Navy IT Service Management Office (ITSMO) Establishing an IT Governance System

Size: px
Start display at page:

Download "Navy IT Service Management Office (ITSMO) Establishing an IT Governance System"

Transcription

1 Navy IT Service Management Office (ITSMO) 20-Step Process Guide Version 1.0 Prepared by ITSMO IT Governance Team 23 September 2013

2 Establishing IT Governance IT Service Management Office (ITSMO) Version 1.0_23 September 2013 Page ii

3 Document Control This page provides details on the document file name and location and its control information. File Information File Location Document Information Version 1.0 Original Author ITSMO Governance Status Final Released by ITSMO Director Reference Date Released 23 September 2013 Revision History Revision Date Revised Revised By Group Change 0.1 8/1/2013 C. Mitchell ITSMO Initial draft 0.1 8/7/2013 P. Withers ITSMO Initial draft review 0.2 9/18/2013 P. Withers ITSMO Consolidated Reviews 1.0 9/23/2013 LCDR Glidden ITSMO Final Version Approval Establishing IT Governance IT Service Management Office (ITSMO) Version 1.0_23 September 2013 Page iii

4 Table of Contents Approval Page... Error! Bookmark not defined. Document Control... iii 1 Introduction Purpose Objectives Scope Background IT Governance Defined Governance versus Management The Need for Enterprise IT Governance Compliance Risk Management Service Execution Performance Measurement Resource Management IT Governance System IT Governance Project Roles in 20 Steps Step 1: Obtain Executive Leadership Level Sponsorship Step 2: Executive Leadership Communicates IT Governance Initiative to the Organization Step 3: Designate the IT Governance Project Manager and Implementation Team Step 4: Obtain IT Governance SME Support Step 5: Develop IT Governance Policy Step 6: Executive Signs and Promulgates IT Governance Policy Step 7: Conduct IT Governance Training Step 8: Construct IT Governance Implementation Project Plan Step 9: Establish IT Governance Repository Step 10: Develop IT Governance Strategic Communications Plan Step 11: Develop IT Governance Strategy Step 12: IT Governance Strategy Approval Step 13: Develop the IT Governance Charter Step 14: Approve and Sign IT Governance Charter Step 15: Develop Operating Guide Establishing IT Governance IT Service Management Office (ITSMO) Version 1.0_23 September 2013 Page iv

5 Exceptions Step 16: Appoint IT Governance Chair Step 17: Issue Letters of Designation Step 18: Train the IT Governance Body Members Step 19: Conduct Pilot Meeting Step 20: Initial Formal IT Governance Meeting Maintain and Improve the IT Governance System IT Governance Implementation Best Practices References Appendix A... 1 Governance Actions, Definitions, and Examples... A-1 IT Governance Body Actions...A-1 Actions Carried Out by Stakeholders...A-1 Navy ITSMO Operating Guide...A-2 IT Governance System Roles...A-2 IT Governance Model Example...A-3 Appendix B... B-1 Figures Figure 1: IT Governance System... 6 Figure 2: Flow Chart... 8 Figure 3: IT Governance Model [Example]...A-4 Tables Table 1: IT Governance Project Roles and Responsibilities... 7 Table 2: IT Governance System Roles and Responsibilities...A-3 Establishing IT Governance IT Service Management Office (ITSMO) Version 1.0_23 September 2013 Page v

6 1 Introduction 1.1 Purpose The purpose of this document is to provide guidance for Navy organizations to establish Information Technology (IT) governance systems. 1.2 Objectives The objective of this document is to provide Navy organizations with a step-by-step process for establishing and sustaining an IT Governance Systems based on the lessons learned, expertise and experience the Navy Information Technology Service Management Office (ITSMO) gained through establishing their own IT Governance System. 1.3 Scope The scope of this document encompasses any organization within the Navy IT enterprise that desires an approach and sequencing of activities for establishing or improving an effective IT Governance System and is not program specific. 1.4 Background The information contained in this document is a compendium of research conducted by the Navy ITSMO using international and industry best practice for establishing and sustaining IT Governance systems. More specifically, this includes guidance from ISACA and the IT Governance Institute (ITGI) using their highly acclaimed COBIT 5 framework, Taking Governance Forward Initiative, and the International Organization for Standardization International Electrotechnical Commission (ISO/IEC) Corporate Governance of Information Technology. To establish a baseline understanding of the IT Governance tenets set forth in these publications, it is recommended that IT governance sponsors and project leads read the ISACA publication Implementing and Continually Improving IT Governance. 1.5 IT Governance Defined In their book entitled IT Governance: how top performers manage IT decision rights for superior results (2004, Harvard Business School Press), authors Peter Weill and Jeanne Ross offer the following definition for IT Governance: IT governance: specifying the decision rights and accountability framework to encourage desirable behavior in the use of IT. Weill and Ross go on to suggest that effective IT Governance must address three questions: What decisions must be made to ensure effective management and use of IT? Who should make these decisions? How will these decisions be made and monitored? Page 1 of 27

7 Similarly, the ISO Study Group position on Governance at the itsmf USA defines IT Governance as: A decision rights and accountability framework for directing, controlling and executing IT Services and the required IT Service Management Processes to determine and achieve desired behaviors and results. The Study Group further elaborates that governance involves defining the management model and the creation of guiding (governing) IT service management principles, including: Who makes directing, controlling and executing decisions? How the decisions will be made? What information is required to make the decisions? What decision-making mechanisms should be required? How will exceptions be managed? How should governance be reviewed and improved? The similarities in the definition of IT Governance from both academia and industry focus attention on decision rights and an accountability framework; decision rights are a formal and cascading delegation of authority to commit resources and resolve conflict, and an accountability framework enables positive control for the actions and behaviors of those vested with decision rights. While the ITSMO does not offer its own definition for IT Governance, it has used this composite definition to inform the creation and sequencing of its own IT Governance model and the 20 discrete steps for establishing a viable IT Governance construct Governance versus Management While it has been said that governance and management are two sides of the same coin, there are distinct differences of focus and authority, and there is often misunderstanding in industry and within the DoD concerning these differences. In support of the purpose for this document, the two terms are defined in the COBIT 5 framework thusly: Governance Governance is derived from the Greek verb meaning to steer. A governance system refers to all the means and mechanisms that enable multiple stakeholders in an enterprise to have an organized say in evaluating conditions and options; setting direction; and monitoring compliance, performance and progress against plans, to satisfy specific enterprise objectives. Means and mechanisms include frameworks, principles, policies, sponsorship, structures and decision mechanisms, roles and responsibilities, processes and practices, to set direction and monitor compliance and performance aligned with the overall objectives. In most [commercial] enterprises, it is the responsibility of the board of directors under the leadership of the CEO and chairman Page 2 of 27

8 Management Often differentiated from governance as the distinction between being Committed (governance) and Involved (management), management entails the judicious use of means (resources, people, processes, practices et al) to achieve an identified end. It is the means or instrument by which the governance body achieves a result or objective. Management is responsible for execution within the direction set by the guiding body or unit. Management is about planning, building, organizing and controlling operational activities to align with the direction set by the governance body. Put succinctly, IT Governance ensures that enterprise objectives are achieved by: Evaluating stakeholder needs, conditions, and options Directing through prioritization and decision-making Monitoring performance, compliance and progress against agreed-to direction that uses Critical Success Factors to achieve objectives Another way to think about the difference between governance and management is to think about the primary focus of each: Management is primarily focused on the efficient use of resources to achieve strategic (governance-set) objectives. Governance, on the other hand, is primarily focused on detecting, understanding and treating (based on appetite) the risks associated with the achievement of strategic goals and objectives (see paragraph Risk Management). 1.6 The Need for Enterprise IT Governance The need for Enterprise IT governance has been growing within industry and government for the past decade. Industry realized during the 1990s that the organization chart (chain of command in the Navy), while sufficient to execute business processes, was not suitable for controlling the risk and associated impact and costs of IT. Capability and alignment of IT initiatives drive business strategic objectives. The establishment of an IT Governance structure that is subordinate to, and integrated with, the business addresses IT and business alignment issues and provides a positive accountability matrix for decisions that directly impact the strategic focus of the business. Within DoD, there has been a steady adoption of IT governance structures to better direct and control IT initiatives. The DoD s needs are similar to those of business: control suppliers, cost, and align IT initiatives to the strategic and tactical mission objectives in support of the Warfighter. IT Governance exists to solve IT problems by adjudicating and communicating decisions, allocating authority to make those decisions, and controlling IT initiatives. Operating in the Navy IT environment poses special considerations that can only be addressed with a top-down integrated IT governance model; IT governance must be established at many levels to address the issues at those levels. IT Governance enhances the command and control, and situational awareness (C2/SA) of the chain of command by setting policies and compliance measures that direct and control IT Service Management (ITSM). The publicly available data from the Massachusetts Institute of Technology (MIT) Center for Information Systems Research (CISR) suggests an almost axiomatic relationship between organizations with, and those without, formal IT Governance bodies: high-performing organizations will most often institute formal IT Governance mechanisms that enable the application and monitoring of controls that support the strategic vision and goals while Page 3 of 27

9 organizations that are not high-performing can trace one or more inhibitors to goal attainment as a lack of IT governance. This proportional relationship between governance and IT further suggests the more mature ITSM processes and services become, the more they drive business service excellence to the customer. Without IT governance bodies to direct, control and evaluate the operational IT community, provide conflict resolution, and set policy, ITSM processes become ineffective; service delivery is not measured, costs are not contained, customer satisfaction with agreed service suffers and the strategic vision is never realized Compliance The need for enterprise IT Governance is never more acutely felt than in the area of compliance. Compliance requirements are mandatory, non-negotiable controls on people, processes and technology that require continual review and may be auditable. IT Governance bodies must ensure compliance with all Federal, DoD, and DON policies and regulations (FISMA, DoDI 8500 (Series), DoDI 8510 (Series), OPNAVINST 2201, etc.) Additionally, directives and decisions from higher level governance bodies mandate that each governance body ensure compliance, including standardization. Governance bodies should clearly communicate compliance requirements and enforce compliance measures. Non-compliance should be reported to the next higher-level structure as an exception (see Exceptions in paragraph ) Risk Management Managing risk also underscores the need for enterprise IT Governance. A core responsibility of IT governance lies in addressing risk to the enterprise relative to IT initiatives. Risk exists whether or not detected and recognized and can be either positive or negative. While positive risk is normally associated with capitalizing on emergent or unforeseen opportunities in marketing and market share capture, negative risk typically includes risk to the mission (failure), operations (inefficiencies), compliance (noncompliance), strategic (achievement), service delivery (breaches), information assurance (compromise), manpower (skill attrition), and others. Risk includes anything that could impact the strategic objectives and operational readiness of the organization for which the governance body maintains direction and control. Risk surveillance, detection, evaluation and response (treatment) should be imbedded into the IT governance system. A risk register (Appendix A) should be maintained and appropriate personnel assigned by the governance body to manage IT risk issues within the organization Service Execution An important focus of IT governance is Service Execution. Service Execution is responsible for the scheduling, operation and performance of IT-based services which have been committed to the customer, applying available resources to workload demands. The enterprise must detect problems that exist in the delivery of service and then implement governance structures to address and govern those areas. Successful service execution is a result of mission alignment with customer requirements given that a service is a value proposition: a predefined value at or above the level of agreed delivery to the customer based on their expectations. The degree to which the customer perceives adequate or exceptional service delivery has a direct bearing on customer satisfaction. The need for enterprise IT Governance is therefore evident in that IT Governance structures must allocate appropriate decision rights and accountability chains as close to the Page 4 of 27

10 service point of delivery as possible to ensure the services are defined in customer terms and then successfully delivered and communicated. If services are not clearly defined in customer terms (i.e., through a service catalog with non-technical customer-centric views), customer expectations are made up of past experience, word-of-mouth and/or needs-versus-wants with little relationship between requirements and service level attainment. In those cases, the chances of true customer satisfaction are low Performance Measurement In nautical terms, the use of defined measures (bearing, course, speed, drift, draft, etc.) is necessary to determine if the ship is on course, or if a course correction is needed. Similarly, a key component of any governance framework is measurement reporting measurement determines whether IT is meeting the mission objectives through established performance levels and results. Why does enterprise IT Governance need to worry about performance measurement? Primarily because the Federal Acquisition Streamlining Act of 1994 and the Clinger-Cohen Act of 1996 prescribe performance-based and results-oriented decision-making are required for all major government investment in IT. Secondarily, because the management adage if you can measure it, you can manage it holds true for IT Governance where the actual metrics for performance measurements are determined by the stakeholders and customers of the services based on their specific requirements. Governance ensures those measurements are transparent, timely, and receive continuous management oversight for successful evaluation of ITSM value delivery. Performance measurement helps to align the enterprise to a set of common ITSM goals that produce quantitative as well as qualitative results. The measurement lexicon should be in commonly understood language and not tech-speak. Measurement reporting is the primary method by which the enterprise can control IT initiatives and set course corrections when necessary. The ITSMO has developed an Enterprise Service Quality Plan for review by anyone interested in becoming familiar with performance measurement Resource Management IT governance is concerned with the effective and efficient management of resources to achieve strategic goals and objectives another risk management vector. Areas that would be in scope in many cases include ensuring manpower availability, utilization and skillsets meet the requirements of the mission. Education and proficiency training of human resources should be addressed and progress tracked. In some organizations, IT governance is responsible for IT budgets, for software and equipment, making proposals to higher level governance bodies and tracking and reporting variance. 1.7 IT Governance System An IT Governance System is a compilation of all governance activities, people, governance bodies, policies, documentation, templates, strategy, charters, and models in a holistic framework that provides visibility and positive command and control of the enterprise. Many of the components of the system are built during creation of the strategy, operating guide development, and project execution activities. Figure 1 illustrates a typical IT governance system. Page 5 of 27

11 It is important for project team leaders to understand that establishing governance is more than creating a charter; there are multiple moving parts, initiatives and artifacts that have to be created and managed to fully achieve IT governance within an organization. Figure 1: IT Governance System 1.8 IT Governance Project Roles Creating or refining an IT Governance construct is an important undertaking for any organization and one that requires the talents of a proven IT Project Manager with experience in IT Governance to balance the competing priorities of both leadership and management. IT governance project roles are defined in Table 1 below. It is strongly suggested that organizations planning IT governance projects obtain the services of an IT Governance Subject Matter Expert (SME) to ensure all requirements are cataloged and project execution milestones are managed within the timeline established in the Plan of Action. Page 6 of 27

12 Project Role Responsibilities Executive Leadership Sponsor IT Governance Project Team Lead IT Governance SME Governance Body Membership Typically a DON 0-6, SES or Chief Information Officer. Responsible for initiating the governance project and constantly communicating support to stakeholders. The Sponsor champions and provides oversight to all project activities. The Project Team Lead is accountable to the Sponsor for the successful implementation of the IT governance project plan. The IT Governance Project Team Lead is also responsible for the following: Construction of the project plan Designating project team members Projecting team deliverables (policy, communications plan, strategy document, charter, operating guide and templates. Establishing IT governance portal and designating an administrator Provide ongoing SME support to Sponsor and IT Governance Project Team Chairman, Principal and Adjunct Members designated to serve on the governance body. Table 1: IT Governance Project Roles and Responsibilities 2 in 20 Steps The process flow chart depicted in Figure 2 and the accompanying explanation for each step in this guide are provided to acquaint governance stakeholders with the recommended incremental methodology and best practice for establishing a functional IT Governance framework and organizational construct. It is by no means prescriptive; organizations may selectively incorporate elements of the 20 steps to bolster control and oversight of an existing IT Governance process, or modify the process flow to better fit organizational requirements and align the process with existing seam and interface management. Notwithstanding, IT Governance practitioners should ensure each of the 20 steps are thoroughly reviewed and represented in the framework and process ultimately adopted to mitigate the inevitable organizational and cultural resistance to change that will occur. The 20-step process flow also represents best practice in the sequencing of activities necessary to establish an effective IT Governance construct. However, some of these activities may be executed in parallel to help expedite achievement of short-term goals and shorten the overall project timeline from a project management perspective. Each organization should thoroughly review and understand the steps to determine the best method for implementation. Page 7 of 27

13 Figure 2: Flow Chart 2.1 Step 1: Obtain Executive Leadership Level Sponsorship 1 Obtain Executive Leadership Sponsorship Obtain executive sponsorship and commitment from the highest level of authority possible. The military environment requires an SES civilian executive or (at a minimum) an O-6 military authority to properly instantiate IT Governance and drive it throughout the organization. If the sponsorship is limited to line level managers or anyone below the executive or command level, you should abandon all thoughts of having effective IT Governance mechanisms. Your sponsor not only sets the resource and outcome expectation of the governance initiative, but enforces organizational compliance to the IT Governance Implementation Project Plan. The executive sponsor must be totally committed, communicate and champion the desire for IT Governance using strategic communications during kick-off, planning, design, transition and maintenance of the IT governance initiative. Page 8 of 27

14 2.2 Step 2: Executive Leadership Communicates IT Governance Initiative to the Organization 2 Exec. Comm. ITG Initiative to Org Executive leadership sponsor must communicate initial executive level support to the entire organization and stay engaged with stakeholders throughout the initiative. Future Leadership communication is covered in Section 2.9, Develop IT Governance Strategic Communication Plan. It is vital for the executive sponsor to constantly communicate executive level support of the initiative to the organization using a communications plan. The ITSMO has developed a Strategic Communications Plan governing communications with and for its stakeholder community and that can be used as a reference and template for developing a tailored IT Governance communications plan. 2.3 Step 3: Designate the IT Governance Project Manager and Implementation Team 3 Designate ITG PM & Implementation Team The executive sponsor will direct the appropriate authorities to select an IT Governance Project Team project manager. This is the key position in the formulation of the initiative and should have the requisite project management skills and seniority within the organization. The project manager selects the project team members from the IT and business sectors of the organization. A critical duty of the Project Manager is close and continual liaison with the executive sponsor, enabling the sponsor to announce quick-wins to the organization in a timely manner. 2.4 Step 4: Obtain IT Governance SME Support 4 Obtain ITG SME Support Most organizations lack the personnel with the skills necessary to provide the guidance and consultation necessary for IT governance training and implementation. Subject Matter Experts selected by the Project Manager in conjunction with appropriate contracting constraints should have a track record in establishing governance bodies and be Certified in the Governance of Enterprise IT (CGEIT) with ISACA, have experience as COBIT trainers, and have direct traceable experience in the field of IT governance. Based on industry experience, ITSM ITIL Experts without governance training and certifications will not have the requisite experience as IT Governance professionals. 2.5 Step 5: Develop IT Governance Policy 5 Develop ITG Policy The IT governance policy establishes the scope, roles and responsibilities of the IT governance initiative and is a precursor to the charter. The policy should apply to the IT organization, all organization IT projects and IT suppliers. Page 9 of 27

15 2.6 Step 6: Executive Signs and Promulgates IT Governance Policy 6 Executive Signs and Promulgates Policy The policy must be signed and promulgated by executive leadership. The policy must be made available to all stakeholders on a publically accessible portal. Transparency is a principle of effectives IT governance, all policies should be widely distributed and posted. 2.7 Step 7: Conduct IT Governance Training 7 Conduct ITG Training Typically includes all project team members, executive leadership, and key stakeholders and conducted by the designated SME with special emphasis on the International Standard for IT Governance- ISO 38500, IT Governance Institute resources, COBIT overview, case studies, and the components of IT governance implementation. The outcomes should be a general understanding of IT governance purpose, terms, concepts, and roadmap for the project team. 2.8 Step 8: Construct IT Governance Implementation Project Plan 8 Construct ITG Project Plan Based on the IT governance training and other consultation with SME support, the project manager constructs the IT governance implementation plan and then socializes and refines the project plan with the team and SME support and ultimately communicates the plan to senior leadership. 2.9 Step 9: Establish IT Governance Repository 9 Establish ITG Repository (Portal) There must be a central repository for all artifacts and stakeholder communication. The repository should have all the relevant governance documents, policies, plans and processes. The repository should have a calendar that indicates project team meetings, risk register, and governance board planned meetings, minutes from past meetings. There should be a public section accessible by anyone in the organization to include charters, strategic communications, announcements, and other approved documents in PDF format. A key principle of IT governance is transparency, sharing the charter, plans, communications, risks and decisions with stakeholders. There should be formal access control and request procedures and an effective document management procedure with responsible owners assigned for all documents Step 10: Develop IT Governance Strategic Communications Plan 10 Develop ITG Communications Plan A strategic communication plan must be developed with a lead assigned for implementing the plan. The plan should cover strategic communication frequency, generation, approval, and defining, maintaining distribution lists. The strategic communications are the main source of communicating with stakeholders. Page 10 of 27

16 Because IT governance conducts self-assessments and strives to improve the system, the strategic communications lead will also be the single point of contact for issues, concerns, and suggestions from the stakeholder community that are relayed to the governance board membership for consideration Step 11: Develop IT Governance Strategy 11 Develop IT Strategy An IT governance strategy document should be developed with SME support to identify the organization s holistic approach to IT governance. The strategy should include: Governance RACI Governance model including future boards, committees, and councils Governance principles Risk management strategy Resource management Strategic alignment with the business or mission Critical Success Factors (CSF) and supporting Key Performance Indicators (KPI) Implementation timelines The ITSMO has developed an IT Governance Strategic Plan template for use by commands and entities as a reference and template for developing a tailored IT Governance Strategic Plan Step 12: IT Governance Strategy Approval 12 Executive Approves and Signs ITG Strategy The Executive leadership approves and signs the IT Governance Strategy. Leadership then proliferates and exercises strong support for the strategy throughout the organization and makes it available for review by stakeholders Step 13: Develop the IT Governance Charter 13 Other than the IT Governance policy, the charter is a formal organization controlled document and is the cornerstone for all IT governance body activities. Develop ITG Charter While all sections of the charter are important, the scope is the most important section because it sets the limits of the IT governance body. There should be a charter for each individual governance body. The suggested sections include: Overview Authority granted (who granted authority) Authority delegated to create subordinate governance bodies Governance body mission Governance body scope Page 11 of 27

17 Expected outcomes Governance body membership and length of appointment (by functional group or organization) Functions mapped to roles and responsibilities (RACI) Meeting frequency Voting and quorums Reporting requirements Self-assessments and improvements Guiding Principles (refer to ISO for guidance) The ITSMO has developed an IT Governance Charter template for use by commands and entities that can be used as a reference and template for developing a tailored IT Governance Charter Step 14: Approve and Sign IT Governance Charter 14 Approve & Sign ITG Charter The charter must be signed by executive leadership of the organization, normally the executive sponsor. It s a critical success factor that the charter be signed by the highest level authority possible. The charter should be posted on the IT Governance Portal and available to stakeholders in a public folder Step 15: Develop Operating Guide 15 Develop Operating Guide The operating guide is the handbook for the how the governance system operates. This could be one board or multiple governance bodies within the organization s governance system. It provides the details of the governance system decision making and governance processes. The processes should include: Strategic communication - how and when the governance body communicates Exceptions - how problems (exceptions) are escalated (see paragraph ) Stakeholder request - how the governance body responds to stakeholder requests Portal access - how stakeholders are approved and maintain access to the governance body portal Meeting arrangements - what needs to do done when planning governance meetings Decision making - how the governance board conducts meetings and makes decisions, voting and quorums Operational IT governance and self-assessments - what happens between meetings The future governance body chair will sign this document as well as all other future documents, plans, and policies after governance body approval. Page 12 of 27

18 Exceptions Exceptions are problems that need resolution decisions or other action by the governance body and flow up the IT governance model (see Appendix A for example) and decisions made by the governance bodies to those exceptions flow down the governance model in response. Exceptions may include issues such as: Resource management Conflict resolution Policy exceptions Cross-functional seam management problems Performance measurement including establishing metrics to meet service level requirements Risk and compliance Strategic and mission alignment Standardization of ITSM terms, processes, service definition, policies, roles, and skills 2.16 Step 16: Appoint IT Governance Chair 16 The senior executive sponsor formally appoints a chair of the governance body via an appointment letter. The appointment letter should be aligned with the charter Appoint ITG Chair directing the chair to assume control of the governance body. The chair begins identifying suitable membership with the functional groups as indicated in the charter. The chair is accountable to the executive sponsor for the successful operation of the governance body within the scope of the governance body charter Step 17: Issue Letters of Designation 17 Issue Letters of Designation The governance chair, using templates from the IT governance SMEs, activates Principal members to the body by letter of designation signed by the chair. The selection of Principal members is determined by the charter which will detail the organizations and functional groups with representatives on the governance body. It is the responsibility of the leadership in those organizations and groups to select members. The ITSMO has developed a Letter of Designation template that can be adapted for use by stakeholders, and is available on the ITSMO Portal Step 18: Train the IT Governance Body Members 18 Train the ITG Body Members There must be governance body training to all voting members including the governance and decision-making processes, meeting arrangements, communication, portal access, exceptions, and using the operating guide. Additionally, members should understand the governance strategy, and charter. Page 13 of 27

19 There should be separate specialized training provided by a certified and experienced IT Governance SME for both the Scribe and the Chair. Chairman training - The IT governance body Chairman has to be trained separately using the procedures in the operating guide. The Chair must understand how to conduct the meetings, and the importance of formality of meetings and consistency of the meeting schedule. IT governance body meetings need to have a battle rhythm that ensures the business of the body is carried out in an effective and efficient manner, get them in, and get them out as quickly as possible. The attendees to such meetings are important people and the meetings should have a definite start and stop time with most of the tasks such as reviewing minutes, completed before the meeting using the Meeting Prerequisites process. The Chair must understand the difference between a regular staff meeting and a governance body meeting. During the meeting, only Principal Members are allowed to discuss agenda items unless they have requested a source outside the body to present expert information. Visitors should only attend the specific section of the meeting that they are required. Adjunct Members attend the meetings but have no part in the proceedings; any input from Adjunct Members should have been communicated to a Principal Member prior to the governance body meeting. The meeting rules should be enumerated in the charter. The Chair must use a condensed form of Robert s Rules of Order. These rules, first published in 1876, were designed for use in ordinary societies rather than legislative assemblies, and are the most commonly adopted parliamentary authority among societies in the United States. The Chair should use the rules most pertinent to the conduct of official board deliberations to ensure the orderly conduct of presentations, voting, recording, and review of new and old business, et al. Scribe training - The scribe records the minutes, sends minutes out for review, posts minutes and generally controls the meeting invites and schedule. The Scribe also makes the call for agenda items and formulates, distributes the agenda and exhibits in advance of the meeting. Meeting minutes, agendas and exhibits should be posted on the IT governance body repository with links sent to principal and adjunct members. The Scribe is a key player in the pilot meeting (Step 19) Step 19: Conduct Pilot Meeting 19 SME support will conduct a mock governance board to ensure all members understand what needs to be done before a meeting, during the meeting and Conduct Pilot Meeting responsibilities of each member. This should be a formal mock meeting using a revised form of Roberts Rules and testing out the meeting arrangements process. An assessment should be conducted to revisit areas of remedial training Step 20: Initial Formal IT Governance Meeting 20 Initial Formal ITG Meeting Conduct the initial governance body meeting using the charter to keep in scope and ensure all participants follow the governance and decision-making processes in the operating guide. It s important for success that meetings are scheduled six months in advance, always on the same time of the month, use the same meeting Page 14 of 27

20 arrangements (room, dial-in, VTC, etc.), so the members keep a rhythm of meetings and activities Maintain and Improve the IT Governance System The operating guide will provide the Operational IT Governance procedures for maintaining and improving the governance system. These procedures or processes provide the decisionmaking and governance process or procedures to operate and improve the governance system and take advantage of lessons learned so that necessary refinements and improvements can be implemented. 3 IT Governance Implementation Best Practices The methodology for implementing IT governance should be based on industry best practices and knowledge based of thousands of successful implementations. The IT Governance Institute, in response to demand signals from government and the business community, has collected a world-wide repository of IT governance case studies, best practices, and survey information on how high performing organizations excel in getting their IT departments to focus on the government and business strategic objectives. Lessons learned have also been a big contribution to the repository and help develop best practices in governance. Any IT governance initiative should use the experience and best practices of established governance initiatives of other organizations. Setting up IT governance isn t as simple as executing a charter and scheduling meetings. Therefore, governance SMEs should aid in the strategy, planning, IT governance system build, and training. The SMEs will phase out as the IT governance system becomes operational but should remain on call for support. Best practices for establishing governance systems include: The IT governance system should be implemented using a project-team phased approach o A phased approach increases control and reduces risk of failure o A phased approach allows continuous improvement and transfer of knowledge from one phase to another o A big bang approach requires buy-in and commitment from the entire organization at the same time, whereas a phased approach requires commitment from a smaller number of people and is incrementally spread across the organization. Unless the organization is unusually small and therefore easily managed from a single vantage point, a big bang approach is not recommended. Involve stakeholders in the implementation, they can help with: o Compliance and risk issues o Alignment with industry best practices and standards o Dependence on suppliers for outsourced services Other considerations in planning the project: o IT Governance must be chaired by senior leadership (senior as possible) o IT Governance structures should exist at many levels o Should be top down with decision rights and accountability allocated down and proposals and exception flowing up Page 15 of 27

21 o Should sustain the organizational mission and objectives o Should be based on international standards and good practices o Each body should have its own charter and internal processes (communications, decision making, conflict resolution, etc.) o IT Governance bodies should have specific interactions with other governance bodies, communication is a critical success factor o Governance bodies should be principle based (see ISO/IEC International Standard; Corporate Governance of Information Technology) o IT Governance bodies allocate authority and decision rights to lower level bodies with each body signing and executing the charters for subordinate bodies. o Letters of designation for IT governance body members should be initiated by the Chairman of the body with the authority to make assignments as indicated in the charter. o All IT governance activities should be transparent and communicated to stakeholders Page 16 of 27

22 References 1. ISACA: 2. IT Governance Institute: 3. ISO/IEC 38500:2008: 4. COBIT 5: 5. Implementing and Continually Improving IT Governance: Center/Research/ResearchDeliverables/Pages/Implementing-and-Continually-Improving-IT- Governance1.aspx 6. ITSMO Enterprise Service Quality Plan: 7. Taking Governance Forward Mapping Initiative: Issues/2009/Volume-1/Documents/jpdf0901-in-summary.pdf 8. ITSMO Strategic Communications Plan: 9. ITSMO IT Governance Charter Template: vernance_charter_template_v1.docx 10. ITSMO IT Governance Strategic Plan Template: ITSMO Operating Guide: Page 17 of 27

23 Appendix A Governance Actions, Definitions, and Examples As an adjunct to the information already presented, the following actions, definitions and examples help to illustrate the cohesiveness of the IT Governance System through actions and interactions that are required to ensure a functioning and capable construct. The information presented in the following paragraphs is not all-inclusive; rather it is representative of the activities performed by a governance body that has been established on good practices. IT Governance Body Actions Direct: Top down policies, strategies and directives ( thou shall ). Direct includes: Process and service ownership Establishment of subordinate governance bodies through charters Detailed DON/DoD policies that map to controls Real time and historical performance data reflecting intent and output of process activities Institutionalization of a process and service improvement methodology Evaluate: Comparing the values of results versus expected results. Baselines and metrics should be established for comparative analysis of reported information. Reporting is typically in the form of balanced scorecards to governance bodies. Monitor: The methods and activities in which information about the use of systems, networks, applications and information is captured and interpreted. Control: The mechanisms of the governance bodies ensure the achievement of mission objectives through responsible use of resources, appropriate management of risk, costs and alignment of IT with the mission of the larger organization. Control includes: Process and service management Service specifications and catalogs Agreement structures, i.e., Service Level Agreements (SLA), Operational Level Agreements (OLA), Underpinning Contracts (UC) and Memoranda of Understanding (MOU) Communicating: Determining who needs to know what and when down and across the organization and applies to all levels of governance. Effective communication is a critical success factor for establishing a governance system. Actions Carried Out by Stakeholders Execute: To carry out and accomplish the assigned tasks of processes, policies, directives, and strategies. This activity ensures the Execute includes: Process and service operations Appendix A-1

24 Activity-level processes and their tasks and SOPs Task-level processes and their SOPs and work instructions Operating integrated ITSM tools Operational Control: The daily activities of operations management to ensure objectives are achieved. The planning, building, organizing, and controlling operational activities to align with the direction set by the governance body, e.g., functional groups, process or service owners, Change Advisory Boards (CAB) and Service Desk. Navy ITSMO Operating Guide Governance systems must have an operating guide that includes the procedures for operating the governance system. There should be SOPs for all facets of the governance system including decision making and governance procedures (see Section 2.15). Especially when establishing governance in an organization, there should be no ambiguity about how the governance system operates. The operating guide is the handbook for all participants and should be updated on a regular basis. The Navy ITSMO Operating Guide is a good example available to Navy stakeholders and organizations for guidance in developing their own operating guide. The key objectives of the Operating Guide include: Provide standardized methods and procedures to be used for the efficient and prompt handling of business needs Minimize variation and promote quality through consistent implementation of the procedures Promote compliance with Navy and DoD policies and directives Ensure that all relevant governance and decision-making processes are properly recorded, reviewed, assessed, and approved Minimize operational risks and duplication of efforts Ensure that all staff are trained and are capable to execute against the implemented SOPs IT Governance System Roles The following table defines the roles necessary for the governance system after the project is completed and should be detailed in the strategy, charter and operating guide. Role Responsibilities Chairman The governance body chairman is granted authority by the governance charter to conduct the daily operations and chair scheduled meetings of the governance body. The chair has overall accountability for the successful operations of the body within the scope of the charter. The chair is a voting member and the single point Appendix A-2

25 Role Responsibilities of contact for other governance bodies and external groups. Principal Member Adjunct Member Scribe Portal Administrator Stakeholders Voting members selected by stakeholder organization leadership or by other means indicated in the charter. The composition and duties of Principal Membership is enumerated in the charter. Non-voting members attending scheduled governance body meetings for situational awareness (SA). Duties of Adjunct Members are detailed in the charter. Typically Adjunct Members don t participate in governance board meeting discussions unless prompted by a Principal member. A key position necessary for governance bodies operation. Duties are in the charter and should include: Maintaining a stakeholder registry Preparing agenda Recording and distributing meeting minutes Meeting arrangements Meeting Prerequisites Maintaining communication with members and stakeholders is critical, the Portal Administrator ensures the governance body meeting schedule, minutes, and charter are available to both. Additionally, there will be a workspace provided for exhibits and artifacts necessary for conducting governance body meetings. Those contacts internal and external to the organization that are affected by governance board decisions. Stakeholder communication should be two-way; they are the major source of governance body issues to resolve. Table 2: IT Governance System Roles and Responsibilities IT Governance Model Example Any organization that establishes IT governance will have to create a governance model in their IT governance strategy indicating the lines of communication, proposals, decisions, exceptions and most important cascaded delegation of authority. In this example the Enterprise ITSMO has created subordinate boards, committees and councils all with their own charters and delegated authority. Governance bodies must also consider higher level governance bodies that have authority over their actions and handle their governance exceptions (problems requiring resolution/ decisions) and proposals. The following is a notional governance model example. Appendix A-3

26 Figure 3: IT Governance Model [Example] Appendix A-4

27 Appendix B Risk Register IT Service Management Office (ITSMO) Version 1.0_23 September 2013 Appendix B

Final. North Carolina Procurement Transformation. Governance Model March 11, 2011

Final. North Carolina Procurement Transformation. Governance Model March 11, 2011 North Carolina Procurement Transformation Governance Model March 11, 2011 Executive Summary Design Approach Process Governance Model Overview Recommended Governance Structure Recommended Governance Processes

More information

Based on 2008 Survey of 255 Non-IT CEOs/Executives

Based on 2008 Survey of 255 Non-IT CEOs/Executives Based on 2008 Survey of 255 Non-IT CEOs/Executives > 50% Ranked ITG as very important > 75% of businesses consider ITG to be an integral part of enterprise governance, but the overall maturity level is

More information

Global Technology Audit Guide. Auditing IT Governance

Global Technology Audit Guide. Auditing IT Governance Global Technology Audit Guide Auditing IT Governance Global Technology Audit Guide (GTAG ) 17 Auditing IT Governance July 2012 GTAG Table of Contents Executive Summary... 1 1. Introduction... 2 2. IT

More information

BMC Software Consulting Services. Fermilab Computing Division Service Catalog & Communications: Process and Procedures

BMC Software Consulting Services. Fermilab Computing Division Service Catalog & Communications: Process and Procedures BMC Software Consulting Services Service Catalog & Communications: Process and Procedures Policies, Client: Date : Version : Fermilab 02/12/2009 1.0 GENERAL Description Purpose This document establishes

More information

Department of Defense INSTRUCTION. Implementation and Management of the DoD-Wide Continuous Process Improvement/Lean Six Sigma (CPI/LSS) Program

Department of Defense INSTRUCTION. Implementation and Management of the DoD-Wide Continuous Process Improvement/Lean Six Sigma (CPI/LSS) Program Department of Defense INSTRUCTION NUMBER 5010.43 July 17, 2009 DCMO SUBJECT: Implementation and Management of the DoD-Wide Continuous Process Improvement/Lean Six Sigma (CPI/LSS) Program References: See

More information

Office of the Auditor General AUDIT OF IT GOVERNANCE. Tabled at Audit Committee March 12, 2015

Office of the Auditor General AUDIT OF IT GOVERNANCE. Tabled at Audit Committee March 12, 2015 Office of the Auditor General AUDIT OF IT GOVERNANCE Tabled at Audit Committee March 12, 2015 This page has intentionally been left blank Table of Contents Executive Summary... 1 Introduction... 1 Background...

More information

The Role of ITIL in IT Governance

The Role of ITIL in IT Governance The Role of ITIL in IT Governance Leveraging IT Governance around IT Service Management Presented By: Rick Leopoldi RL Information Consulting LLC Q2 2005 People Process Technology Why Focus on IT Governance

More information

Project Governance Plan Next Generation 9-1-1 Project Oregon Military Department, Office of Emergency Management, 9-1-1 Program (The OEM 9-1-1)

Project Governance Plan Next Generation 9-1-1 Project Oregon Military Department, Office of Emergency Management, 9-1-1 Program (The OEM 9-1-1) Oregon Military Department, Office of Emergency Management, 9-1-1 Program (The OEM 9-1-1) Date: October 1, 2014 Version: 3.1 DOCUMENT REVISION HISTORY Version Date Changes Updated By 0.1 02/13/014 Initial

More information

Information Technology Governance Overview and Charter

Information Technology Governance Overview and Charter Information Technology Governance Overview and Charter Prepared by: Project #: Date submitted Document version: IT Governance Charter v03.05.2012 1.0 48.0 - Page 1 of 34 Document History Version Date Author

More information

Fermilab Computing Division Service Level Management Process & Procedures Document

Fermilab Computing Division Service Level Management Process & Procedures Document BMC Software Consulting Services Fermilab Computing Division Process & Procedures Document Client: Fermilab Date : 07/07/2009 Version : 1.0 1. GENERAL Description Purpose Applicable to Supersedes This

More information

Department Of Defense (DoD) Enterprise Service Management Framework. Edition III. 22 Jan 15

Department Of Defense (DoD) Enterprise Service Management Framework. Edition III. 22 Jan 15 Department Of Defense (DoD) Enterprise Service Management Framework Edition III 22 Jan 15 DESMF Edition III is currently being reviewed by the Enterprise Service and Data Panel (ESDP) REVISION HISTORY

More information

Value to the Mission. FEA Practice Guidance. Federal Enterprise Architecture Program Management Office, OMB

Value to the Mission. FEA Practice Guidance. Federal Enterprise Architecture Program Management Office, OMB Value to the Mission FEA Practice Guidance Federal Enterprise Program Management Office, OMB November 2007 FEA Practice Guidance Table of Contents Section 1: Overview...1-1 About the FEA Practice Guidance...

More information

IT Governance Charter

IT Governance Charter Version : 1.01 Date : 16 September 2009 IT Governance Network South Africa USA UK Switzerland www.itgovernance.co.za info@itgovernance.co.za 0825588732 IT Governance Network, Copyright 2009 Page 1 1 Terms

More information

IT Governance isn t one thing, it s everything. Steve Romero PMP, CISSP, CCP

IT Governance isn t one thing, it s everything. Steve Romero PMP, CISSP, CCP IT Governance isn t one thing, it s everything. Steve Romero PMP, CISSP, CCP 1 An executive view of governance Based on 2009 Survey of 255 Non-IT CEOs/Executives 50% Ranked ITG as very important 75% of

More information

State of California Department of Transportation. Transportation System Data Business Plan

State of California Department of Transportation. Transportation System Data Business Plan DRAFT Page i State of California Department of Transportation Transportation System Data Business Plan RFO# TSI DPA-0003 September 29, 2011 DRAFT Page ii Table of Contents Executive Summary... 4 Chapter

More information

State of Minnesota IT Governance Framework

State of Minnesota IT Governance Framework State of Minnesota IT Governance Framework June 2012 Table of Contents Table of Contents... 2 Introduction... 4 IT Governance Overview... 4 Process for Developing the New Framework... 4 Management of the

More information

EXECUTIVE SUMMARY...5

EXECUTIVE SUMMARY...5 Table of Contents EXECUTIVE SUMMARY...5 CONTEXT...5 AUDIT OBJECTIVE...5 AUDIT SCOPE...5 AUDIT CONCLUSION...6 KEY OBSERVATIONS AND RECOMMENDATIONS...6 1. INTRODUCTION...9 1.1 BACKGROUND...9 1.2 OBJECTIVES...9

More information

U.S. Department of Education Federal Student Aid

U.S. Department of Education Federal Student Aid U.S. Department of Education Federal Student Aid Lifecycle Management Methodology Stage Gate Review Process Description Version 1.3 06/30/2015 Final DOCUMENT NUMBER: FSA_TOQA_PROC_STGRW.NA_001 Lifecycle

More information

TOGAF TOGAF & Major IT Frameworks, Architecting the Family

TOGAF TOGAF & Major IT Frameworks, Architecting the Family Fall 08 TOGAF TOGAF & Major IT Frameworks, Architecting the Family Date: February 2013 Prepared by: Danny Greefhorst, MSc., Director of ArchiXL TOGAF is a registered trademark of The Open Group. TOGAF

More information

ITS Project Management

ITS Project Management ITS Project Management Policy Contents I. POLICY STATEMENT II. REASON FOR POLICY III. SCOPE IV. AUDIENCE V. POLICY TEXT VI. PROCEDURES VII. RELATED INFORMATION VIII. DEFINITIONS IX. FREQUENTLY ASKED QUESTIONS

More information

Information Technology Project Oversight Framework

Information Technology Project Oversight Framework i This Page Intentionally Left Blank i Table of Contents SECTION 1: INTRODUCTION AND OVERVIEW...1 SECTION 2: PROJECT CLASSIFICATION FOR OVERSIGHT...7 SECTION 3: DEPARTMENT PROJECT MANAGEMENT REQUIREMENTS...11

More information

Project Management Office (PMO) Charter

Project Management Office (PMO) Charter Project Management Office (PMO) Charter Information & Communication Technologies 10 January 2008 Information & Communication Technologies Enterprise Application DISCLAIMER Services Project Management Office

More information

US Treasury Data Transparency Town Hall September 26, 2014

US Treasury Data Transparency Town Hall September 26, 2014 US Treasury Data Transparency Town Hall September 26, 2014 Collaboration & Transformation Financial Management Committee DATA Act Co-Leads: Herschel Chandler, Herschel.Chandler@iui.com KC McHargue, KMcHargue@e3federal.com

More information

PHASE 1: INITIATION PHASE

PHASE 1: INITIATION PHASE PHASE 1: INITIATION PHASE The Initiation Phase begins when agency management determines that a business function requires enhancement through an agency information technology (IT) project and investment

More information

Performance Management. Date: November 2012

Performance Management. Date: November 2012 Performance Management Date: November 2012 SSBA Background Document Background 3 4 Governance in Saskatchewan Education System 5 Role of School Boards 6 Performance Management Performance Management Overview

More information

Positive Train Control (PTC) Program Management Plan

Positive Train Control (PTC) Program Management Plan Positive Train Control (PTC) Program Management Plan Proposed Framework This document is considered an uncontrolled copy unless it is viewed online in the organization s Program Management Information

More information

How To Implement Itil V3

How To Implement Itil V3 2009 NMCI Conference: Implementing ITIL Session 1: ITSM Process ITSM COE Agenda Background ITSM Overview ITIL and Service Delivery Adopting ITIL to NGEN SE&I Activities 2 Background Develop Government

More information

Minnesota Health Insurance Exchange (MNHIX)

Minnesota Health Insurance Exchange (MNHIX) Minnesota Health Insurance Exchange (MNHIX) 1.2 Plan September 21st, 2012 Version: FINAL v.1.0 11/9/2012 2:58 PM Page 1 of 87 T A B L E O F C O N T E N T S 1 Introduction to the Plan... 12 2 Integration

More information

EXIN.Passguide.EX0-001.v2014-10-25.by.SAM.424q. Exam Code: EX0-001. Exam Name: ITIL Foundation (syllabus 2011) Exam

EXIN.Passguide.EX0-001.v2014-10-25.by.SAM.424q. Exam Code: EX0-001. Exam Name: ITIL Foundation (syllabus 2011) Exam EXIN.Passguide.EX0-001.v2014-10-25.by.SAM.424q Number: EX0-001 Passing Score: 800 Time Limit: 120 min File Version: 24.5 http://www.gratisexam.com/ Exam Code: EX0-001 Exam Name: ITIL Foundation (syllabus

More information

Copyright 2014 Carnegie Mellon University The Cyber Resilience Review is based on the Cyber Resilience Evaluation Method and the CERT Resilience

Copyright 2014 Carnegie Mellon University The Cyber Resilience Review is based on the Cyber Resilience Evaluation Method and the CERT Resilience Copyright 2014 Carnegie Mellon University The Cyber Resilience Review is based on the Cyber Resilience Evaluation Method and the CERT Resilience Management Model (CERT-RMM), both developed at Carnegie

More information

U.S. Department of Education Federal Student Aid

U.S. Department of Education Federal Student Aid U.S. Department of Education Federal Student Aid Lifecycle Management Methodology Version 1.3 06/30/15 Final DOCUMENT NUMBER: FSA_TOQA_PROC_STGRW.NA_001 Update History Lifecycle Management Methodology

More information

Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS. www.fic.gov.bc.ca

Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS. www.fic.gov.bc.ca Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS www.fic.gov.bc.ca INTRODUCTION The Financial Institutions Commission 1 (FICOM) holds the Board of Directors 2 (board) accountable for the stewardship

More information

Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance

More information

Department of Administration Portfolio Management System 1.3 June 30, 2010

Department of Administration Portfolio Management System 1.3 June 30, 2010 E 06/ 30/ 2010 EX AM PL 1. 3 06/ 28/ 2010 06/ 24/ 2010 06/ 23/ 2010 06/ 15/ 2010 06/ 18/ 2010 Portfolio System 1.3 June 30, 2010 Contents Section 1. Project Overview... 1 1.1 Project Description... 1 1.2

More information

Project Management Methodology

Project Management Methodology Project Management Methodology 1/6/2015 PAGE 1 OF 28 Version 2.0 Contents INTRODUCTION... 4 1. Overview... 4 PHASE 1 PROJECT INITIATION... 5 1. Governance Model... 6 2. Project Prioritization Process...

More information

TOGAF. TOGAF & Major IT Frameworks, Architecting the Family. by Danny Greefhorst, MSc., Director of ArchiXL. IT Governance and Strategy

TOGAF. TOGAF & Major IT Frameworks, Architecting the Family. by Danny Greefhorst, MSc., Director of ArchiXL. IT Governance and Strategy TOGAF TOGAF & Major IT Frameworks, Architecting the Family by Danny Greefhorst, MSc., Director of ArchiXL TOGAF is a registered trademark of The Open Group. Copyright 2013 ITpreneurs. All rights reserved.

More information

Role and Skill Descriptions. For An ITIL Implementation Project

Role and Skill Descriptions. For An ITIL Implementation Project Role and Skill Descriptions For An ITIL Implementation Project The following skill traits were identified as fairly typical of those needed to execute many of the key activities identified: Customer Relationship

More information

WHY DO I NEED A PROGRAM MANAGEMENT OFFICE (AND HOW DO I GET ONE)?

WHY DO I NEED A PROGRAM MANAGEMENT OFFICE (AND HOW DO I GET ONE)? WHY DO I NEED A PROGRAM MANAGEMENT OFFICE (AND HOW DO I GET ONE)? Due to the often complex and risky nature of projects, many organizations experience pressure for consistency in strategy, communication,

More information

IT Baseline Management Policy. Table of Contents

IT Baseline Management Policy. Table of Contents Table of Contents 1. INTRODUCTION... 1 1.1 Purpose... 2 1.2 Scope and Applicability... 2 1.3 Compliance, Enforcement, and Exceptions... 3 1.4 Authority... 3 2. ROLES, RESPONSIBILITIES, AND GOVERNANCE...

More information

Agile Master Data Management TM : Data Governance in Action. A whitepaper by First San Francisco Partners

Agile Master Data Management TM : Data Governance in Action. A whitepaper by First San Francisco Partners Agile Master Data Management TM : Data Governance in Action A whitepaper by First San Francisco Partners First San Francisco Partners Whitepaper Executive Summary What do data management, master data management,

More information

WHITE PAPER December, 2008

WHITE PAPER December, 2008 INTRODUCTION Key to most IT organization s ongoing success is the leadership team s ability to anticipate, plan for, and adapt to change. With ever changing business/mission requirements, customer/user

More information

Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire. P3M3 Project Management Self-Assessment

Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire. P3M3 Project Management Self-Assessment Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire P3M3 Project Management Self-Assessment Contents Introduction 3 User Guidance 4 P3M3 Self-Assessment Questionnaire

More information

PM Services. Transition Program Management

PM Services. Transition Program Management PM Services Transition Program Management Transition Program Management The PM Services team brings strong PM knowledge, years of program management experience, and a proven PM tool set to assure successful

More information

Architecture Maturity: The PDCA Cycle

Architecture Maturity: The PDCA Cycle Architecture Maturity: The PDCA Cycle The architecture maturity cycle is based on the well recognized Plan-Do-Check-Act cycle, a four phase cycle for implementing change. Refer to Figure 11.1-1. Repetition

More information

Preparation Guide. IT Service Management Foundation Bridge based on ISO/IEC 20000

Preparation Guide. IT Service Management Foundation Bridge based on ISO/IEC 20000 Preparation Guide IT Service Management Foundation Bridge based on ISO/IEC 20000 Edition April 2011 Copyright 2011 EXIN All rights reserved. No part of this publication may be published, reproduced, copied

More information

Approved by ALLETE Board of Directors on October 25, 2013. ALLETE, Inc. Board of Directors. Corporate Governance Guidelines

Approved by ALLETE Board of Directors on October 25, 2013. ALLETE, Inc. Board of Directors. Corporate Governance Guidelines Approved by ALLETE Board of Directors on October 25, 2013 ALLETE, Inc. Board of Directors Corporate Governance Guidelines Approved by ALLETE Board of Directors on October 25, 2013 BOARD ROLES AND RESPONSIBILITIES...

More information

WHITE PAPER APRIL 2012. Leading an Implementation Campaign to Address the Convergence of Healthcare Reform Initiatives

WHITE PAPER APRIL 2012. Leading an Implementation Campaign to Address the Convergence of Healthcare Reform Initiatives WHITE PAPER APRIL 2012 Leading an Implementation Campaign to Address the Convergence of Healthcare Reform Initiatives New healthcare reforms have created an unprecedented impact on hospital systems operations.

More information

Partnering for Project Success: Project Manager and Business Analyst Collaboration

Partnering for Project Success: Project Manager and Business Analyst Collaboration Partnering for Project Success: Project Manager and Business Analyst Collaboration By Barbara Carkenord, CBAP, Chris Cartwright, PMP, Robin Grace, CBAP, Larry Goldsmith, PMP, Elizabeth Larson, PMP, CBAP,

More information

Free ITIL v.3. Foundation. Exam Sample Paper 4. You have 1 hour to complete all 40 Questions. You must get 26 or more correct to pass

Free ITIL v.3. Foundation. Exam Sample Paper 4. You have 1 hour to complete all 40 Questions. You must get 26 or more correct to pass Free ITIL v.3. Foundation Exam Sample Paper 4 You have 1 hour to complete all 40 Questions You must get 26 or more correct to pass Compliments of Advance ITSM www.advanceitsm.com 1 A Service is not very

More information

Integrating Project Management and Service Management

Integrating Project Management and Service Management Integrating Project and Integrating Project and By Reg Lo with contributions from Michael Robinson. 1 Introduction Project has become a well recognized management discipline within IT. is also becoming

More information

Program Management Professional (PgMP) Examination Content Outline

Program Management Professional (PgMP) Examination Content Outline Program Management Professional (PgMP) Examination Content Outline Project Management Institute Program Management Professional (PgMP ) Examination Content Outline April 2011 Published by: Project Management

More information

HRO Provider Management: Success Requires a Disciplined Approach

HRO Provider Management: Success Requires a Disciplined Approach February 2007 HRO Provider Management: Success Requires a Disciplined Approach By Jeff Krynski Governance Competency Leader, CHRO Services, TPI CONTENTS 2. The Case for HRO Provider Management 2. Provider

More information

OE PROJECT CHARTER TEMPLATE

OE PROJECT CHARTER TEMPLATE PROJECT : PREPARED BY: DATE (MM/DD/YYYY): Project Name Typically the Project Manager Project Charter Last Modified Date PROJECT CHARTER VERSION HISTORY VERSION DATE (MM/DD/YYYY) COMMENTS (DRAFT, SIGNED,

More information

Program Lifecycle Methodology Version 1.7

Program Lifecycle Methodology Version 1.7 Version 1.7 March 30, 2011 REVISION HISTORY VERSION NO. DATE DESCRIPTION AUTHOR 1.0 Initial Draft Hkelley 1.2 10/22/08 Updated with feedback Hkelley 1.3 1/7/2009 Copy edited Kevans 1.4 4/22/2010 Updated

More information

P3M3 Portfolio Management Self-Assessment

P3M3 Portfolio Management Self-Assessment Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire P3M3 Portfolio Management Self-Assessment P3M3 is a registered trade mark of AXELOS Limited Contents Introduction

More information

CHARTER OF THE BOARD OF DIRECTORS

CHARTER OF THE BOARD OF DIRECTORS SUN LIFE FINANCIAL INC. CHARTER OF THE BOARD OF DIRECTORS This Charter sets out: 1. The duties and responsibilities of the Board of Directors (the Board ); 2. The position description for Directors; 3.

More information

The following is intended to outline our general product direction. It is intended for informational purposes only, and may not be incorporated into

The following is intended to outline our general product direction. It is intended for informational purposes only, and may not be incorporated into The following is intended to outline our general product direction. It is intended for informational purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any

More information

Department of Veterans Affairs VA Directive 0054. VA Enterprise Risk Management (ERM)

Department of Veterans Affairs VA Directive 0054. VA Enterprise Risk Management (ERM) Department of Veterans Affairs VA Directive 0054 Washington, DC 20420 Transmittal Sheet April 8, 2014 VA Enterprise Risk Management (ERM) 1. REASON FOR ISSUE: This directive provides guidelines to help

More information

Business Analyst Position Description

Business Analyst Position Description Analyst Position Description September 4, 2015 Analysis Position Description September 4, 2015 Page i Table of Contents General Characteristics... 1 Career Path... 2 Explanation of Proficiency Level Definitions...

More information

CSR / Sustainability Governance and Management Assessment By Coro Strandberg Principal, Strandberg Consulting www.corostrandberg.

CSR / Sustainability Governance and Management Assessment By Coro Strandberg Principal, Strandberg Consulting www.corostrandberg. Introduction CSR / Sustainability Governance and Management Assessment By Coro Strandberg Principal, Strandberg Consulting www.corostrandberg.com June 2015 Companies which adopt CSR or sustainability 1

More information

APPENDIX J INFORMATION TECHNOLOGY MANAGEMENT GOALS

APPENDIX J INFORMATION TECHNOLOGY MANAGEMENT GOALS APPENDIX J INFORMATION TECHNOLOGY MANAGEMENT GOALS Section 5123 of the Clinger-Cohen Act requires that the Department establish goals for improving the efficiency and effectiveness of agency operations

More information

COMMUNICATIONS MANAGEMENT PLAN <PROJECT NAME>

COMMUNICATIONS MANAGEMENT PLAN <PROJECT NAME> COMMUNICATIONS MANAGEMENT PLAN TEMPLATE This Project Communications Management Template is free for you to copy and use on your project and within your organization. We hope that you find this template

More information

Project Management Office Charter

Project Management Office Charter Old Dominion University Office of Computing and Communication Services Project Management Office Charter Version: 1.0 Last Update: February 18, 2010 Created By: Anthony Fox, PMP OCCS Project Management

More information

Practice makes perfect Simulation games to increase the return-on-investment of ITIL training

Practice makes perfect Simulation games to increase the return-on-investment of ITIL training Practice makes perfect Simulation games to increase the return-on-investment of ITIL training By Paul Wilkinson, GamingWorks * In an effort to improve the performance of IT service delivery many IT organizations

More information

Portfolio Management Professional (PfMP)SM. Examination Content Outline

Portfolio Management Professional (PfMP)SM. Examination Content Outline Portfolio Management Professional (PfMP)SM Examination Content Outline Project Management Institute Portfolio Management Professional (PfMP) SM Examination Content Outline Published by: Project Management

More information

ITIL by Test-king. Exam code: ITIL-F. Exam name: ITIL Foundation. Version 15.0

ITIL by Test-king. Exam code: ITIL-F. Exam name: ITIL Foundation. Version 15.0 ITIL by Test-king Number: ITIL-F Passing Score: 800 Time Limit: 120 min File Version: 15.0 Sections 1. Service Management as a practice 2. The Service Lifecycle 3. Generic concepts and definitions 4. Key

More information

The Key to a Successful KM Project

The Key to a Successful KM Project Introduction An integrated PKM methodology enables organizations to maximize their investments by ensuring initiatives are on time and within budget, while sharing project challenges and successes that

More information

Implementing a Data Governance Initiative

Implementing a Data Governance Initiative Implementing a Data Governance Initiative Presented by: Linda A. Montemayor, Technical Director AT&T Agenda AT&T Business Alliance Data Governance Framework Data Governance Solutions: o Metadata Management

More information

DEFENSE TRAVEL MANAGEMENT OFFICE. Defense Travel Management Office FY 2012 FY 2016 Strategic Plan

DEFENSE TRAVEL MANAGEMENT OFFICE. Defense Travel Management Office FY 2012 FY 2016 Strategic Plan DEFENSE TRAVEL MANAGEMENT OFFICE Defense Travel Management Office FY 2012 FY 2016 Strategic Plan December 2011 Table of Contents 1. Introduction... 1 2. DTMO Overview... 1 3. DTMO Strategy... 6 4. Measuring

More information

IT Project Governance Manual Version 1.1

IT Project Governance Manual Version 1.1 IT Project Governance Manual Version 1.1 A Mandatory Reference for ADS Chapter 577 New Reference: 04/13/2010 Responsible Office: CIO File Name: 577mak_041310 UNITED STATES AGENCY FOR IT Project Goverance

More information

CHESAPEAKE ENERGY CORPORATION CORPORATE GOVERNANCE PRINCIPLES. (Amended as of June 13, 2014)

CHESAPEAKE ENERGY CORPORATION CORPORATE GOVERNANCE PRINCIPLES. (Amended as of June 13, 2014) CHESAPEAKE ENERGY CORPORATION CORPORATE GOVERNANCE PRINCIPLES (Amended as of June 13, 2014) 1. The Role of the Board of Directors The Board of Directors is responsible for the oversight of the Corporation

More information

DEFENSE LOGISTICS AGENCY HEADQUARTERS 8725 JOHN J. KINGMAN ROAD FORT BELVOIR, VIRGINIA 22060-6221

DEFENSE LOGISTICS AGENCY HEADQUARTERS 8725 JOHN J. KINGMAN ROAD FORT BELVOIR, VIRGINIA 22060-6221 DEFENSE LOGISTICS AGENCY HEADQUARTERS 8725 JOHN J. KINGMAN ROAD FORT BELVOIR, VIRGINIA 22060-6221 June 16, 2015 MEMORANDUM FOR DLA EXECUTIVE BOARD SUBJECT: Directive-Type Memorandum (DTM) [15-012] Defense

More information

HKITPC Competency Definition

HKITPC Competency Definition HKITPC Competency Definition for the Certification copyright 2011 HKITPC HKITPC Competency Definition Document Number: HKCS-CD-L1L2 Version: 1.0 Date: June 2011 Prepared by Hong Kong IT Professional Certification

More information

ITIL Roles Descriptions

ITIL Roles Descriptions ITIL Roles s Role Process Liaison Incident Analyst Operations Assurance Analyst Infrastructure Solution Architect Problem Manager Problem Owner Change Manager Change Owner CAB Member Release Analyst Test

More information

U.S. Department of Education. Office of the Chief Information Officer

U.S. Department of Education. Office of the Chief Information Officer U.S. Department of Education Office of the Chief Information Officer Investment Review Board (IRB) CHARTER January 23, 2013 I. ESTABLISHMENT The Investment Review Board (IRB) is the highest level IT investment

More information

STRATEGIC INTELLIGENCE WITH BI COMPETENCY CENTER. Student Rodica Maria BOGZA, Ph.D. The Bucharest Academy of Economic Studies

STRATEGIC INTELLIGENCE WITH BI COMPETENCY CENTER. Student Rodica Maria BOGZA, Ph.D. The Bucharest Academy of Economic Studies STRATEGIC INTELLIGENCE WITH BI COMPETENCY CENTER Student Rodica Maria BOGZA, Ph.D. The Bucharest Academy of Economic Studies ABSTRACT The paper is about the strategic impact of BI, the necessity for BI

More information

ILO. Information Technology Governance Committee (ITGC) Charter

ILO. Information Technology Governance Committee (ITGC) Charter ILO Information Technology Governance Committee (ITGC) Charter TABLE OF CONTENTS Charter... 1 Purpose... 1 Authority... 1 Membership... 1 Responsibilities... 2 Responsibilities of the ITG Committee...

More information

Operations. Group Standard. Business Operations process forms the core of all our business activities

Operations. Group Standard. Business Operations process forms the core of all our business activities Standard Operations Business Operations process forms the core of all our business activities SMS-GS-O1 Operations December 2014 v1.1 Serco Public Document Details Document Details erence SMS GS-O1: Operations

More information

Army Regulation 702 11. Product Assurance. Army Quality Program. Headquarters Department of the Army Washington, DC 25 February 2014 UNCLASSIFIED

Army Regulation 702 11. Product Assurance. Army Quality Program. Headquarters Department of the Army Washington, DC 25 February 2014 UNCLASSIFIED Army Regulation 702 11 Product Assurance Army Quality Program Headquarters Department of the Army Washington, DC 25 February 2014 UNCLASSIFIED SUMMARY of CHANGE AR 702 11 Army Quality Program This major

More information

http://www.io4pm.org IO4PM - International Organization for Project Management

http://www.io4pm.org IO4PM - International Organization for Project Management THE ONLY BOOK CAN SIMPLY LEARN PROJECT MANAGEMENT! Page 1 Contents ABOUT THE AUTHOR... 3 WHAT IS PROJECT MANAGEMENT?... 5 ORGANIZATIONAL INFLUENCES AND PROJECT LIFECYCLE... 11 PROJECT MANAGEMENT PROCESSES...

More information

Beyond Mandates: Getting to Sustainable IT Governance Best Practices. Steve Romero PMP, CISSP, CPM IT Governance Evangelist

Beyond Mandates: Getting to Sustainable IT Governance Best Practices. Steve Romero PMP, CISSP, CPM IT Governance Evangelist Beyond Mandates: Getting to Sustainable IT Governance Best Practices Steve Romero PMP, CISSP, CPM IT Governance Evangelist Agenda > IT Governance Definition > IT Governance Principles > IT Governance Decisions

More information

Documents and Policies Pertaining to Corporate Governance

Documents and Policies Pertaining to Corporate Governance Documents and Policies Pertaining to Corporate Governance 3.1 Charter of the Board of Directors IMPORTANT NOTE Chapter 1, Dream, Mission, Vision and Values of the CGI Group Inc. Fundamental Texts constitutes

More information

ICT Project Management

ICT Project Management THE UNITED REPUBLIC OF TANZANIA PRESIDENT S OFFICE PUBLIC SERVICE MANAGEMENT ICT Project Management A Step-by-step Guidebook for Managing ICT Projects and Risks Version 1.0 Date Release 04 Jan 2010 Contact

More information

ITSM Process Description

ITSM Process Description ITSM Process Description Office of Information Technology Incident Management 1 Table of Contents Table of Contents 1. Introduction 2. Incident Management Goals, Objectives, CSFs and KPIs 3. Incident Management

More information

CORPORATE GOVERNANCE GUIDELINES

CORPORATE GOVERNANCE GUIDELINES CORPORATE GOVERNANCE GUIDELINES The term "Corporation" refers to Pembina Pipeline Corporation, the term "Pembina" refers collectively to the Corporation and all entities controlled by the Corporation,

More information

Cerner Corporation Corporate Governance Guidelines

Cerner Corporation Corporate Governance Guidelines Cerner Corporation Corporate Governance Guidelines The following Corporate Governance Guidelines (the Guidelines ) have been adopted by the Board of Directors (the Board ), and together with charters of

More information

University of Michigan Medical School Data Governance Council Charter

University of Michigan Medical School Data Governance Council Charter University of Michigan Medical School Data Governance Council Charter 1 Table of Contents 1.0 SIGNATURE PAGE 2.0 REVISION HISTORY 3.0 PURPOSE OF DOCUMENT 4.0 DATA GOVERNANCE PROGRAM FOUNDATIONAL ELEMENTS

More information

An Implementation Roadmap

An Implementation Roadmap An Implementation Roadmap The 2nd Abu Dhabi IT s Forum P J Corum, CSQA, CSTE, ITSM Managing Director Quality Assurance Institute Middle East and Africa Dubai, UAE Quality Assurance Institute Middle East

More information

PHASE 3: PLANNING PHASE

PHASE 3: PLANNING PHASE PHASE 3: PLANNING PHASE The Planning Phase focuses principally on required project planning work. Proper comprehensive project planning is essential to a successful IT project, and incomplete project planning

More information

COMPLIANCE CHARTER 1

COMPLIANCE CHARTER 1 COMPLIANCE CHARTER 1 Contents 1. Compliance Policy Statement... 2 2. Purpose... 2 3. Mission and objective of the Directorate: Compliance... 2 3.1 Mission... 2 3.2 Objective... 3 4. Compliance risk management...

More information

PROJECT MANAGEMENT PLAN Outline VERSION 0.0 STATUS: OUTLINE DATE:

PROJECT MANAGEMENT PLAN Outline VERSION 0.0 STATUS: OUTLINE DATE: PROJECT MANAGEMENT PLAN Outline VERSION 0.0 STATUS: OUTLINE DATE: Project Name Project Management Plan Document Information Document Title Version Author Owner Project Management Plan Amendment History

More information

U.S. Department of Homeland Security

U.S. Department of Homeland Security U.S. Department of Homeland Security Information Technology Infrastructure Services Governance Board Digital Government Strategy Senior Advisory Council Charter Version: 1.1 Date: November 29, 2012 Digital

More information

The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012

The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012 The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only Agenda Introduction Basic program components Recent trends in higher education risk management Why

More information

ATTACHMENT 3 SPS PROJECT SENIOR PROGRAM MANAGER (SPM) DUTIES & RESPONSIBILITIES

ATTACHMENT 3 SPS PROJECT SENIOR PROGRAM MANAGER (SPM) DUTIES & RESPONSIBILITIES 1. ROLE DEFINITIONS ATTACHMENT 3 SPS PROJECT SENIOR PROGRAM MANAGER (SPM) DUTIES & RESPONSIBILITIES The purpose of this section is to distinguish among the roles interacting with the SPM obtained through

More information

Enabling IT Performance & Value with Effective IT Governance Assessment & Improvement Practices. April 10, 2013

Enabling IT Performance & Value with Effective IT Governance Assessment & Improvement Practices. April 10, 2013 Enabling IT Performance & Value with Effective IT Governance Assessment & Improvement Practices April 10, 2013 Today's Agenda: Key Topics Defining IT Governance IT Governance Elements & Responsibilities

More information

Internal Auditing Guidelines

Internal Auditing Guidelines Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may

More information

PHASE 8: IMPLEMENTATION PHASE

PHASE 8: IMPLEMENTATION PHASE PHASE 8: IMPLEMENTATION PHASE The Implementation Phase has one key activity: deploying the new system in its target environment. Supporting actions include training end-users and preparing to turn the

More information

Develop Project Charter. Develop Project Management Plan

Develop Project Charter. Develop Project Management Plan Develop Charter Develop Charter is the process of developing documentation that formally authorizes a project or a phase. The documentation includes initial requirements that satisfy stakeholder needs

More information

Central Project Office: Charter

Central Project Office: Charter Central Project Office: Charter ITCS: Central Project Office EAST CAROLINA UNIVERSITY 209 COTANCHE STREET, GREENVILLE, NC 27858 1 Table of Contents INTRODUCTION... 3 PURPOSE... 3 EXPECTED BENEFITS... 3

More information