COBIT5 Assessment Questionnaire. BAI07 Manage Change Acceptance & Testing

Size: px
Start display at page:

Download "COBIT5 Assessment Questionnaire. BAI07 Manage Change Acceptance & Testing"

Transcription

1 BAI07 Manage Change Acceptance & Testing

2 Document History Drafted Reviewed Approved V. Modification Date Who Date Who Date Who 1.00 Initial Document Information Author: Manager: Document Name: Title: Subject: Category: Comment: Daniel Frutschi Martin Andenmatten GLF_COBIT5_eng_T11_Questionnaire_BAI07_r2_v2.0.doc Questionnaire for the COBIT5 process assessment. 2

3 Summary 1. Individual Data Base Practices Work Products Maturity Level 1 Assessment Maturity Level 2 Assessment Work Products for Level Maturity Level 2 Assessment Work Products for Level Maturity Level 4 Assessment Work Products for Level Maturity Level 5 Assessment Work Products for Level

4 1. Individual Data Name Current Position Seniority in the Organization and History of Positions Daily Tasks Description % of Time Spent on This Location Specific Skills Degree of Involvement During Interview Comments 4

5 2. ID BAI07 Name Description Purpose Statement Management Practice Manage Change Acceptance & Testing Formally accept and make operational new solutions, including implementation planning, system and data conversion, acceptance testing, communication, release preparation, promotion to production of new or changed business processes and IT services, early production support, and a post-implementation review. Implement solutions safely and in line with the agreed-on expectations and outcomes. BAI07.01 Establish an implementation plan. Establish an implementation plan that covers system and data conversion, acceptance testing criteria, communication, training, release preparation, promotion to production, early production support, a fallback/backout plan, and a post-implementation review. Obtain approval from relevant parties. BAI07.02 Plan business process, system and data conversion. Prepare for business process, IT service data and infrastructure migration as part of the enterprise s development methods, including audit trails and a recovery plan should the migration fail. BAI07.03 Plan acceptance tests. Establish a test plan based on enterprisewide standards that define roles, responsibilities, and entry and exit criteria. Ensure that the plan is approved by relevant parties. BAI07.04 Establish a test environment. Define and establish a secure test environment representative of the planned business process and IT operations environment, performance and capacity, security, internal controls, operational practices, data quality and privacy requirements, and workloads. BAI07.05 Perform acceptance tests. Test changes independently in accordance with the defined test plan prior to migration to the live operational environment. BAI07.06 Promote to production and manage releases. Promote the accepted solution to the business and operations. Where appropriate, run the solution as a pilot implementation or in parallel with the old solution for a defined period and compare behaviour and results. If significant problems occur, revert back to the original environment based on the fallback/backout plan. Manage releases of solution components. 5

6 BAI07.07 Provide early production support. Provide early support to the users and IT operations for an agreed-on period of time to deal with issues and help stabilise the new solution. BAI07.08 Perform a post-implementation review. Conduct a post-implementation review to confirm outcome and results, identify lessons learned, and develop an action plan. Evaluate and check the actual performance and outcomes of the new or changed service against the predicted performance and outcomes (i.e., the service expected by the user or customer). 6

7 2.1. Base Practices BAI07.BP1 N/P/L/F/N.A. BAI07.01 Establish an implementation plan Establish an implementation plan that covers system and data conversion, acceptance testing criteria, communication, training, release preparation, promotion to production, early production support, a fallback/backout plan, and a post-implementation review. Obtain approval from relevant parties. Are the following activities planned, done, checked and improved? 1. Create an implementation plan that reflects the broad implementation strategy, the sequence of implementation steps, resource requirements, inter-dependencies, criteria for management acceptance of the production implementation, installation verification requirements, transition strategy for production support, and update of BCPs. 2. Confirm that all implementation plans are approved by technical and business stakeholders and reviewed by internal audit, as appropriate. 3. Obtain commitment from external solution providers to their involvement in each step of the implementation. 4. Identify and document the fallback and recovery process. 5. Formally review the technical and business risk associated with implementation and ensure that the key risk is considered and addressed in the planning process. 7

8 BAI07.BP2 BAI07.02 Plan business process, system and data conversion. Prepare for business process, IT service data and infrastructure migration as part of the enterprise s development methods, including audit trails and a recovery plan should the migration fail. Are the following activities planned, done, checked and improved? N/P/L/F/N.A. 1. Define a business process, IT: service data and infrastructure migration plan. Consider, for example, hardware, networks, operating systems, software, transaction data, master files, backups and archives, interfaces with other systems (both internal and external), possible compliance requirements, business procedures, and system documentation, in the development of the plan. 2. Consider all necessary adjustments to procedures, including revised roles and responsibilities and control procedures, in the business process conversion plan. 3. Incorporate in the data conversion plan methods for collecting, converting and verifying data to be converted, and identifying and resolving any errors found during conversion. Include comparing the original and converted data for completeness and integrity. 4. Confirm that the data conversion plan does not require changes in data values unless absolutely necessary for business reasons. Document changes made to data values, and secure approval from the business process data owner. 5. Rehearse and test the conversion before attempting a live conversion. 6. Consider the risk of conversion problems, business continuity planning, and fallback procedures in the business process, data and infrastructure migration plan where there are risk management, business needs or regulatory/compliance requirements. 7. Co-ordinate and verify the timing and completeness of the conversion cutover so there is a smooth, continuous transition with no loss of transaction data. Where necessary, in the absence of any other alternative, freeze live operations. 8. Plan to back up all systems and data taken at the point prior to conversion. Maintain audit trails to enable the conversion to be retraced and ensure that there is a recovery plan covering rollback of migration and fallback to previous processing should the migration fail. 9. Plan retention of backup and archived data to conform to business needs and regulatory or compliance requirements. 8

9 BAI07.BP3 BAI07.03 Plan acceptance tests. Establish a test plan based on enterprisewide standards that define roles, responsibilities, and entry and exit criteria. Ensure that the plan is approved by relevant parties. Are the following activities planned, done, checked and improved? N/P/L/F/N.A. 1. Develop and document the test plan, which aligns to the programme and project quality plan and relevant organisational standards. Communicate and consult with appropriate business process owners and IT stakeholders. 2. Ensure that the test plan reflects an assessment of risk from the project and that all functional and technical requirements are tested. Based on assessment of the risk of system failure and faults on implementation, the plan should include requirements for performance, stress, usability, pilot and security testing. 3. Ensure that the test plan addresses the potential need for internal or external accreditation of outcomes of the test process (e.g., financial regulatory requirements). 4. Ensure that the test plan identifies necessary resources to execute testing and evaluate the results. Examples of resources include construction of test environments and use of staff time for the test group, including potential temporary replacement of test staff in the production or development environments. Ensure that stakeholders are consulted on the resource implications of the test plan. 5. Ensure that the test plan identifies testing phases appropriate to the operational requirements and environment. Examples of such testing phases include unit test, system test, integration test, user acceptance test, performance test, stress test, data conversion test, security test, operational readiness test, and backup and recovery tests. 6. Confirm that the test plan considers test preparation (including site preparation), training requirements, installation or an update of a defined test environment, planning/performing/documenting/retaining test cases, error and problem handling, correction and escalation, and formal approval. 7. Ensure that the test plan establishes clear criteria for measuring the success of undertaking each testing phase. Consult the business process owners and IT stakeholders in defining the success criteria. Determine that the plan establishes remediation procedures when the success criteria are not met (e.g., in a case of significant failures in a testing phase, the plan provides guidance on whether to proceed to the next phase, stop testing or postpone implementation). 8. Confirm that all test plans are approved by stakeholders, including business process owners and IT, as appropriate. Examples of such stakeholders are application development managers, project managers and business process end users. 9

10 BAI07.BP4 BAI07.04 Establish a test environment. Define and establish a secure test environment representative of the planned business process and IT operations environment, performance and capacity, security, internal controls, operational practices, data quality and privacy requirements, and workloads. Are the following activities planned, done, checked and improved? N/P/L/F/N.A. 1. Create a database of test data that are representative of the production environment. Sanitise data used in the test environment from the production environment according to business needs and organisational standards (e.g., consider whether compliance or regulatory requirements oblige the use of sanitised data). 2. Protect sensitive test data and results against disclosure, including access, retention, storage and destruction. Consider the effect of interaction of organisational systems with those of third parties. 3. Put in place a process to enable proper retention or disposal of test results, media and other associated documentation to enable adequate review and subsequent analysis as required by the test plan. Consider the effect of regulatory or compliance requirements. 4. Ensure that the test environment is representative of the future business and operational landscape, including business process procedures and roles, likely workload stress, operating systems, necessary application software, database management systems, and network and computing infrastructure found in the production environment. 5. Ensure that the test environment is secure and incapable of interacting with production systems. 10

11 BAI07.BP5 BAI07.05 Perform acceptance tests. Test changes independently in accordance with the defined test plan prior to migration to the live operational environment. Are the following activities planned, done, checked and improved? N/P/L/F/N.A. 1. Review the categorised log of errors found in the testing process by the development team, verifying that all errors have been remediated or formally accepted. 2. Evaluate the final acceptance against the success criteria and interpret the final acceptance testing results. Present them in a form that is understandable to business process owners and IT so an informed review and evaluation can take place. 3. Approve the acceptance with formal sign-off by the business process owners, third parties (as appropriate) and IT stakeholders prior to promotion to production. 4. Ensure that testing of changes is undertaken in accordance with the testing plan. Ensure that the testing is designed and conducted by a test group independent from the development team. Consider the extent to which business process owners and end users are involved in the test group. Ensure that testing is conducted only within the test environment. 5. Ensure that the tests and anticipated outcomes are in accordance with the defined success criteria set out in the testing plan. 6. Consider using clearly defined test instructions (scripts) to implement the tests. Ensure that the independent test group assesses and approves each test script to confirm that it adequately addresses test success criteria set out in the test plan. Consider using scripts to verify the extent to which the system meets security requirements. 7. Consider the appropriate balance between automated scripted tests and interactive user testing. 8. Undertake tests of security in accordance with the test plan. Measure the extent of security weaknesses or loopholes. Consider the effect of security incidents since construction of the test plan. Consider the effect on access and boundary controls. 9. Undertake tests of system and application performance in accordance with the test plan. Consider a range of performance metrics (e.g., end-user response times and database management system update performance). 10. When undertaking testing, ensure that the fallback and rollback elements of the test plan have been addressed. 11. Identify, log and classify (e.g., minor, significant, mission-critical) errors during testing. Ensure that an audit trail of test results is available. Communicate results of testing to stakeholders in accordance with the test plan to facilitate bug fixing and further quality enhancement. 11

12 BAI07.BP6 BAI07.06 Promote to production and manage releases. Promote the accepted solution to the business and operations. Where appropriate, run the solution as a pilot implementation or in parallel with the old solution for a defined period and compare behaviour and results. If significant problems occur, revert back to the original environment based on the fallback/backout plan. Manage releases of solution components. Are the following activities planned, done, checked and improved? N/P/L/F/N.A. 1. Prepare for transfer of business procedures and supporting services, applications and infrastructure from testing to the production environment in accordance with organisational change management standards. 2. Determine the extent of pilot implementation or parallel processing of the old and new systems in line with the implementation plan. 3. Promptly update relevant business process and system documentation, configuration information and contingency plan documents, as appropriate. 4. Ensure that all media libraries are updated promptly with the version of the solution component being transferred from testing to the production environment. Archive the existing version and its supporting documentation. Ensure that promotion to production of systems, application software and infrastructure is under configuration control. 5. Where distribution of solution components is conducted electronically, control automated distribution to ensure that users are notified and distribution occurs only to authorised and correctly identified destinations. Include in the release process backout procedures to enable the distribution of changes to be reviewed in the event of a malfunction or error. 6. Where distribution takes physical form, keep a formal log of what items have been distributed, to whom, where they have been implemented, and when each has been updated. 12

13 BAI07.BP7 BAI07.07 Provide early production support. Provide early support to the users and IT operations for an agreed-on period of time to deal with issues and help stabilise the new solution. Are the following activities planned, done, checked and improved? N/P/L/F/N.A. 1. Provide additional resources, as required, to end users and support personnel until the release has stabilised. 2. Provide additional IT systems resources, as required, until the release is in a stable operational environment. 13

14 BAI07.BP8 BAI07.08 Perform a post-implementation review. Conduct a post-implementation review to confirm outcome and results, identify lessons learned, and develop an action plan. Evaluate and check the actual performance and outcomes of the new or changed service against the predicted performance and outcomes (i.e., the service expected by the user or customer). Are the following activities planned, done, checked and improved? N/P/L/F/N.A. 1. Establish procedures to ensure that post-implementation reviews identify, assess and report on the extent to which: Enterprise requirements have been met. Expected benefits have been realised. The system is considered usable. Internal and external stakeholder expectations are met. Unexpected impacts on the enterprise have occurred. Key risk is mitigated. The change management, installation and accreditation processes were performed effectively and efficiently. 2. Consult business process owners and IT technical management in the choice of metrics for measurement of success and achievement of requirements and benefits. 3. Conduct the post-implementation review in accordance with the organisational change management process. Engage business process owners and third parties, as appropriate. 4. Consider requirements for post-implementation review arising from outside business and IT (e.g., internal audit, ERM, compliance). 5. Agree on and implement an action plan to address issues identified in the post-implementation review. Engage business process owners and IT technical management in the development of the action plan. 14

15 2.2. Work Products Input Work Products ID Name Used (X) BAI07.01 Establish an implementation plan Name in the Organization Location BAI01.09 Quality management plan BAI06.01 Change plan and schedule Approved requests for change BAI07.02 Plan business process, system and data conversion. BAI07.03 Plan acceptance tests. BAI01.09 Requirements for independent verification of deliverables BAI03.07 Test procedures Test plan BAI03.08 Test result communications Test result logs and audit trails BAI07.04 Establish a test environment. BAI07.05 Perform acceptance tests. BAI07.06 Promote to production and manage releases. BAI07.07 Provide early production support. APO11.03 Review results of quality of service, including customer feedback BAI05.05 Success measures and results BAI07.08 Perform a post-implementation review. APO11.04 Results of quality reviews and audits APO11.05 Root causes of quality delivery failures Results of solution and service delivery quality monitoring BAI05.05 Success measures and results 15

16 Output Work Products ID Name Used (X) BAI07.01 Establish an implementation plan Internal Approved implementation plan Internal Implementation fallback and recovery process BAI07.02 Plan business process, system and data conversion. DSS06.02 Migration plan BAI07.03 Plan acceptance tests. BAI01.04 Approved acceptance BAI01.08 test plan BAI07.04 Establish a test environment. Internal Test data BAI07.05 Perform acceptance tests. Internal Test results log BAI01.06 Evaluation of acceptance results BAI01.04 Approved acceptance and release for production BAI07.06 Promote to production and manage releases. BAI10.01 Internal Release plan Release log BAI07.07 Provide early production support. APO08.04 Supplemental support plan APO08.05 DSS02.04 BAI07.08 Perform a post-implementation review. BAI01.13 BAI01.14 BAI01.13 BAI01.14 Post-implementation review report Remedial action plan Name in the Organization Location 16

17 2.3. Maturity Level 1 Assessment Level 1 Performed PA 1.1 Performance Attribute GP 111 Achieve the Expected Results The implemented process achieves its Purpose. The Performance attribute is a measure of the extent to which the Purpose is achieved. As a result of full achievement of this attribute, the process achieves its defined Expected Results. Did this process reach its objectives, its Expected Results, and show some tangible evidence of process activities (e.g. information or document)? What could be improved? 17

18 2.4. Maturity Level 2 Assessment Level 2 Managed PA 2.1 Performance Management Attribute GP 211 Identify the Objectives for the Performance of the The Performed is now implemented in a managed fashion (planned, monitored, and adjusted) and its Work Products are appropriately established, controlled, and maintained. The Performance Management attribute is a measure of the extent to which the performance of the process is managed. Are the objectives of the process defined? Are there deadlines, constraints, or target values to reach? Who defines those objectives? Is there a plan of actions to execute the process? What type of plan is it? Is there any monitoring of process activities against that plan? Are activities appropriately and regularly monitored? Is the time to perform the process estimated and tracked? GP 212 Plan and Monitor the Performance of the to Fulfill the Identified Objectives 18

19 Is someone tracking the process activities? Does someone notice and react if they are not performed? Are there corrective actions when process results don t meet objectives? (More resources, new planning)? GP 213 Adjust the Performance of the What are the roles and responsibilities that have been identified for this process? Are they clearly defined (even not formally at this stage)? Are they communicated to everyone? Who is responsible for that? GP 214 Define Responsibilities and Authorities for Performing the Do you think that existing HR are well trained and efficient? Are they numerous enough and available? Are other resources available when needed (monitoring, tracking, and reporting tools)? GP 215 Identify and Make Available Resources to Perform the according to Plan 19

20 Who are involved parties in the process? Who uses the outputs from this process (reporting, documents or information)? What type of communication is there between the different stakeholders? How is the coordination between the organizational functions involved in the process managed? GP 216 Manage the Interfaces Between Involved Parties PA 2.2 Work Product Management Attribute GP 221 Define the Requirements for the Work Products The Work Product Management attribute is a measure of the extent to which the Work Products produced by the process are appropriately managed. What are the documents/information used or resulting from the process? Do you have defined requirements and quality criteria for these documents (and information)? Do you know what they should contain? Are the input and output of the process based on templates (at your level)? Do you have specific rules to manage the process inputs and outputs? Are there rules for versioning? Document naming? Are there access rules for documents, information, databases? GP 222 Define the Requirements for Documentation and Control of the Work Products 20

21 Are these rules applied in the field? Overall, do you have trouble handling documents? Does it happen that people do not have access to the information when they should? that you cannot find the latest version of a document? GP 223 Identify, Document, and Control the Work Products Are there reviews of the documents and other outputs produced by the process? Do you compare the actual documents to their requirements and quality criteria? Is there a frequency for reviewing the documents and other outputs produced by the process? If any problem is detected, are corrective actions taken? How? GP 224 Review and Adjust Work Products to Meet the Defined Requirements 21

22 2.5. Work Products for Level 2 ID Name Used (X) PA 2.1 Performance Management Attribute 3-00 Plan 5-00 Record 6-00 Report PA 2.2 Work Product Management Attribute 1-00 Object 3-00 Plan 5-00 Record 8-00 Specification Work Products Name in the Organization Location 22

23 2.6. Maturity Level 2 Assessment Level 3 Established PA 3.1 Definition Attribute The Managed is now implemented using a standard process definition capable of achieving its process Expected Results. The Definition attribute is a measure of the extent to which a standard process is defined and maintained to support the deployment of the. Is this process described formally? Are all the process activities described in a reference guide, a Quality or Service Management System (SMS or QMS), or in procedures? Do you have templates supporting the process? GP 311 Define the Standard that will support the Deployment of the GP 312 Determine the Sequence and Interaction between es so that they work as an Integrated System of es Are the connections between the process activities and other processes clearly identified and defined? Where? Do you have a diagram describing the relationships? 23

24 Is there a clear description of required competencies for those activities? Are the various roles defined in job descriptions, competence profiles? GP 313 Identify the Roles and Competencies for Performing the Standard Is the required work environment appropriately identified and described? Are the tools required for supporting the process performance specified? GP 314 Identify the Required Infrastructure and Work Environment for Performing the Standard GP 315 Determine Suitable Methods to Monitor the Effectiveness and Suitability of the Standard Is a mechanism defined to monitor the efficiency and suitability of the process across the organization? Have you identified the need for internal audits or management reviews? Are these internal audits or management reviews planned? Do you have defined the way to identify the weaknesses (and strengths) of your process? And how to benefit from them? 24

25 [ITIL 2011: Service Reporting] Have you identified the different audiences for the service management reports? Have you defined the layout, contents, and frequency of Service Management reports (according to the audience)? Was it agreed with the business? GP 316 Define and Agree upon the Content of Service Management Reports PA 3.2 Deployment Attribute GP 321 Deploy a Standard that satisfies the context-specific Requirements from the Standard Definition The Deployment attribute is a measure of the extent to which the standard process is effectively deployed to achieve its process Expected Results. Does the process implemented correspond to the one that is described formally? How do you organize the deployment of the process across the organization? 25

26 Are all the defined roles for this process assigned to someone? Are all the responsibilities identified and communicated? With appropriate authority lead? GP 322 Assign and Communicate Roles, Responsibilities, and Authorities for Performing the Standard GP 323 Ensure necessary Competencies for Performing the Standard Do you think that people working on this process have the right level of knowledge or training? How do you ensure that the competence level is adequate? Do you look at particular skills when hiring people? Is there a training plan for the actors of this process? Are there training sessions organized to improve the competence level? 26

27 Are resources and required information available to implement the process? Do you have enough financial and human resources? Do you miss any other resource? GP 324 Provide Resources and Information to Support the Performance of the Standard GP 325 Provide Adequate Infrastructure to Support the Performance of the Standard Does the work environment correspond to what has been defined formally for implementing this process? Do you have enough technical (HW, SW) resources? Do you have the appropriate tools? GP 326 Collect and Analyze Data about the Performance of the to Demonstrate its Suitability and Effectiveness Do you collect information on the performed activities? Do you collect and analyze data on the process implementation? What for? (to ensure that the process activities meet the requirements defined in the standard guide, or to check that it is suitable and effective) How do you analyze this data? Can it help determine process efficiency? 27

28 Do you produce Service Management reports according to service reporting policies and rules? What is the frequency? Do you communicate Service Management reports to interested parties? How? [ITIL 2011: Service Reporting] GP 327 Produce and Publish Service Management Reports 28

29 2.7. Work Products for Level 3 ID Name Used (X) PA 3.1 Definition Attribute 2-00 Description 3-00 Plan 4-00 Procedure 5-00 Record 8-00 Specification PA 3.2 Deployment Attribute 2-00 Description 3-00 Plan 5-00 Record 6-00 Report 8-00 Specification Work Products Name in the Organization Location 29

30 2.8. Maturity Level 4 Assessment Level 4 Predictable PA 4.1 Measurement Attribute The Established now operates within defined limits to achieve its process Expected Results. The Measurement attribute is a measure of the extent to which measurement results are used to ensure that the performance of the process supports the achievement of the relevant process performance objectives in support of defined business goals. Are business goals known? What process information is necessary to determine whether business goals are met? GP 411 Identify Information Needs, in Relation with Business Goals What needs to be measured in this process? Are the reports produced compatible with process objectives and business goals? GP 412 Derive Measurement Objectives from Information Needs 30

31 GP 413 Establish Quantitative Objectives for the Performance of the Standard, according to the Alignment of the with the Business Goals Can you give examples of process quantitative objectives that you follow? GP 414 Identify Product and Measures that support the Achievement of the Quantitative Objectives for Performance What metrics are measured and what is the frequency of those measurements? With these measures can you determine whether the process reaches its quantitative objectives? GP 415 Collect Product and Measurement Results through performing the Standard How are those measures collected? Who is responsible for collecting, and reporting measures? Are they measured automatically? How hard is it? How long does it take to get those measures? 31

32 GP 416 Use the Results of the Defined Measurement to Monitor and Verify the Achievement of the Performance Objectives Who analysis the measures? Are measurement results used to verify the achievement of the process? Is there, somewhere, a summary of the evolution of the process indicators? PA 4.2 Control Attribute The Control attribute is a measure of the extent to which the process is quantitatively managed to produce a process that is stable, capable, and predictable within defined limits. Are there regular statistical analyses of the process performance? Have you defined techniques to control the process performance? GP 421 Determine Analysis and Control Techniques, appropriate to control the Performance Are some performance limits defined for the process? Where do those limits come from? How have they been defined? GP 422 Define Parameters suitable to Control the Performance 32

33 GP 423 Analyze and Product Measurement Results to Identify Variations in Performance Does the analysis of measurement data enable the identification of problems encountered in the implementation of the process itself? Do you compare the process performance to the defined limits? Do you identify root causes of process performance variations? GP 424 Identify and Implement Corrective Actions to Address Assignable Causes How are special causes of variations treated? How are corrective action implemented? After the implementation of corrective actions, are new limits defined for process performance? GP 425 Re- Establish Control Limits following Corrective Actions 33

34 2.9. Work Products for Level 4 ID Name Used (X) PA 4.1 Measurement Attribute 2-00 Description 3-00 Plan 5-00 Record 6-00 Report 8-00 Specification PA 4.2 Control Attribute 2-00 Description 3-00 Plan 5-00 Record 6-00 Report Work Products Name in the Organization Location 34

35 2.10. Maturity Level 5 Assessment Level 5 Optimizing PA 5.1 Innovation Attribute The Predictable is continuously improved to meet relevant, current, and projected business goals. The Innovation attribute is a measure of the extent to which changes to the process are identified from analysis of common causes of variation in performance and from investigations of innovative approaches to the definition and deployment of the process. Do you define improvement objectives for the process based on your business goals? GP 511 Define the Improvement Objectives for the that Support the Relevant Business Goals Is the process reviewed to identify potential sources of variation? Do you identify improvement opportunities based on the analysis of these variations? GP 512 Analyze Measurement Data of the to Identify Real and Potential Variations in the Performance 35

36 Do you watch innovation and the evolution of best practices in the process domain to identify improvement opportunities? GP 513 Identify Improvement Opportunities of the Based on Innovation and Best Practices Are there reviews of new technologies? Do you define improvement opportunities for the process based on new technologies? GP 514 Derive Improvement Opportunities of the from New Technologies and Concepts Is there a defined improvement strategy for the process? GP 515 Define an Implementatio n Strategy based on longterm Improvement Vision and Objectives 36

37 PA 5.2 Optimization Attribute GP 521 Assess the Impact of Each Proposed Change against the Objectives of the Defined Standard GP 522 Manage the Implementatio n of agreed changes to select areas of the Defined Standard according to the Implementatio n Strategy GP 523 Evaluate the Effectiveness of Change on the basis of actual Performance against Performance and Capability Objectives and Business Goals The Optimization attribute is a measure of the extent to which changes to the definition, management, and performance of the process result in an effective impact that achieves the relevant process improvement objectives. How do you assess the proposed improvements of the standard process? How are the process improvements implemented? What are the steps? Who implements the process improvement changes? Who will follow and check the positive or negative effect? When improvement changes are implemented, is the implementation effectiveness assessed? Who is in charge? (top management, process owner?) 37

38 2.11. Work Products for Level 5 ID Name Used (X) PA 5.1 Innovation Attribute 2-00 Description 3-00 Plan 4-00 Procedure 5-00 Record 6-00 Report 8-00 Specification PA 5.2 Optimization Attribute 2-00 Description 3-00 Plan 5-00 Record 6-00 Report 8-00 Specification Work Products Name in the Organization Location 38

Project Risk and Pre/Post Implementation Reviews

Project Risk and Pre/Post Implementation Reviews Project Risk and Pre/Post Implementation Reviews Material Changes to the System of Internal Control VGFOA Conference (Virginia Beach, VA) May 20, 2015 Agenda/Objectives Understand why system implementations

More information

Roles, Activities and Relationships

Roles, Activities and Relationships and in COBIT 5 Objective: Value Creation Benefits Realisation Risk Resource Enablers Scope Roles, Activities and Relationships Source: COBIT 5, figure 8 Key Roles, Activities and Relationships Roles, Activities

More information

Issue 1.0. UoG/ILS/IS 001. Information Security and Assurance Policy. Information Security and Compliance Manager

Issue 1.0. UoG/ILS/IS 001. Information Security and Assurance Policy. Information Security and Compliance Manager Document Reference Number Date Title Author Owning Department Version Approval Date Review Date Approving Body UoG/ILS/IS 001 January 2016 Information Security and Assurance Policy Information Security

More information

DNV GL Assessment Checklist ISO 9001:2015

DNV GL Assessment Checklist ISO 9001:2015 DNV GL Assessment Checklist ISO 9001:2015 Rev 0 - December 2015 4 Context of the Organization No. Question Proc. Ref. Comments 4.1 Understanding the Organization and its context 1 Has the organization

More information

ISO 9001:2015 Internal Audit Checklist

ISO 9001:2015 Internal Audit Checklist Page 1 of 14 Client: Date: Client ID: Auditor Audit Report Key - SAT: Satisfactory; OBS: Observation; NC: Nonconformance; N/A: Not Applicable at this time Clause Requirement Comply Auditor Notes / Evidence

More information

ISO 20000-1:2005 Requirements Summary

ISO 20000-1:2005 Requirements Summary Contents 3. Requirements for a Management System... 3 3.1 Management Responsibility... 3 3.2 Documentation Requirements... 3 3.3 Competence, Awareness, and Training... 4 4. Planning and Implementing Service

More information

Information Technology Engineers Examination. Information Technology Service Manager Examination. (Level 4) Syllabus

Information Technology Engineers Examination. Information Technology Service Manager Examination. (Level 4) Syllabus Information Technology Engineers Examination Information Technology Service Manager Examination (Level 4) Syllabus Details of Knowledge and Skills Required for the Information Technology Engineers Examination

More information

UMHLABUYALINGANA MUNICIPALITY IT CHANGE MANAGEMENT POLICY

UMHLABUYALINGANA MUNICIPALITY IT CHANGE MANAGEMENT POLICY UMHLABUYALINGANA MUNICIPALITY IT CHANGE MANAGEMENT POLICY Originator IT Change Management Policy Approval and Version Control Approval Process: Position or Meeting Number: Date: Recommended by Director

More information

ITIL Introducing service transition

ITIL Introducing service transition ITIL Introducing service transition The goals of service transition Aligning the new or changed service with the organisational requirements and organisational operations Plan and manage the capacity and

More information

Quality Manual ISO 9001:2015 Quality Management System

Quality Manual ISO 9001:2015 Quality Management System Quality management input comprises the standard requirements from ISO 9001:2015 which are deployed by our organization to achieve customer satisfaction through process control. Quality Manual ISO 9001:2015

More information

EQF CODE EQF. European Competence Profiles in e-content Professions. http://www.ubique.org/eqfcode

EQF CODE EQF. European Competence Profiles in e-content Professions. http://www.ubique.org/eqfcode EQF CODE EQF European Competence Profiles in e-content Professions http://www.ubique.org/eqfcode European Competence Profiles in e-content Professions This project has been funded with support from the

More information

CMS Policy for Configuration Management

CMS Policy for Configuration Management Chief Information Officer Centers for Medicare & Medicaid Services CMS Policy for Configuration April 2012 Document Number: CMS-CIO-POL-MGT01-01 TABLE OF CONTENTS 1. PURPOSE...1 2. BACKGROUND...1 3. CONFIGURATION

More information

Manage Release and Deployment

Manage Release and Deployment Manage Release and Deployment Description Once development is complete, new and enhanced services need to be made operational. Effective requires planning, scheduling and controlling the implementation

More information

<name of project> Software Project Management Plan

<name of project> Software Project Management Plan The document in this file is adapted from the IEEE standards for Software Project Management Plans, 1058-1998, which conforms to the requirements of ISO standard 12207 Software Life Cycle Processes. Tailor

More information

Information Security Policies. Version 6.1

Information Security Policies. Version 6.1 Information Security Policies Version 6.1 Information Security Policies Contents: 1. Information Security page 3 2. Business Continuity page 5 3. Compliance page 6 4. Outsourcing and Third Party Access

More information

Managing and Maintaining Windows Server 2008 Servers

Managing and Maintaining Windows Server 2008 Servers Managing and Maintaining Windows Server 2008 Servers Course Number: 6430A Length: 5 Day(s) Certification Exam There are no exams associated with this course. Course Overview This five day instructor led

More information

Release Management Policy Aspen Marketing Services Version 1.1

Release Management Policy Aspen Marketing Services Version 1.1 Release Management Policy Version 1.1 John Toso 5/10/2010 2 Contents Release Management Policy Overview:... 3 Critical Success Factors... 3 Service Level Management (SLM)... 4 Key Performance Indicators:...

More information

ITIL A guide to service asset and configuration management

ITIL A guide to service asset and configuration management ITIL A guide to service asset and configuration management The goal of service asset and configuration management The goals of configuration management are to: Support many of the ITIL processes by providing

More information

Release & Deployment Management

Release & Deployment Management 1. Does the tool facilitate the management of the full lifecycle of Release and Deployment Management? For example, planning, building, testing, quality assurance, scheduling and deployment? Comments:

More information

PHASE 5: DESIGN PHASE

PHASE 5: DESIGN PHASE PHASE 5: DESIGN PHASE During the Design Phase, the system is designed to satisfy the requirements identified in the previous phases. The requirements identified in the Requirements Analysis Phase are transformed

More information

The Configuration Management process area involves the following:

The Configuration Management process area involves the following: CONFIGURATION MANAGEMENT A Support Process Area at Maturity Level 2 Purpose The purpose of is to establish and maintain the integrity of work products using configuration identification, configuration

More information

Software Test Plan (STP) Template

Software Test Plan (STP) Template (STP) Template Items that are intended to stay in as part of your document are in bold; explanatory comments are in italic text. Plain text is used where you might insert wording about your project. This

More information

PHASE 9: OPERATIONS AND MAINTENANCE PHASE

PHASE 9: OPERATIONS AND MAINTENANCE PHASE PHASE 9: OPERATIONS AND MAINTENANCE PHASE During the Operations and Maintenance Phase, the information system s availability and performance in executing the work for which it was designed is maintained.

More information

e-tourism Marketing Specialist

e-tourism Marketing Specialist ! Role Profile for e-tourism Marketing Specialist e-jobs-observatory.eu European Profiles in e-tourism Functions e-tourism Marketing Specialist 1 e-tourism Marketing Specialist 1. Role Profile Role title

More information

Spillemyndigheden s change management programme. Version 1.3.0 of 1 July 2012

Spillemyndigheden s change management programme. Version 1.3.0 of 1 July 2012 Version 1.3.0 of 1 July 2012 Contents 1 Introduction... 3 1.1 Authority... 3 1.2 Objective... 3 1.3 Target audience... 3 1.4 Version... 3 1.5 Enquiries... 3 2. Framework for managing system changes...

More information

NOS for Network Support (903)

NOS for Network Support (903) NOS for Network Support (903) November 2014 V1.1 NOS Reference ESKITP903301 ESKITP903401 ESKITP903501 ESKITP903601 NOS Title Assist with Installation, Implementation and Handover of Network Infrastructure

More information

Maturity Model. March 2006. Version 1.0. P2MM Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce

Maturity Model. March 2006. Version 1.0. P2MM Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce Maturity Model March 2006 Version 1.0 P2MM Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce This is a Value Added product which is outside the scope of the HMSO

More information

Template K Implementation Requirements Instructions for RFP Response RFP #

Template K Implementation Requirements Instructions for RFP Response RFP # Template K Implementation Requirements Instructions for RFP Response Table of Contents 1.0 Project Management Approach... 3 1.1 Program and Project Management... 3 1.2 Change Management Plan... 3 1.3 Relationship

More information

Qlik UKI Consulting Services Catalogue

Qlik UKI Consulting Services Catalogue Qlik UKI Consulting Services Catalogue The key to a successful Qlik project lies in the right people, the right skills, and the right activities in the right order www.qlik.co.uk Table of Contents Introduction

More information

Internal Audit Checklist

Internal Audit Checklist Internal Audit Checklist 4.2 Policy Verify required elements Verify management commitment Verify available to the public Verify implementation by tracing links back to policy statement Check review/revisions

More information

Achieve. Performance objectives

Achieve. Performance objectives Achieve Performance objectives Performance objectives are benchmarks of effective performance that describe the types of work activities students and affiliates will be involved in as trainee accountants.

More information

COBIT 5 Introduction. 28 February 2012

COBIT 5 Introduction. 28 February 2012 COBIT 5 Introduction 28 February 2012 COBIT 5 Executive Summary 2012 ISACA. All rights reserved. 2 Information! Information is a key resource for all enterprises. Information is created, used, retained,

More information

Release and Deployment Management Software

Release and Deployment Management Software ( Bron: ITG, Integration Technologies Group; zie ook blz 13) (Service Transition) Release and Deployment Management Software 1. Does the tool facilitate the management of the full lifecycle of Release

More information

The ITIL Foundation Examination

The ITIL Foundation Examination The ITIL Foundation Examination Sample Paper B, version 4.0 Multiple Choice Instructions 1. All 40 questions should be attempted. 2. All answers are to be marked on the answer grid provided. 3. You have

More information

44-76 mix 2. Exam Code:MB5-705. Exam Name: Managing Microsoft Dynamics Implementations Exam

44-76 mix 2. Exam Code:MB5-705. Exam Name: Managing Microsoft Dynamics Implementations Exam 44-76 mix 2 Number: MB5-705 Passing Score: 800 Time Limit: 120 min File Version: 22.5 http://www.gratisexam.com/ Exam Code:MB5-705 Exam Name: Managing Microsoft Dynamics Implementations Exam Exam A QUESTION

More information

ITIL Intermediate Capability Stream:

ITIL Intermediate Capability Stream: ITIL Intermediate Capability Stream: OPERATIONAL SUPPORT AND ANALYSIS (OSA) CERTIFICATE Sample Paper 1, version 5.1 Gradient Style, Complex Multiple Choice QUESTION BOOKLET Gradient Style Multiple Choice

More information

PORTFOLIO, PROGRAMME & PROJECT MANAGEMENT MATURITY MODEL (P3M3)

PORTFOLIO, PROGRAMME & PROJECT MANAGEMENT MATURITY MODEL (P3M3) PORTFOLIO, PROGRAMME & PROJECT MANAGEMENT MATURITY MODEL (P3M3) 1st February 2006 Version 1.0 1 P3M3 Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce This is a Value

More information

Internal Quality Management System Audit Checklist (ISO9001:2015) Q# ISO 9001:2015 Clause Audit Question Audit Evidence 4 Context of the Organization

Internal Quality Management System Audit Checklist (ISO9001:2015) Q# ISO 9001:2015 Clause Audit Question Audit Evidence 4 Context of the Organization Internal Quality Management System Audit Checklist (ISO9001:2015) Q# ISO 9001:2015 Clause Audit Question Audit Evidence 4 Context of the Organization 4.1 Understanding the organization and its context

More information

Certification criteria for. Internal QMS Auditor Training Course

Certification criteria for. Internal QMS Auditor Training Course Certification criteria for Internal QMS Auditor Training Course CONTENTS 1. INTRODUCTION 2. LEARNING OBJECTIVES 3. ENABLING OBJECTIVES KNOWLEDGE & SKILLS 4. TRAINING METHODS 5. COURSE CONTENT 6. COURSE

More information

Row Manufacturing Inc. Quality Manual ISO 9001:2008

Row Manufacturing Inc. Quality Manual ISO 9001:2008 Row Manufacturing Inc. Quality Manual ISO 9001:2008 Row Manufacturing 210 Durham Drive Athens, Alabama 35611 Phone:256.232.4151 Fax:256.232.4133 Page 2 of 33 This Page intentionally left Blank Page 3 of

More information

Revised October 2013

Revised October 2013 Revised October 2013 Version 3.0 (Live) Page 0 Owner: Chief Examiner CONTENTS: 1. Introduction..2 2. Foundation Certificate 2 2.1 The Purpose of the COBIT 5 Foundation Certificate.2 2.2 The Target Audience

More information

Guideline. Records Management Strategy. Public Record Office Victoria PROS 10/10 Strategic Management. Version Number: 1.0. Issue Date: 19/07/2010

Guideline. Records Management Strategy. Public Record Office Victoria PROS 10/10 Strategic Management. Version Number: 1.0. Issue Date: 19/07/2010 Public Record Office Victoria PROS 10/10 Strategic Management Guideline 5 Records Management Strategy Version Number: 1.0 Issue Date: 19/07/2010 Expiry Date: 19/07/2015 State of Victoria 2010 Version 1.0

More information

Sound Transit Internal Audit Report - No. 2014-3

Sound Transit Internal Audit Report - No. 2014-3 Sound Transit Internal Audit Report - No. 2014-3 IT Project Management Report Date: Dec. 26, 2014 Table of Contents Page Background 2 Audit Approach and Methodology 2 Summary of Results 4 Findings & Management

More information

ITIL Roles Descriptions

ITIL Roles Descriptions ITIL Roles s Role Process Liaison Incident Analyst Operations Assurance Analyst Infrastructure Solution Architect Problem Manager Problem Owner Change Manager Change Owner CAB Member Release Analyst Test

More information

State of Oregon. State of Oregon 1

State of Oregon. State of Oregon 1 State of Oregon State of Oregon 1 Table of Contents 1. Introduction...1 2. Information Asset Management...2 3. Communication Operations...7 3.3 Workstation Management... 7 3.9 Log management... 11 4. Information

More information

SAP ERP Upgrade Checklist Project Preparation

SAP ERP Upgrade Checklist Project Preparation A SAP ERP Upgrade Checklist Project Preparation Upgrade Project Phase Project Preparation Definition From the project perspective the project preparation phase includes: Learning about the new functionality

More information

IT Service Continuity Management PinkVERIFY

IT Service Continuity Management PinkVERIFY -11-G-001 General Criteria Does the tool use ITIL 2011 Edition process terms and align to ITIL 2011 Edition workflows and process integrations? -11-G-002 Does the tool have security controls in place to

More information

QUALITY MANUAL ISO 9001:2015

QUALITY MANUAL ISO 9001:2015 Page 1 of 22 QUALITY MANUAL ISO 9001:2015 Quality Management System Page 1 of 22 Page 2 of 22 Sean Duclos Owner Revision History Date Change Notice Change Description 11/02/2015 1001 Original Release to

More information

UoD IT Job Description

UoD IT Job Description UoD IT Job Description Role: Projects Portfolio Manager HERA Grade: 8 Responsible to: Director of IT Accountable for: Day to day leadership of team members and assigned workload Key Relationships: Management

More information

Information Systems and Technology

Information Systems and Technology As public servants, it is our responsibility to use taxpayers dollars in the most effective and efficient way possible while adhering to laws and regulations governing those processes. There are many reasons

More information

Build (develop) and document Acceptance Transition to production (installation) Operations and maintenance support (postinstallation)

Build (develop) and document Acceptance Transition to production (installation) Operations and maintenance support (postinstallation) It is a well-known fact in computer security that security problems are very often a direct result of software bugs. That leads security researches to pay lots of attention to software engineering. The

More information

Fundamentals of Information Systems, Fifth Edition. Chapter 8 Systems Development

Fundamentals of Information Systems, Fifth Edition. Chapter 8 Systems Development Fundamentals of Information Systems, Fifth Edition Chapter 8 Systems Development Principles and Learning Objectives Effective systems development requires a team effort of stakeholders, users, managers,

More information

The ITIL v.3 Foundation Examination

The ITIL v.3 Foundation Examination The ITIL v.3 Foundation Examination ITIL v. 3 Foundation Examination: Sample Paper B, version 3.1 Multiple Choice Instructions 1. All 40 questions should be attempted. 2. There are no trick questions.

More information

Information Management Advice 35: Implementing Information Security Part 1: A Step by Step Approach to your Agency Project

Information Management Advice 35: Implementing Information Security Part 1: A Step by Step Approach to your Agency Project Information Management Advice 35: Implementing Information Security Part 1: A Step by Step Approach to your Agency Project Introduction This Advice provides an overview of the steps agencies need to take

More information

Computing Services Network Project Methodology

Computing Services Network Project Methodology Computing Services Network Project Prepared By: Todd Brindley, CSN Project Version # 1.0 Updated on 09/15/2008 Version 1.0 Page 1 MANAGEMENT PLANNING Project : Version Control Version Date Author Change

More information

PROCESSING & MANAGEMENT OF INBOUND TRANSACTIONAL CONTENT

PROCESSING & MANAGEMENT OF INBOUND TRANSACTIONAL CONTENT PROCESSING & MANAGEMENT OF INBOUND TRANSACTIONAL CONTENT IN THE GLOBAL ENTERPRISE A BancTec White Paper SUMMARY Reducing the cost of processing transactions, while meeting clients expectations, protecting

More information

IT General Controls Domain COBIT Domain Control Objective Control Activity Test Plan Test of Controls Results

IT General Controls Domain COBIT Domain Control Objective Control Activity Test Plan Test of Controls Results Acquire or develop application systems software Controls provide reasonable assurance that application and system software is acquired or developed that effectively supports financial reporting requirements.

More information

Certified Information Professional 2016 Update Outline

Certified Information Professional 2016 Update Outline Certified Information Professional 2016 Update Outline Introduction The 2016 revision to the Certified Information Professional certification helps IT and information professionals demonstrate their ability

More information

Exhibit to Data Center Services Service Component Provider Master Services Agreement

Exhibit to Data Center Services Service Component Provider Master Services Agreement Exhibit to Data Center Services Service Component Provider Master Services Agreement DIR Contract No. DIR-DCS-SCP-MSA-002 Between The State of Texas, acting by and through the Texas Department of Information

More information

Procuring Penetration Testing Services

Procuring Penetration Testing Services Procuring Penetration Testing Services Introduction Organisations like yours have the evolving task of securing complex IT environments whilst delivering their business and brand objectives. The threat

More information

70-646 R3: Windows Server 2008 Administration. Course Overview. Course Outline. Course Length: 4 Day

70-646 R3: Windows Server 2008 Administration. Course Overview. Course Outline. Course Length: 4 Day 70-646 R3: Windows Server 2008 Administration Course Length: 4 Day Course Overview This course will prepare the student for Exam 70-646: Pro: Windows Server 2008, Server Administrator. Topics covered include

More information

Enterprise Security Tactical Plan

Enterprise Security Tactical Plan Enterprise Security Tactical Plan Fiscal Years 2011 2012 (July 1, 2010 to June 30, 2012) Prepared By: State Chief Information Security Officer The Information Security Council State of Minnesota Enterprise

More information

AUDITOR GUIDELINES. Responsibilities Supporting Inputs. Receive AAA, Sign and return to IMS with audit report. Document Review required?

AUDITOR GUIDELINES. Responsibilities Supporting Inputs. Receive AAA, Sign and return to IMS with audit report. Document Review required? 1 Overview of Audit Process The flow chart below shows the overall process for auditors carrying out audits for IMS International. Stages within this process are detailed further in this document. Scheme

More information

EXECUTIVE SUMMARY...5

EXECUTIVE SUMMARY...5 Table of Contents EXECUTIVE SUMMARY...5 CONTEXT...5 AUDIT OBJECTIVE...5 AUDIT SCOPE...5 AUDIT CONCLUSION...6 KEY OBSERVATIONS AND RECOMMENDATIONS...6 1. INTRODUCTION...9 1.1 BACKGROUND...9 1.2 OBJECTIVES...9

More information

Identifying & Implementing Quick Wins

Identifying & Implementing Quick Wins Identifying & Implementing Quick Wins 1 Executive Summary........3 2 Introduction....... 5 3 Key Steps to Quick Wins....... 7 4 Sample Quick Wins...8 4.1 People Quick Wins... 8 4.2 Process Quick Wins......9

More information

An organization properly establishes and operates its control over risks regarding the information system to fulfill the following objectives:

An organization properly establishes and operates its control over risks regarding the information system to fulfill the following objectives: p. 1 System Management Standards Proposed on October 8, 2004 Preface Today, the information system of an organization works as an important infrastructure of the organization to implement its management

More information

Digital Asset Manager, Digital Curator. Cultural Informatics, Cultural/ Art ICT Manager

Digital Asset Manager, Digital Curator. Cultural Informatics, Cultural/ Art ICT Manager Role title Digital Cultural Asset Manager Also known as Relevant professions Summary statement Mission Digital Asset Manager, Digital Curator Cultural Informatics, Cultural/ Art ICT Manager Deals with

More information

Project Management Toolkit Version: 1.0 Last Updated: 23rd November- Formally agreed by the Transformation Programme Sub- Committee

Project Management Toolkit Version: 1.0 Last Updated: 23rd November- Formally agreed by the Transformation Programme Sub- Committee Management Toolkit Version: 1.0 Last Updated: 23rd November- Formally agreed by the Transformation Programme Sub- Committee Page 1 2 Contents 1. Introduction... 3 1.1 Definition of a... 3 1.2 Why have

More information

7 Directorate Performance Managers. 7 Performance Reporting and Data Quality Officer. 8 Responsible Officers

7 Directorate Performance Managers. 7 Performance Reporting and Data Quality Officer. 8 Responsible Officers Contents Page 1 Introduction 2 2 Objectives of the Strategy 2 3 Data Quality Standards 3 4 The National Indicator Set 3 5 Structure of this Strategy 3 5.1 Awareness 4 5.2 Definitions 4 5.3 Recording 4

More information

Criticism of Implementation of ITSM & ISO20000 in IT Banking Industry. Presented by: Agus Sutiawan, MIT, CISA, CISM, ITIL, BSMR3

Criticism of Implementation of ITSM & ISO20000 in IT Banking Industry. Presented by: Agus Sutiawan, MIT, CISA, CISM, ITIL, BSMR3 Criticism of Implementation of ITSM & ISO20000 in IT Banking Industry Presented by: Agus Sutiawan, MIT, CISA, CISM, ITIL, BSMR3 Outline What is IT Service Management What is ISO 20000 Step by step implementation

More information

EMA CMDB Assessment Service

EMA CMDB Assessment Service The Promise of the CMDB The Configuration Management Database (CMDB) provides a common trusted source for all IT data used by the business and promises to improve IT operational efficiency and increase

More information

JOB DESCRIPTION CONTRACTUAL POSITION

JOB DESCRIPTION CONTRACTUAL POSITION Ref #: IT/P /01 JOB DESCRIPTION CONTRACTUAL POSITION JOB TITLE: INFORMATION AND COMMUNICATIONS TECHNOLOGY (ICT) SECURITY SPECIALIST JOB SUMMARY: The incumbent is required to provide specialized technical

More information

INTERNAL AUDIT DIVISION AUDIT REPORT 2013/020. Audit of the Umoja software system (SAP) implementation

INTERNAL AUDIT DIVISION AUDIT REPORT 2013/020. Audit of the Umoja software system (SAP) implementation INTERNAL AUDIT DIVISION AUDIT REPORT 2013/020 Audit of the Umoja software system (SAP) implementation Overall results relating to effective implementation and configuration of the SAP system were initially

More information

2.2 INFORMATION SERVICES Documentation of computer services, computer system management, and computer network management.

2.2 INFORMATION SERVICES Documentation of computer services, computer system management, and computer network management. 3 Audit Trail Files Data generated during the creation of a master file or database, used to validate a master file or database during a processing cycle. GS 14020 Retain for 3 backup cycles Computer Run

More information

Lot 1 Service Specification MANAGED SECURITY SERVICES

Lot 1 Service Specification MANAGED SECURITY SERVICES Lot 1 Service Specification MANAGED SECURITY SERVICES Fujitsu Services Limited, 2013 OVERVIEW OF FUJITSU MANAGED SECURITY SERVICES Fujitsu delivers a comprehensive range of information security services

More information

Request for Proposal. Supporting Document 3 of 4. Contract and Relationship Management for the Education Service Payroll

Request for Proposal. Supporting Document 3 of 4. Contract and Relationship Management for the Education Service Payroll Request for Proposal Supporting Document 3 of 4 Contract and Relationship December 2007 Table of Contents 1 Introduction 3 2 Governance 4 2.1 Education Governance Board 4 2.2 Education Capability Board

More information

Blend Approach of IT Service Management and PMBOK for Application Support Project

Blend Approach of IT Service Management and PMBOK for Application Support Project Blend Approach of IT Service and PMBOK for Application Support Project Introduction: This paper addresses the process area, phases and documentation to be done for Support Project using Project and ITSM

More information

ITIL A guide to release and deployment management

ITIL A guide to release and deployment management ITIL A guide to release and deployment management The goal of release and deployment management Release and deployment management aims to build, test and deliver services to the customers specified by

More information

1 Why should monitoring and measuring be used when trying to improve services?

1 Why should monitoring and measuring be used when trying to improve services? 1 Why should monitoring and measuring be used when trying to improve services? a) To validate, direct, justify and intervene b) To validate, measure, monitor and change c) To validate, plan, act and improve

More information

FISCAL PLAN RESPONSE TO THE AUDITOR GENERAL

FISCAL PLAN RESPONSE TO THE AUDITOR GENERAL Government FISCAL PLAN RESPONSE TO THE AUDITOR GENERAL OCTOBER 2015 127 TABLE OF CONTENTS RESPONSE TO THE AUDITOR GENERAL October 2015.... 129 128 RESPONSE TO THE AUDITOR GENERAL FISCAL PLAN 2016 19 RESPONSE

More information

Second Clinical Safety Review of the Personally Controlled Electronic Health Record (PCEHR) June 2013

Second Clinical Safety Review of the Personally Controlled Electronic Health Record (PCEHR) June 2013 Second Clinical Safety Review of the Personally Controlled Electronic Health Record (PCEHR) June 2013 Undertaken by KPMG on behalf of Australian Commission on Safety and Quality in Health Care Contents

More information

Project Management Fact Sheet:

Project Management Fact Sheet: Project Management Fact Sheet: Project Documentation Version: 2.2, November 2008 DISCLAIMER This material has been prepared for use by Tasmanian Government agencies and Instrumentalities. It follows that

More information

Feature. A Higher Level of Governance Monitoring IT Internal Controls. Controls tend to degrade over time and between audits.

Feature. A Higher Level of Governance Monitoring IT Internal Controls. Controls tend to degrade over time and between audits. Feature A Higher Level of Governance Monitoring IT Internal Controls Mike Garber, CGEIT, CIA, CITP, CPA, has many years experience as both director for IT governance and as IT audit director for Motorola

More information

Adequate Records Management - Implementation Plan

Adequate Records Management - Implementation Plan GPO Box 2343 Adelaide SA 5001 Tel (+61 8) 8204 8773 Fax (+61 8) 8204 8777 DX:467 srsarecordsmanagement@sa.gov.au www.archives.sa.gov.au Adequate Records Management - Implementation Plan October 2012 Version

More information

MKS Integrity & CMMI. July, 2007

MKS Integrity & CMMI. July, 2007 & CMMI July, 2007 Why the drive for CMMI? Missed commitments Spiralling costs Late delivery to the market Last minute crunches Inadequate management visibility Too many surprises Quality problems Customer

More information

http://www.softwaretestinghelp.com/ Test Plan Template: (Name of the Product) Prepared by: (Names of Preparers) (Date) TABLE OF CONTENTS

http://www.softwaretestinghelp.com/ Test Plan Template: (Name of the Product) Prepared by: (Names of Preparers) (Date) TABLE OF CONTENTS http://www.softwaretestinghelp.com/ Test Plan Template: (Name of the Product) Prepared by: (Names of Preparers) (Date) TABLE OF CONTENTS 1.0 INTRODUCTION 2.0 OBJECTIVES AND TASKS 2.1 Objectives 2.2 Tasks

More information

CMMI KEY PROCESS AREAS

CMMI KEY PROCESS AREAS CMMI KEY PROCESS AREAS http://www.tutorialspoint.com/cmmi/cmmi-process-areas.htm Copyright tutorialspoint.com A Process Area is a cluster of related practices in an area that, when implemented collectively,

More information

The ITIL Foundation Examination

The ITIL Foundation Examination The ITIL Foundation Examination Sample Paper B, version 5.0 Multiple Choice Instructions 1. All 40 questions should be attempted. 2. All answers are to be marked on the answer grid provided. 3. You have

More information

RS Official Gazette, No 23/2013 and 113/2013

RS Official Gazette, No 23/2013 and 113/2013 RS Official Gazette, No 23/2013 and 113/2013 Pursuant to Article 15, paragraph 1 and Article 63, paragraph 2 of the Law on the National Bank of Serbia (RS Official Gazette, Nos 72/2003, 55/2004, 85/2005

More information

NIST 800-53A: Guide for Assessing the Security Controls in Federal Information Systems. Samuel R. Ashmore Margarita Castillo Barry Gavrich

NIST 800-53A: Guide for Assessing the Security Controls in Federal Information Systems. Samuel R. Ashmore Margarita Castillo Barry Gavrich NIST 800-53A: Guide for Assessing the Security Controls in Federal Information Systems Samuel R. Ashmore Margarita Castillo Barry Gavrich CS589 Information & Risk Management New Mexico Tech Spring 2007

More information

COBIT Helps Organizations Meet Performance and Compliance Requirements

COBIT Helps Organizations Meet Performance and Compliance Requirements DISCUSS THIS ARTICLE COBIT Helps Organizations Meet Performance and Compliance Requirements By Sreechith Radhakrishnan, COBIT Certified Assessor, ISO/IEC 20000 LA, ISO/IEC 27001 LA, ISO22301 LA, ITIL Expert,

More information

Office of the Auditor General of Canada. Internal Audit of Document Management Through PROxI Implementation. July 2014

Office of the Auditor General of Canada. Internal Audit of Document Management Through PROxI Implementation. July 2014 Office of the Auditor General of Canada Internal Audit of Document Management Through PROxI Implementation July 2014 Practice Review and Internal Audit Her Majesty the Queen in Right of Canada, represented

More information

Design Document Version 0.0

Design Document Version 0.0 Software Development Templates Design Document Version 0.0 Description of Project DOCUMENT NO: VERSION: CONTACT: EMAIL: Ivan Walsh DATE: 4/13/2004 Distribution is subject to copyright. Design Document

More information

Minnesota Health Insurance Exchange (MNHIX)

Minnesota Health Insurance Exchange (MNHIX) Minnesota Health Insurance Exchange (MNHIX) 1.2 Plan September 21st, 2012 Version: FINAL v.1.0 11/9/2012 2:58 PM Page 1 of 87 T A B L E O F C O N T E N T S 1 Introduction to the Plan... 12 2 Integration

More information

Integrating Project Management and Service Management

Integrating Project Management and Service Management Integrating Project and Integrating Project and By Reg Lo with contributions from Michael Robinson. 1 Introduction Project has become a well recognized management discipline within IT. is also becoming

More information

How To Use Adobe Software For A Business

How To Use Adobe Software For A Business EXHIBIT FOR MANAGED SERVICES (2013V3) This Exhibit for Managed Services, in addition to the General Terms, the OnDemand Exhibit, and any applicable PDM, applies to any Managed Services offering licensed

More information

A system is a set of integrated components interacting with each other to serve a common purpose.

A system is a set of integrated components interacting with each other to serve a common purpose. SYSTEM DEVELOPMENT AND THE WATERFALL MODEL What is a System? (Ch. 18) A system is a set of integrated components interacting with each other to serve a common purpose. A computer-based system is a system

More information

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY AUTHOR/ APPROVAL DETAILS Document Author Written By: Human Resources Authorised Signature Authorised By: Helen Shields Date: 20

More information

SUBSIDIARY BODY FOR SCIENTIFIC AND TECHNOLOGICAL ADVICE Twenty-first session Buenos Aires, 6 14 December 2004

SUBSIDIARY BODY FOR SCIENTIFIC AND TECHNOLOGICAL ADVICE Twenty-first session Buenos Aires, 6 14 December 2004 UNITED NATIONS Distr. GENERAL FCCC/SBSTA/2004/12 29 November 2004 Original: ENGLISH SUBSIDIARY BODY FOR SCIENTIFIC AND TECHNOLOGICAL ADVICE Twenty-first session Buenos Aires, 6 14 December 2004 Item 5

More information

PRINCE2:2009 Glossary of Terms (English)

PRINCE2:2009 Glossary of Terms (English) accept (risk response) acceptance acceptance criteria activity agile methods approval approver assumption assurance A risk response to a threat where a conscious and deliberate decision is taken to retain

More information