve the quality of service to customers. This study reports on recent surveys and case studies of organizations which have embarked on IT service management improvement. It highlights specific difficulties experienced by organizations. Six factors were found to be critical in achieving an effective service-oriented philosophy. The factors are support from senior management; the threat or opportunity to outsource IT services; integration of processes to provide end-to-end service; involvement of business stakeholders; culture change of IT staff to service excellence; and the redesign of processes prior to investing in tools. Emergent IT service frameworks such as ISO/IEC 20000, and the CMMI® for Service Delivery are discussed.


2020 ◽  
Author(s):  
deni setiawan

COBIT merupakan a set of best practice (framework) bagi pengelolaan teknologi informasi (IT management) yang secara lengkap terdiri dari: executive summary, framework, control objectives, audit guidelines, implementation tool set serta management guidelines yang sangat berguna untuk proses sistem informasi strategis.COBIT berguna bagi IT users dalam memperoleh keyakinan atas kehandalan sistem aplikasi yang dipergunakan. Sedangkan para manajer memperoleh manfaat dalam keputusan saat menyusun strategic IT plan, menentukan information architecture,dan keputusan atas procurement (pengadaan/pembelian) inventaris organisasi.IT governance memastikan adanya pengukuran yang efisien dan efektif terhadap peningkatan proses bisnis perusahaan melalui struktur yang menggunakan proses-proses TI, sumberdaya TI dan informasi ke arah dan tujuan strategis perusahaan dengan menggunakan metode penilaian (scoring) sehingga suatu organisasi dapat menilai proses-proses TI yang dimilikinya dari skala non-existent sampai dengan optimised (dari 0 sampai 5).Dari studi literatur ini terlihat bahwa COBIT mempunyai spektrum proses TI yang luas dan lebih mendetail serta lebih mendalam dalam mendefinisikan proses-proses TI yang bersifat teknis dan operasional bila dibandingkan dengan COSO atau ITIL.Kata kunci : COBIT, IT Governance, IT Governance


2021 ◽  
Vol 5 (1) ◽  
pp. 138
Author(s):  
Samsinar Samsinar ◽  
Rudolf Sinaga ◽  
Renny Afriany

The implementation of IT requires good IT governance mechanisms to conduct comprehensive oversight so that the business goals of an organization can truly be achieved effectively and efficiently. All levels of IT managers must understand that risk is uncertain and harms a goal to be achieved. Risk can be a big challenge for any organization or institution that must be able to perform risk management as best it can. With well-managed risk management, it will be able to protect IT assets and add value to IT management. STIKES Garuda Putih is one of the nonprofit organizations that operate in the field of health education. To ensure excellent service for all communities and stakeholders related to IT services, it is necessary to conduct IT governance analysis activities to see if it is working properly. The analysis activity will be done using the COBIT framework 5. In this study, the capability model as a measuring tool for respondents' answers from the questionnaire is made based on the cobit framework 5. Based on the results of the process maturity level analysis on IT management (capability) is in the 3.6 to 1.4 the gap, so that concluded that IT governance has been implemented, but there is still the domain must be improved to achieve the maximum level. It is recommended that SOPs and IT performance management achievement reports, IT risk management, IT management strategy improvement, and the need for an internal control structure of IT governance be established


Sign in / Sign up

Export Citation Format

Share Document