NSW Government. Software Asset Management Standard. Version 1.0. October 2014

Size: px
Start display at page:

Download "NSW Government. Software Asset Management Standard. Version 1.0. October 2014"

Transcription

1 NSW Gvernment Sftware Asset Management Standard Versin 1.0 Octber 2014 ICT Services Office f Finance & Services Level 23, McKell Building 2-24 Rawsn Place SYDNEY NSW 2000

2 Sftware Asset Management Standard CONTENTS 1. CONTEXT 3 2. KEY PRINCIPLES 4 3. REQUIREMENTS 4 DOCUMENT CONTROL 8 APPENDIX A SAM PROCESS FRAMEWORKS 9 APPENDIX B CORE SOFTWARE ASSET MANAGEMENT PROCESSES 11 APPENDIX C CORE SOFTWARE ASSET MANAGEMENT PROCESSES MAPPED TO ISO/IEC APPENDIX D REFERENCES 19 APPENDIX E STANDARDS 20 2

3 Sftware Asset Management Standard 1. CONTEXT 1.1. Backgrund This Sftware Asset Management (SAM) Standard is a technical standard develped thrugh the NSW ICT Prcurement and Technical Standards Wrking Grup (PTS Wrking Grup). The standard cntains technical and business requirements that agencies shuld cnsider when prcuring SAM services. By defining cmmn gvernment requirements, the standard prvides an pprtunity t leverage whle f gvernment buying pwer and reduce inefficiencies. A substantial prprtin f an agency s ICT expenditure is allcated t purchasing, maintaining and perating sftware. The SAM standard will assist agencies in maintaining strategic versight f their sftware assets, and will help agencies ptimise their sftware envirnments Purpse The purpse f this standard is t assist NSW Gvernment agencies t develp, prcure and implement SAM slutins and tls, as well as take full advantage f the benefits f SAM slutins and tls. It details the issues that need t be cnsidered s each agency can identify the available ptins that best suit their business requirements, helping agencies achieve value fr mney thrugh cst savings and imprved flexibility f service fferings Scpe and applicatin This standard applies t all NSW Gvernment departments, statutry bdies and shared service prviders. It des nt apply t state wned crpratins, but is recmmended fr adptin. This standard des nt exhaustively cver all agency specific cnsideratins. Agencies may need t asses any specific requirements they have in additin t thse detailed in this standard Plicy The NSW Gvernment ICT Strategy sets ut the Gvernment s plan t build capability acrss the NSW public sectr t deliver better, mre custmer-fcused services that are available anywhere, anytime, and derive better value frm the Gvernment s annual investment in ICT. Develping whle f NSW Gvernment ICT technical standards is a key initiative f the NSW Gvernment ICT Strategy, with this wrk being driven by the PTS Wrking Grup. The standards are designed t be cnsistent with NSW Gvernment ICT Strategy and NSW Gvernment Clud Services Plicy and Guidelines bjectives, and they supprt the develpment f the NSW Gvernment s ICT Services Catalgue. The standards set ut service definitins as minimum requirements that suppliers must meet t be able t ffer their services thrugh the NSW Services Catalgue. This helps achieve cnsistency acrss service fferings, emphasising a mve t as a service surcing strategies, and it signals gvernment prcurement pririties t industry. This standard shuld be applied with existing standards, plicies and guidance that make up the NSW Infrmatin Management Framewrk, as set ut in the Infrmatin Management: A Cmmn Apprach, and including the NSW Digital Infrmatin Security Plicy. NSW Gvernment agencies must carefully cnsider their bligatins t manage gvernment data and infrmatin. Cntract arrangements and business prcesses shuld address 3

4 Sftware Asset Management Standard requirements fr data security, privacy, access, strage,, retentin and dispsal. ICT systems and services shuld supprt data exchange, prtability and interperability. Mre infrmatin n the develpment f standards fr the ICT Services Catalgue is at Appendix E Standards The ICT Services Catalgue This catalgue prvides suppliers with a shwcase fr their prducts and services, and an pprtunity t utline hw their fferings meet r exceed standard gvernment requirements. The standards, tgether with supplier service fferings in the ICT Services Catalgue, help t reduce red tape and duplicatin f effrt by allwing suppliers t submit service details nly nce. The fferings are then available t all ptential buyers, simplifying prcurement prcesses fr gvernment agencies. Implementing this categry apprach will embed cmmn appraches, technlgies and systems t maintain currency, imprve interperability and prvide better value ICT investment acrss Gvernment. 2. KEY PRINCIPLES The fllwing principles guide the develpment and implementatin f this standard. Facilitating as a service: Specificatin f envirnments shuld supprt agencies in mving t as a service surcing mdels. Interperability: Meeting this standard shuld help agencies achieve applicatin and hardware interperability, ensuring that agency cmputing envirnments enable apprpriate infrmatin sharing acrss devices and applicatins. Mbile and flexible: Envirnments shuld supprt mdern ffice wrk practices, including flexible and/r activity based wrking r ht desking. Vendr / perating envirnment agnstic: Envirnments shuld be vendr and perating system agnstic. Devices such as laptps, ntebks, thin-clients etc. shuld be able t cnnect t, and access the netwrk. The netwrk shuld als be fully cmpatible with widely used perating envirnments. 3. REQUIREMENTS 3.1. SAM system deliverables In accrdance with recgnised standards an effective SAM system shuld: Capture infrmatin abut sftware assets and their use Supprt cre tasks and functins Manage the sftware asset lifecycle Supprt business bjectives and utcmes Prmte respnsible SAM, and Deliver best practice Capturing infrmatin The SAM system shuld incrprate the ability t capture accurate, cmplete infrmatin abut the sftware assets and their use. This may include asset discvery tls, deplyment recrds and prcurement recrds. This may als invlve deplying sftware asset registers r lgs t recrd the sftware assets that the agency wns, as well as sftware asset audit and metering tls t track where and hw agency sftware is used. 4

5 Sftware Asset Management Standard Supprting cre tasks and functins The SAM system shuld assist the agency t perfrm its cre asset tasks including asset identificatin, cntrl, and licence cmpliance mnitring. This includes enabling the agency t cmplete sftware licence ptimisatin, ratinalising its sftware prtfli by reallcating, re-harvesting and deplying sftware licences where apprpriate. The system shuld enable the agency t readily and reliably plan fr its future sftware needs, including identifying pprtunities fr retirement, prtability r pling fr planned prjects Managing the sftware asset lifecycle The SAM system shuld address the full asset lifecycle, frm identifying business requirements t the retirement f the asset. The system shuld prvide interfaces int ther systems that enable the agency t manage, change, acquire, develp and deply sftware, as well as manage incidents and exceptins. It shuld enable the agency t manage sftware retirements, including identifying pprtunities fr reuse where permissible under licence agreements Supprting business bjectives and utcmes The SAM system shuld assist agencies in achieving their business bjectives. Objectives may include imprving wrker prductivity and mbility by allwing the agency t scale and deply its sftware assets as needed, assisting the agency t manage the cst f its sftware assets mre effectively, and managing the risks assciated with sftware licencing. Ultimately, the SAM system shuld assist the agency t achieve a better return n its sftware investments Prmting respnsible SAM Agencies deplying SAM systems shuld establish and implement internal plicies and cntrls that help them t manage the system apprpriately. This includes clarifying emplyee bligatins fr cmpliance with cpyright and infrmatin legislatin, as well as cntrls that ensure ptential r actual breaches are quickly addressed and remedied. T ensure this ccurs, the SAM system shuld include educatin and cmmunicatin strategies t assist emplyees at all levels understand their respnsibilities Delivering best practice Agencies shuld utilise a system that aligns with r addresses the elements f ne f the standards fr SAM. This standard references ISO/IEC and ITIL v3 SAM, which are internatinally recgnised. The prcess framewrks fr these standards are shwn in Appendix A, and the elements f the ISO standard are detailed in Appendix B. There are ther widely recgnised standards such as COBIT 5, and thers may becme available ver time. Appendix C shws cre sftware asset prcesses mapped t ISO/IEC , and Appendix D lists ther references. 5

6 Sftware Asset Management Standard 3.2. SAM cmpetency Agencies can assess their current SAM cmpetency r the capability f their SAM system against the fur brad levels as described in Table 1, r n the basis f the cre SAM elements (t be) implemented as per Table 2 and described in detail in Appendix B. Table 1: SAM Capability Classificatins SAM implementatin Reactive SAM Practive SAM Managed SAM Optimised SAM Descriptin Mst manual prcesses, ad-hc purchasing and cmpliance risks due t limited licensing prcedures. Defined and standard sftware purchasing, deplyments and security updates. Organised licensing and standardised plicies. Managed acquisitin prcesses and plicies, centralised asset tracking and. Visibility and cntrl f asset csts, savings, gvernance and liabilities. Optimal acquisitin and redeplyment cycles, efficient business infrastructure with agile and adaptable IT slutins. Optimised insight int agency assets fr current needs and future plans. The fur levels f intended r implemented SAM capability r cmpetency are listed in the first clumn in the table belw. The crrespnding required prcesses t be adpted frm the ISO standard are ticked in the clumns. As nted thrughut, cmpliance can be t any apprpriate standard, prviding the agency is satisfied that the business utcmes it requires frm SAM are being achieved. 6

7 Sftware asset identificatin Sftware asset inventry Sftware asset cntrl Applicatin gvernance Dependency analysis Sftware asset verificatin Sftware licence cmpliance Sftware asset security Cnfrmance verificatin Relatinship and cntract mgmt. Financial Service level Security Sftware Asset Management Standard Table 2: SAM Prcesses and Capability / Cmpetency Matrix Cre Sftware Asset Management Prcesses Sftware Asset Management Capability r Cmpetency Reactive SAM Practive SAM Managed SAM Optimised SAM 7

8 Sftware Asset Management Standard DOCUMENT CONTROL Dcument histry Status: Final Versin: 1.0 Apprved by: NSW Prcurement & Technical Standards Wrking Grup Apprved n: 23/9/2014 Issued by: NSW Office f Finance & Services Cntact: standards@finance.nsw.gv.au Telephne: (02) Review This standard will be reviewed in 12 mnths. It may be reviewed earlier in respnse t pstimplementatin feedback frm agencies. 8

9 Sftware Asset Management Standard APPENDIX A SAM PROCESS FRAMEWORKS Table 3 belw summarises, at a high level, the ISO/IEC Prcess Framewrk fr SAM, while Table 4 n the fllwing page utlines the ITIL Prcess Framewrk. Table 3: ISO/IEC Prcess Framewrk fr SAM Gvernance Cntrl envirnment Gvernance structures Rles and respnsibilities Plicies, prcesses and prcedures Capabilities and cmpetence Planning and implementatin prcesses Planning Implementatin Mnitring and review Cntinuus imprvement Cre SAM prcesses Inventry prcesses Sftware asset identificatin Sftware asset inventry Sftware asset cntrl Verificatin and cmpliance prcesses Sftware asset recrd verificatin Sftware licensing cmpliance Sftware asset security cmpliance Cnfrmance verificatin Operatins prcesses and interfaces Relatinship and cntract Financial Service level Security Primary prcess interfaces fr SAM Sftware lifecycle Change Sftware develpment Sftware deplyment Prblem Acquisitin Sftware release Incident Retirement A detailed explanatin f the expected cre SAM prcesses mentined in the table abve is cntained in Appendix B. 9

10 Sftware Asset Management Standard Table 4: ITIL v3 Prcess Framewrk fr SAM Overall prcesses Overall respnsibility Cmpetence, awareness and training Risk assessment Perfrmance metrics and cntinuus imprvement Plicies and prcedures Service cntinuity and availability Cre asset prcesses Asset identificatin Status accunting Asset cntrl Database Financial Management Lgistic Prcesses Requirements definitin Design Evaluatin Prcurement Build Deplyment Operatin Optimisatin Retirement Verificatin and cmpliance prcesses Verificatin and audit Licensing cmpliance Security cmpliance Other cmpliance Relatinship prcesses Cntract Supplier Internal business relatinship Outsurcing 10

11 Sftware Asset Management Standard APPENDIX B CORE SOFTWARE ASSET MANAGEMENT PROCESSES A. Inventry prcesses Sftware asset identificatin The SAM system shuld enable the agency t ensure necessary classes f assets are selected and gruped. Assets shuld be defined, recrded and srted by apprpriate characteristics that enable effective and efficient cntrl f sftware and related assets. The SAM system shuld include a Sftware Asset Register that meets the fllwing minimum sftware identificatin requirements: The register shuld identify the type f sftware assets t be cntrlled and infrmatin assciated with them frmally defined, taking int accunt: Items t be managed are chsen using established selectin criteria, and gruped, classified and identified t ensure manageability and traceability thrughut their lifecycle. Basic infrmatin, including: Sftware vendr Sftware title Sftware editin Sftware versin Licence type/mdel Number f licences wned Cntract numbers relating t purchase UNSPSC cde (if available) System wner / prduct manager (where apprpriate) Supprt and maintenance status. Items t be managed include: Definitive Sftware Master List List f all sftware apprved fr use in the rganisatin Cntracts related t sftware assets regardless f frmat Licence agreements (including end user licence agreements, click thrugh licence agreements and freeware licence agreements etc.), incrprating terms and cnditins Prf f purchase. A Hardware Asset Register shuld be used t capture relevant details relating t hardware asset classes, namely: Lcatin (where apprpriate) System wner Status (test/develpment/prductin etc.) Type (sftware, hardware facility etc.) Platfrms n which sftware assets can be installed/run Changes t assets Hardware inventry including lcatins are verified n a regular (minimum six mnthly) basis including reprting identified exceptins. Sftware asset inventry The SAM system shuld enable the agency t ensure physical instances f sftware assets are prperly stred and that required data characteristics fr all assets/cnfiguratin items are accurately recrded thrughut the lifecycle. 11

12 Sftware Asset Management Standard T achieve these gals, the system shuld include the fllwing: Definitive Sftware Master List: media library (including cpies f all versins/patches f all sftware currently in use in the envirnment). Definitive Sftware Master List: dcumentatin (a cpy f each piece f dcumentatin relating t each sftware title installed in the envirnment). Definitive Sftware Master List: licences and prf f purchase (including all base licences, upgrades, crss grades etc.). Cpies f all sftware patches relating t sftware currently installed in the envirnment Installed sftware (including versin, editins, patches etc.). Sftware packages authrised fr deplyment. Sftware asset cntrl The SAM system shuld enable the agency t cntrl its sftware assets while maintaining a recrd f changes t its sftware asset hldings. The sftware asset cntrls shuld allw the agency t demnstrate that: An audit trail is maintained with changes made t sftware including changes in status, lcatin, custdianship and versin. Apprpriate plicies, prcesses and prcedures are apprved and issued fr develpment, maintenance and f sftware versins, images, builds and releases. B. Verificatin and cmpliance prcesses Sftware asset recrd verificatin The SAM system shuld enable the agency t ensure recrds are accurate and maintained in accrdance with infrmatin requirements. The system shuld include prcesses fr sftware asset recrd verificatin, including: Verificatin f installed sftware reprting t ensure accuracy at least. Minimum quarterly recnciliatin between what is installed and what was authrised fr installatin acrss the envirnment. Inventry and verificatin f the Definitive Sftware Master List media library, licence and prf f purchase cnducted n a half yearly basis. Cntract dcumentatin related t sftware assets verified fr cmpleteness at least annually. Any issues, prblems r exceptins t the abve are dcumented, rt-cause analysis is perfrmed and remediatin activities undertaken t achieve crrectin. All findings and remediatin activities t be fully dcumented. Sftware licensing cmpliance The SAM system shuld enable the agency t ensure all sftware is licensed crrectly and that cntractual and licence terms and cnditins relating t sftware installatin and usage are met. The system shuld include plicies, prcesses and prcedures t ensure that emplyees cmply with their sftware licence bligatins and terms f use, including: Prcurement plicy. Deplyment/installatin plicy. Usage plicy. Regular cnfirmatin f effective licence psitin. Recrding f discvered cmpliance issues in the Sftware Risk Register. Apprpriate remediatin actins are taken and recrded. The rt cause f the issue is determined and actin is taken t address it. 12

13 Sftware Asset Management Standard Sftware asset security cmpliance The agency shuld ensure physical and technical security measures related t the strage f sftware and related assets prevent unauthrised access r use. Implementatin f the SAM system shuld enable the agency t: Reprt n wh has had access t the sftware media and licence keys. Identify which purpse the sftware was accessed fr. The date f access and return. Reprt n actins taken t address unauthrised r extended access. Cnfrmance verificatin The SAM system shuld enable the agency t mnitr and ensure cnfrmance with regulatry requirements and best practice standards. Agencies shuld be in a psitin t demnstrate that: Plicies and prcedures are develped, apprved and issued fr verifying cmpliance with their selected standard. Verificatin prcedures are being perfrmed annually and that crrective fllw-up actin is taken n identified exceptins. C. Operatins prcesses and interfaces The SAM system shuld enable the agency t execute the peratinal functins that are essential t achieving verall SAM bjectives and benefits. Relatinship and cntract The SAM system shuld enable the agency t manage its relatinships with ther rganisatins, including its cntracts and cntractual relatinships fr sftware and related assets/services. Implementatin f the system will enable the agency t demnstrate: Plicies and prcedures are develped, apprved and issued fr managing relatinships with suppliers prviding sftware and related assets/services t include: Definitin f respnsibilities fr supplier with individuals assigned t have clear verall respnsibility fr managing suppliers. Frmal dcumented reviews at least half yearly f supplier perfrmance, achievements and issues, with dcumented cnclusins and decisins abut actins t be taken. Plicies and prcedures develped, apprved and issued fr f custmer-side relatinships including: Definitin f respnsibilities fr managing custmer-side business relatinships with respect t sftware and related assets/services. Regular reviews f current/future sftware requirements acrss the agency as a whle. Frmal dcumented annual reviews f service prvider perfrmance, custmer satisfactin, achievements and issues, with dcumented cnclusins and decisins abut any actins t be taken. Plicies and prcedures develped, apprved and issued fr managing cntracts including: Ensuring cntractual details are recrded in an n-ging cntract system as cntracts are signed. Cpies f all signed cntractual dcumentatin securely maintained in a dcument system in additin t keeping riginal signed dcuments. Half-yearly dcumented reviews prir t cntract expiry, and all cntracts with dcumented cnclusins and decisins abut actins taken. 13

14 Sftware Asset Management Standard Financial The SAM system shuld enable the agency t apprpriately budget and accunt fr its sftware and related assets. Implementatin shuld allw the agency t achieve the fllwing: Definitins f financial infrmatin relevant t f sftware and related assets are agreed with relevant parties and dcumented by asset type. Frmal budgets are develped fr acquisitin f sftware assets and related supprt. Actual expenditure n sftware assets and related supprt and infrastructure csts is accunted fr against budget. Clearly dcumented financial infrmatin is available abut sftware asset values (including but nt limited t histrical and/r depreciatin csts). Frmal dcumented quarterly reviews f actual expenditure against budget with dcumented cnclusins and decisins abut any actins required. Security Manage infrmatin security effectively with all SAM activities and supprt apprval requirements related t SAM. Implementatin will enable agencies t demnstrate: Frmal plicy is develped and apprved regarding security/access restrictins fr all SAM resurces, including physical/electrnic stres f sftware builds/releases. Access cntrls are specified, bth physical and lgical, t enfrce the apprval requirements f SAM plicies. There is dcumentary evidence shwing that specified access cntrls are implemented in practice. D. MANAGING THE SOFTWARE LIFECYCLE An effective SAM system shuld be clsely integrated with standard prcesses. Change Ensuring effective integratin between the SAM system and the change prcess will enable the agency t demnstrate that a frmal prcess exists, requiring that: All change requests that affect sftware and/r SAM prcesses are identified and recrded. All change requests that affect sftware and/r SAM prcesses are assessed and apprved via a frmal change prcess that includes SAM representatives. The success r failure f changes is dcumented and peridically reviewed. Acquisitin Effective integratin between the SAM system and the prcurement prcess will allw the agency t demnstrate that: The relevant standard architectures are defined fr the prvisin f sftware services, as well as criteria fr deviating frm thse standards. Standard sftware cnfiguratins are defined, as are criteria fr deviating frm thse standards. Standard sftware prcurement methds are defined, as are criteria fr deviating frm thse standards. Sftware apprved fr use is detailed in the Sftware Catalgue indicating editins, versins and apprved acquisitin methd. 14

15 Sftware Asset Management Standard Plicies and prcedures are develped, prperly authrised and issued fr requisitining and rdering sftware and related assets, including: Hw requirements are specified. Management and technical apprvals required. Use/redeplyment f existing licences if available. Recrding future purchase requirements fr thse cases where sftware can be deplyed befre reprting and payment. Acquisitin methd and apprved exceptins. Plicies and prcedures develped, prperly authrised and used fr receipt-prcessing functins related t sftware and related assets including: Prcessing invices, recnciliatins t rders and retentin f cpies fr licence purpses. Receipting and safe-keeping valid prf f licence fr all licences purchased. Prcessing incming media including requirements fr verificatin, recrd-keeping and safekeeping f cntents (physical and electrnic). Sftware develpment Effective integratin between the SAM system and the sftware develpment prcess will allw the agency t demnstrate: That, where practical, sftware develpment is ccurring in a segregated envirnment. That a frmal prcess fr sftware develpment exists and cnsiders standard architectures and cnfiguratins, licence cnstraints and dependencies. Frmal prcess fr sftware develpment t include SAM requirements and cntrls. Sftware release Effective integratin between the SAM system and the sftware release prcess will allw the agency t demnstrate that: Release f sftware is apprved by the respnsible. Result f the release is recrded and peridically reviewed. Sftware deplyment Effective integratin between the SAM system and the sftware deplyment prcess will allw the agency t demnstrate that: Distributin f sftware and related assets is apprved by the respnsible. Security requirements are cmplied with, including ver access t sftware being distributed and after installatin. All changes t the status f relevant sftware are recrded accurately and in a timely fashin including any change f custdianship, and an audit trail f changes is kept. Dcumented cntrl t verify what was deplyed is the same as authrised fr deplyment. Success r failure f deplyments is recrded and peridically reviewed. 15

16 Sftware Asset Management Standard Incident Effective integratin between the SAM system and the incident prcess enables the agency t demnstrate that: All incidents that affect sftware/related assets r SAM prcesses are recrded and classified as t their pririty fr reslutin. All such incidents are reslved in accrdance with pririty fr reslutin and the reslutin is dcumented. Prblem Effective integratin between the SAM system and the Prblem Management prcess enables agencies t demnstrate that: All incidents that affect sftware and/r related assets and/r services, alng with SAM prcesses, are recrded and classified as t their impact. High pririty and repeat incidents are analysed fr underlying causes and priritised fr reslutin. Underlying causes are dcumented and cmmunicated t incident. Prblems are reslved in accrdance with pririties fr reslutin and the reslutin is dcumented and cmmunicated t incident. Retirement/re-harvesting The SAM system shuld assist the agency t ensure that sftware and related assets are remved, recycled and reused as apprpriate and in cmpliance with infrmatin requirements. The system shuld enable prcesses t ensure that: Deplyed cpies f sftware are remved frm retired hardware (where it is permitted fr licences t be remved). Licences and ther assets which can be redeplyed are identified fr redeplyment. Assets transferred (re-harvested) t ther parties, and are transferred taking int accunt any cnfidentiality, licensing r ther cntractual requirements. Licences and ther assets that cannt be redeplyed are prperly dispsed f. Recrds are updated t reflect the changes abve, and audit trails are maintained f all changes. 16

17 Planning Prcurement Sftware Cntract Mnitring & reprting Sftware Asset Management Standard APPENDIX C CORE SOFTWARE ASSET MANAGEMENT PROCESSES MAPPED TO ISO/IEC Inventry prcesses Sftware asset identificatin Sftware asset inventry Sftware asset cntrl Applicatin gvernance Dependency analysis Verificatin and cmpliance prcesses Sftware asset recrd verificatin Sftware licensing cmpliance Sftware asset security cmpliance Cnfrmance verificatin The scpe f sftware assets cntrlled shuld be defined and address sftware entitlement (prduct and versin), prf-f-licence, cntracts/agreements, media and sftware deplyment. A central and cmprehensive inventry f sftware assets (physical and electrnic) shuld be maintained t recrd installed sftware and sftware licences. Activities t ensure that the inventry is effectively maintained must be embedded brader SAM prcesses. Prcesses t cntrl and recrd changes t sftware assets shuld be embedded within the SAM system t ensure that an apprpriate audit is maintained. Prcesses t cntrl and recrd types, versins, OEM and utcmes f all applicatins deplyed acrss the enterprise t ensure redundancies in types f applicatins are effectively mnitred, managed and where apprpriate cllated. Prcesses t cntrl and recrd peratinal and technical requirements dependencies driving deplyment t map dependency f cmmissined ICT capabilities against the type and number f applicatins s deplyed, and where applicable, enterprise wide licence prtability, licence re-harvesting, active bslescence and eliminating redundancies acrss bth licence numbers and types. Cntrls shuld be established t detect and manage deviatins in SAM prcesses and ensure that accurate sftware asset recrds are maintained. Effective prcesses shuld be established t ensure that licensing terms are understd and there are regular licence recnciliatins perfrmed t verify that sftware is being used under the terms f the licence. Effective prcesses and cntrls shuld be established t prevent unauthrised installatin f sftware and detect any deviatins t the standard prcesses. NSW Gvernment aims t implement standards based n parts f the ISO/IEC standards hwever there is n requirement fr ISO certificatin. Deviatins frm the SAM system shuld be addressed. 17

18 Planning Prcurement Sftware Cntract Mnitring & reprting Sftware Asset Management Standard Operatins prcesses and interfaces Relatinship and cntract Effective prcesses and cntrls shuld be established t address relatinship and cntract fr SAM in line with crprate plicies and prcedures. Specific cnsideratins relating t effective relatinship and cntract fr SAM shuld be addressed thrugh: Identifying a relatinship wner fr each vendr relatinship Engaging with the apprpriate cmmercial authrity (as required) Ensuring that the terms f the licence are understd and cmplied with Vendr driven activities (e.g. true up, audit r maintenance / subscriptin renewals) are cmpleted in line with the terms f the licence Peridic frecasting f lng-term sftware requirements. Financial Service level Security Regular reprting f sftware related spend shuld be established. The requirements f the financial reprting must be determined by the rganisatin-wide financial practices. Service levels shuld be embedded within the SAM system t measure the effectiveness f the prcesses. Effective security cntrls shuld be established t ensure that access t the sftware asset inventries (physical and electrnic) is apprpriately restricted. 18

19 Sftware Asset Management Standard APPENDIX D REFERENCES Agencies shuld have regard t the fllwing statutes, NSW Gvernment plicies and standards: AS/NZS ISO Risk Principles and guidelines Cpyright Act 1968 Electrnic Transactins Act 2000 Gvernment Infrmatin (Infrmatin Cmmissiner) Act 2009 Gvernment Infrmatin (Public Access) Act 2009 Health Recrds and Infrmatin Privacy Act 2002 Infrmatin Technlgy Infrastructure Library (ITIL) v3 ISO/IEC Sftware Asset Management NSW Digital Infrmatin Security Plicy NSW Gvernment Clud Services Plicy and Guidelines NSW Gvernment Open Data Plicy NSW Gvernment ICT Strategy NSW Gvernment ICT Technical Standards Mbility Standard NSW Gvernment Digital Infrmatin Security Plicy NSW Gvernment ICT Strategy and Implementatin Update NSW Gvernment Infrmatin Classificatin and Labelling Guidelines NSW Prcurement: Small and Medium Enterprises Plicy Framewrk Privacy and Persnal Infrmatin Prtectin Act 1998 Public Finance and Audit Act 1983 Public Interest Disclsures Act 1994 State Recrds Act 1998 TPP Internal Audit and Risk Management Plicy fr the NSW Public Sectr 19

20 Sftware Asset Management Standard APPENDIX E STANDARDS Develping standards Develpment f a standard begins with identifying the need fr a new standard, which is fllwed by the develpment f the standard in cnsultatin with the industry and experts grups, including the Australian Infrmatin Industry Assciatin (AIIA). The fllwing diagram utlines the prcess. Need fr new r amended standard identified Business requirements change Standard develped (Industry/agencies cnsulted) Services added t Catalgue Standard apprved and released by PTS Wrking Grup Market engagement fr services which meet the standard The PTS Wrking Grup is chaired by the Office f Finance and Services and includes senir representatin frm acrss the NSW Gvernment clusters. Agencies engage with the PTS Wrking Grup cncerning services fr inclusin in the ICT Services Catalgue. This drives the develpment f technical standards, where nne exist. The PTS Wrking Grup has the leading rle in reviewing and endrsing the technical standards develped in respnse t agencies requirements. The PTS Wrking Grup is supprted by tw sub grups respnsible fr the areas f Telecmmunicatins and Services & Slutins. The sub-grups are respnsible fr initial develpment and review f standards relating t their areas f respnsibility. Management and implementatin There is scpe t mdify standards thrugh the NSW ICT gvernance arrangements as necessary. Standards are designed t add value, augment and be cmplementary t, ther guidance, and they are cntinually imprved and updated. This standard des nt affect r verride the respnsibilities f an agency r any emplyee regarding the and dispsal f infrmatin, data, and assets. Standards in ICT prcurement must als address business requirements fr service delivery. NSW Prcurement facilitates the implementatin f the standards by applying them t the gds and services made available thrugh the ICT Services Catalgue. Standards will als be available n the PrcurePint web site. 20

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT Plicy Number: 2.20 1. Authrity Lcal Gvernment Act 2009 Lcal Gvernment Regulatin 2012 AS/NZS ISO 31000-2009 Risk Management Principles

More information

Professional Leaders/Specialists

Professional Leaders/Specialists Psitin Prfile Psitin Lcatin Reprting t Jb family Band BI/Infrmatin Manager Wellingtn Prfessinal Leaders/Specialists Band I Date February 2013 1. POSITION PURPOSE The purpse f this psitin is t: Lead and

More information

LINCOLNSHIRE POLICE Policy Document

LINCOLNSHIRE POLICE Policy Document LINCOLNSHIRE POLICE Plicy Dcument 1. POLICY IDENTIFICATION PAGE POLICY TITLE: ICT CHANGE & RELEASE MANAGEMENT POLICY POLICY REFERENCE NO: PD 186 POLICY OWNERSHIP: ACPO Cmmissining Officer: Prtfli / Business-area

More information

Sources of Federal Government and Employee Information

Sources of Federal Government and Employee Information Inf Surce Surces f Federal Gvernment and Emplyee Infrmatin Ridley Terminals Inc. TABLE OF CONTENTS General Infrmatin Intrductin t Inf Surce Backgrund Respnsibilities Institutinal Functins, Prgram and Activities

More information

Internal Audit Charter and operating standards

Internal Audit Charter and operating standards Internal Audit Charter and perating standards 2 1 verview This dcument sets ut the basis fr internal audit: (i) the Internal Audit charter, which establishes the framewrk fr Internal Audit; and (ii) hw

More information

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013 Versin: Mdified By: Date: Apprved By: Date: 1.0 Michael Hawkins Octber 29, 2013 Dan Bwden Nvember 2013 Rule 4-004J Payment Card Industry (PCI) Patch Management (prpsed) 01.1 Purpse The purpse f the Patch

More information

Risk Management Policy AGL Energy Limited

Risk Management Policy AGL Energy Limited Risk Management Plicy AGL Energy Limited AUGUST 2014 Table f Cntents 1. Abut this Dcument... 2 2. Plicy Statement... 2 3. Purpse... 2 4. AGL Risk Cntext... 3 5. Scpe... 3 6. Objectives... 3 7. Accuntabilities...

More information

Version Date Comments / Changes 1.0 January 2015 Initial Policy Released

Version Date Comments / Changes 1.0 January 2015 Initial Policy Released Page 1 f 6 Vice President, Infrmatics and Transfrmatin Supprt APPROVED (S) REVISED / REVIEWED SUMMARY Versin Date Cmments / Changes 1.0 Initial Plicy Released INTENT / PURPOSE The Infrmatin and Data Gvernance

More information

CMS Eligibility Requirements Checklist for MSSP ACO Participation

CMS Eligibility Requirements Checklist for MSSP ACO Participation ATTACHMENT 1 CMS Eligibility Requirements Checklist fr MSSP ACO Participatin 1. General Eligibility Requirements ACO participants wrk tgether t manage and crdinate care fr Medicare fee-fr-service beneficiaries.

More information

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply Sectin 1 General Infrmatin RFR Number: (Reference BPO Number) Functinal Area (Enter One Only) F50B3400026 7 Infrmatin System Security Labr Categry A single supprt resurce may be engaged fr a perid nt t

More information

ENTERPRISE RISK MANAGEMENT ENTERPRISE RISK MANAGEMENT POLICY

ENTERPRISE RISK MANAGEMENT ENTERPRISE RISK MANAGEMENT POLICY ENTERPRISE RISK MANAGEMENT POLICY Plicy N. 10014 Review Date Octber 1, 2014 Effective Date March 1, 2014 Crss- Respnsibility Vice President, Reference Administratin Apprver Executive Cuncil 1. 1. Plicy

More information

CHANGE MANAGEMENT STANDARD

CHANGE MANAGEMENT STANDARD The electrnic versin is current, r when printed and stamped with the green cntrlled dcument stamp. All ther cpies are uncntrlled. DOCUMENT INFORMATION Descriptin Dcument Owner This standard utlines the

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Cntinuity Management Plicy Versin: 1.0 Last Amendment: Apprved by: Library Cuncil f New Suth Wales Plicy wner/spnsr: Directr, Operatins and Chief Financial Officer Plicy Cntact Officer: Senir

More information

Systems Support - Extended

Systems Support - Extended 1 General Overview This is a Service Level Agreement ( SLA ) between and the Enterprise Windws Services t dcument: The technlgy services the Enterprise Windws Services prvides t the custmer. The targets

More information

UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES

UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES REFERENCES AND RELATED POLICIES A. UC PPSM 2 -Definitin f Terms B. UC PPSM 12 -Nndiscriminatin in Emplyment C. UC PPSM 14 -Affirmative

More information

TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY

TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY REFERENCE NUMBER: 14/103368 RESPONSIBLE DEPARTMENT: Crprate Services APPLICABLE LEGISLATION: State Recrds Act 1997 Lcal Gvernment Act 1999 Crpratins Act

More information

Training - Quality Manual

Training - Quality Manual Training - Quality Manual 1 st Octber 2010 Babcck Internatinal Grup PLC www.babcck.c.uk/training Key Cntacts... Errr! Bkmark nt defined. Authrities...2 Intrductin t Babcck Internatinal Grup...3 Meeting

More information

Nuance Healthcare Services Project Delivery Methodology

Nuance Healthcare Services Project Delivery Methodology NUANCE PROFESSIONAL SERVICES Nuance Healthcare Services 2008 Nuance Cmmunicatins, Inc. All rights reserved. Nuance Healthcare Services 1 INTRODUCTION This dcument describes the prject management methdlgy

More information

Financial Accountability Handbook

Financial Accountability Handbook Financial Accuntability Handbk >> Vlume 5 Reprting Systems Infrmatin Sheet 5.2 Preparatin f Financial Statements Intrductin The Financial Accuntability Act 2009 (the Act) and the Financial and Perfrmance

More information

INFRASTRUCTURE TECHNICAL LEAD

INFRASTRUCTURE TECHNICAL LEAD 1. PURPOSE OF POSITION This psitin is respnsible fr the delivery f peratinal supprt and maintenance f the TDHB IT infrastructure envirnment. This rle is als pivtal in the develpment and delivery f infrastructure

More information

How To Write An Ehsms Training, Awareness And Competency Procedure

How To Write An Ehsms Training, Awareness And Competency Procedure Envirnmental, Health & Safety Management System (EHSMS) Dcument Number: 00122 Issue Date: 05/07/2014 Training, Awareness and Cmpetency Prcedure Revisin Number: 7 Prepared By: Stalcup, Bryce Apprved By:

More information

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Audit Cmmittee Charter St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Versin 2.0, 22 February 2016 Apprver Bard f Directrs St Andrew

More information

Security Services. Service Description Version 1.00. Effective Date: 07/01/2012. Purpose. Overview

Security Services. Service Description Version 1.00. Effective Date: 07/01/2012. Purpose. Overview Security Services Service Descriptin Versin 1.00 Effective Date: 07/01/2012 Purpse This Enterprise Service Descriptin is applicable t Security Services ffered by the MN.IT Services and described in the

More information

expertise hp services valupack consulting description security review service for Linux

expertise hp services valupack consulting description security review service for Linux expertise hp services valupack cnsulting descriptin security review service fr Linux Cpyright services prvided, infrmatin is prtected under cpyright by Hewlett-Packard Cmpany Unpublished Wrk -- ALL RIGHTS

More information

Presentation: The Demise of SAS 70 - What s Next?

Presentation: The Demise of SAS 70 - What s Next? Presentatin: The Demise f SAS 70 - What s Next? September 15, 2011 1 Presenters: Jeffrey Ziplw - Partner BlumShapir Jennifer Gerasimv Senir Manager Delitte. SAS 70 Backgrund and Overview Purpse f a SAS

More information

Waitemata District Health Board, 15 Shea Terrace, Takapuna

Waitemata District Health Board, 15 Shea Terrace, Takapuna Date: Octber 2015 Jb Title: Quality and Audit Manager Department: Planning, Funding and Outcmes Unit Lcatin: Waitemata District Health Bard, 15 Shea Terrace, Takapuna Reprting t: Directr Funding Direct

More information

VCU Payment Card Policy

VCU Payment Card Policy VCU Payment Card Plicy Plicy Type: Administrative Respnsible Office: Treasury Services Initial Plicy Apprved: 12/05/2013 Current Revisin Apprved: 12/05/2013 Plicy Statement and Purpse The purpse f this

More information

General Records Authority 33. Accredited Training

General Records Authority 33. Accredited Training General Recrds Authrity 33 2012/00579704 Accredited Training February 2013 This is an accurate reprductin f the authrised recrds authrity cntent, created fr accessibility purpses CONTENTS INTRODUCTION

More information

Major capital investment in councils. Good practice checklist for project managers

Major capital investment in councils. Good practice checklist for project managers Majr capital investment in cuncils checklist fr prject managers Prepared by Audit Sctland March 2013 b The Accunts Cmmissin The Accunts Cmmissin is a statutry, independent bdy which, thrugh the audit prcess,

More information

AUDIT AND RISK COMMITTEE TERMS OF REFERENCE

AUDIT AND RISK COMMITTEE TERMS OF REFERENCE AUDIT AND RISK COMMITTEE TERMS OF REFERENCE 1. TITLE OF COMMITTEE Audit and Risk Cmmittee 2. ESTABLISHMENT The Audit and Risk Cmmittee is established under Part 3 Sectin 19(1) f the Charles Darwin University

More information

BIBH Duty Statements and Governance chart reviewed and approved April 2014. BIBH Executive Governance & Management Arrangements

BIBH Duty Statements and Governance chart reviewed and approved April 2014. BIBH Executive Governance & Management Arrangements BIBH Duty Statements and Gvernance chart reviewed and apprved April 2014 BIBH Executive Gvernance & Management Arrangements BIBH COMMITTEE CEO - Paul O Cnnell Executive Secretary - Brian Firth Executive

More information

OFFICIAL JOB SPECIFICATION. Network Services Analyst. Network Services Team Manager

OFFICIAL JOB SPECIFICATION. Network Services Analyst. Network Services Team Manager JOB SPECIFICATION FUNCTION JOB TITLE REPORTING TO GRADE WORK PATTERN LOCATION IT & Digital Netwrk Services Analyst Netwrk Services Team Manager Band D Full-time Birmingham TRAVEL REQUIRED Occasinally ROLE

More information

This report provides Members with an update on of the financial performance of the Corporation s managed IS service contract with Agilisys Ltd.

This report provides Members with an update on of the financial performance of the Corporation s managed IS service contract with Agilisys Ltd. Cmmittee: Date(s): Infrmatin Systems Sub Cmmittee 11 th March 2015 Subject: Agilisys Managed Service Financial Reprt Reprt f: Chamberlain Summary Public Fr Infrmatin This reprt prvides Members with an

More information

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS SERIES: 1 General Rules RULE: 17.1 Recrd Retentin Scpe: The purpse f this rule is t establish the systematic review, retentin and destructin

More information

IT CONTROL ENVIRONMENT ASSESSMENT AND RECOMMENDATIONS REPORT

IT CONTROL ENVIRONMENT ASSESSMENT AND RECOMMENDATIONS REPORT Chairpersn and Subcmmittee Members AUDIT AND RISK SUBCOMMITTEE 6 AUGUST 2015 Meeting Status: Public Purpse f Reprt: Fr Infrmatin IT CONTROL ENVIRONMENT ASSESSMENT AND RECOMMENDATIONS REPORT PURPOSE OF

More information

POSITION NUMBER: LOCATION: Vancouver. DATE: February 2009

POSITION NUMBER: LOCATION: Vancouver. DATE: February 2009 POSITION TITLE: Team Lead Service Centre DIVISION/BRANCH: IS/IT CURRENT CLASSIFICATION LEVEL: IS27 SUPERVISOR S POSITION NUMBER POSITION NUMBER: LOCATION: Vancuver DATE: February 2009 SUPERVISOR S TITLE/CLASSIFICATION:

More information

Agenda. o Purpose of IT Assessment o Scope of IT Assessment o Deloitte Recommendations o IBM Discussions o Research Data Center o Open Season

Agenda. o Purpose of IT Assessment o Scope of IT Assessment o Deloitte Recommendations o IBM Discussions o Research Data Center o Open Season Agenda Purpse f IT Assessment Scpe f IT Assessment Delitte Recmmendatins IBM Discussins Research Data Center Open Seasn Purpse f IT Assessment Determine if IT resurces are being utilized efficiently and

More information

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014 State f Michigan POLICY 1390 Infrmatin Technlgy Cntinuity f Business Planning Issued: June 4, 2009 Revised: June 12, 2014 SUBJECT: APPLICATION: PURPOSE: CONTACT AGENCY: Plicy fr Infrmatin Technlgy (IT)

More information

Health Stream Portfolio (e.g. Mental health, drug & alcohol) and Contract of Employment

Health Stream Portfolio (e.g. Mental health, drug & alcohol) and Contract of Employment Psitin Descriptin Psitin Agency Reprts t Terms and Cnditins f Emplyment Classificatin/ Salary Stream Length f Psitin Lcatin Health Stream Lead Health Stream Prtfli (e.g. Mental health, drug & alchl) Primary

More information

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments University f Texas at Dallas Plicy fr Accepting Credit Card and Electrnic Payments Cntents: Purpse Applicability Plicy Statement Respnsibilities f a Merchant Department Prcess t Becme a Merchant Department

More information

Change Management Process

Change Management Process Change Management Prcess B1.10 Change Management Prcess 1. Intrductin This plicy utlines [Yur Cmpany] s apprach t managing change within the rganisatin. All changes in strategy, activities and prcesses

More information

Job Profile Data & Reporting Analyst (Grant Fund)

Job Profile Data & Reporting Analyst (Grant Fund) Jb Prfile Data & Reprting Analyst (Grant Fund) Directrate Lcatin Reprts t Hurs Finance Slihull Finance Directr Nminally 37 hurs but peratinally available at all times t meet Cmpany requirements Cntract

More information

Service Level Agreement in IBM T Clud - ITAP

Service Level Agreement in IBM T Clud - ITAP G-Clud Lt 4: Specialist Clud Services Service Definitin 100 Lngwater Avenue Green Park Reading Berkshire RG2 6GP Tel: 0118 9213 510 Email: gclud@dssec.c.uk Website: www.dssec.c.uk Intrductin Thank yu fr

More information

Personal Data Security Breach Management Policy

Personal Data Security Breach Management Policy Persnal Data Security Breach Management Plicy 1.0 Purpse The Data Prtectin Acts 1988 and 2003 impse bligatins n data cntrllers in Western Care Assciatin t prcess persnal data entrusted t them in a manner

More information

Implementing an electronic document and records management system using SharePoint 7

Implementing an electronic document and records management system using SharePoint 7 Reprt title Agenda item Implementing an electrnic dcument and recrds management system using SharePint 7 Meeting Finance, Prcurement & Prperty Cmmittee 16 June 2008 Date Reprt by Dcument Number Head f

More information

POSITION DESCRIPTION. Classification Higher Education Worker, Level 7. Responsible to. I.T Manager. The Position

POSITION DESCRIPTION. Classification Higher Education Worker, Level 7. Responsible to. I.T Manager. The Position Psitin Title I.T Prject Officer Classificatin Higher Educatin Wrker, Level 7 Respnsible t The Psitin I.T Manager The psitin assists with the cmpletin f varius IT prjects intended t enable the nging administratin

More information

ITIL Release Control & Validation (RCV) Certification Program - 5 Days

ITIL Release Control & Validation (RCV) Certification Program - 5 Days ITIL Release Cntrl & Validatin (RCV) Certificatin Prgram - 5 Days Prgram Overview ITIL is a set f best practices guidance that has becme a wrldwide-adpted framewrk fr Infrmatin Technlgy Services Management

More information

A96 CALA Policy on the use of Computers in Accredited Laboratories Revision 1.5 August 4, 2015

A96 CALA Policy on the use of Computers in Accredited Laboratories Revision 1.5 August 4, 2015 A96 CALA Plicy n the use f Cmputers in Accredited Labratries Revisin 1.5 August 4, 2015 A96 CALA Plicy n the use f Cmputers in Accredited Labratries TABLE OF CONTENTS TABLE OF CONTENTS... 1 CALA POLICY

More information

CDC UNIFIED PROCESS PRACTICES GUIDE

CDC UNIFIED PROCESS PRACTICES GUIDE Dcument Purpse The purpse f this dcument is t prvide guidance n the practice f Business Case and t describe the practice verview, requirements, best practices, activities, and key terms related t these

More information

ITIL Service Offerings & Agreement (SOA) Certification Program - 5 Days

ITIL Service Offerings & Agreement (SOA) Certification Program - 5 Days ITIL Service Offerings & Agreement (SOA) Certificatin Prgram - 5 Days Prgram Overview ITIL is a set f best practices guidance that has becme a wrldwide-adpted framewrk fr Infrmatin Technlgy Services Management

More information

Service Level Agreement (SLA) Hosted Products. Netop Business Solutions A/S

Service Level Agreement (SLA) Hosted Products. Netop Business Solutions A/S Service Level Agreement (SLA) Hsted Prducts Netp Business Slutins A/S Cntents 1 Service Level Agreement... 3 2 Supprt Services... 3 3 Incident Management... 3 3.1 Requesting service r submitting incidents...

More information

SERVICE DESK TEAM LEADER

SERVICE DESK TEAM LEADER 1. PURPOSE OF POSITION The Service Desk Team Leader rle is respnsible fr managing the peratin f the Service Desk. This rle is crucial t ensuring custmer requirements are met in terms f cmmunicatin, priritising,

More information

Data Warehouse Scope Recommendations

Data Warehouse Scope Recommendations Rensselaer Data Warehuse Prject http://www.rpi.edu/datawarehuse Financial Analysis Scpe and Data Audits This dcument describes the scpe f the Financial Analysis data mart scheduled fr delivery in July

More information

Audit Committee Charter

Audit Committee Charter Audit Cmmittee Charter Membership The Audit Cmmittee (the "Cmmittee") f the Bard f Directrs (the "Bard") f Philip Mrris Internatinal Inc. (the "Cmpany") shall cnsist f at least three directrs all f whm

More information

Human Resources Policy pol-020

Human Resources Policy pol-020 Human Resurces Plicy pl-020 Versin: 2.00 Last amendment: Jul 2014 Next Review: Jul 2017 Apprved By: Cuncil Date: 04 May 2005 Cntact Officer: Directr, Office f Human Resurce Services INTRODUCTION The University

More information

GUIDELINE INFORMATION MANAGEMENT (IM) PROGRAM PLAN

GUIDELINE INFORMATION MANAGEMENT (IM) PROGRAM PLAN Gvernment f Newfundland and Labradr Office f the Chief Infrmatin Officer Infrmatin Management Branch GUIDELINE INFORMATION MANAGEMENT (IM) PROGRAM PLAN Guideline (Definitin): OCIO Guidelines derive frm

More information

17 Construction environmental management plan (CEMP)

17 Construction environmental management plan (CEMP) 17 Cnstructin envirnmental management plan (CEMP) Bur Happld Cntents 17 Cnstructin Envirnmental Management Plan (CEMP) 17-1 17.1 Intrductin 17-1 17.2 Intrductin t EMS 17-1 17.2.1 Plicy 17-2 17.2.2 Planning

More information

Business Continuity Management Systems Foundation Training Course

Business Continuity Management Systems Foundation Training Course Certificatin criteria fr Business Cntinuity Management Systems Fundatin Training Curse CONTENTS 1. INTRODUCTION 2. LEARNING OBJECTIVES 3. ENABLING OBJECTIVES KNOWLEDGE & SKILLS 4. TRAINING METHODS 5. COURSE

More information

BRISTOL CITY COUNCIL ROLE AND EMPLOYEE PROFILE: Architect (Practitioner Level) Specific Role Data Architect

BRISTOL CITY COUNCIL ROLE AND EMPLOYEE PROFILE: Architect (Practitioner Level) Specific Role Data Architect BRISTOL CITY COUNCIL ROLE AND EMPLOYEE PROFILE: Architect (Practitiner Level) Specific Rle Data Architect Grade Directrate Managed by BG13 (TBC) Business Change Senir Infrmatin Systems & Technlgy Architect

More information

HP ValuPack Consulting Description OpenVMS Engineering Change Order (ECO) Patch List

HP ValuPack Consulting Description OpenVMS Engineering Change Order (ECO) Patch List HP ValuPack Cnsulting Descriptin OpenVMS Engineering Change Order (ECO) Patch List HP ValuPacks are standardized cnsulting services, prvided by HP Slutin Center Service Prfessinals, with pre-defined custm

More information

Change Management Process For [Project Name]

Change Management Process For [Project Name] Management Prcess Fr [Prject Name] i 1 Intrductin The is fllwed during the Executin phase f the Prject Management Life Cycle, nce the prject has been frmally defined and planned. 1.1 What is a Management

More information

Electronic and Information Resources Accessibility Compliance Plan

Electronic and Information Resources Accessibility Compliance Plan Electrnic and Infrmatin Resurces Accessibility Cmpliance Plan Intrductin The University f Nrth Texas at Dallas (UNTD) is cmmitted t prviding a wrk envirnment that affrds equal access and pprtunity t therwise

More information

Mobile Telecom Expense Management

Mobile Telecom Expense Management Mbile Telecm Expense Management Quick Start Mbile Telecm Expense Management Intrductin The BT Mbile Telecm Expense Management Quick Start Service is part BT Managed Mbility Expenses* BT s suite f telecm

More information

Chief Finance and Operations Officer IfM Education and Consultancy Services (IfM ECS)

Chief Finance and Operations Officer IfM Education and Consultancy Services (IfM ECS) Chief Finance and Operatins Officer IfM Educatin and Cnsultancy Services (IfM ECS) Rle Summary IfM ECS disseminates the research and educatin utputs f the University f Cambridge Institute fr Manufacturing

More information

The Importance Advanced Data Collection System Maintenance. Berry Drijsen Global Service Business Manager. knowledge to shape your future

The Importance Advanced Data Collection System Maintenance. Berry Drijsen Global Service Business Manager. knowledge to shape your future The Imprtance Advanced Data Cllectin System Maintenance Berry Drijsen Glbal Service Business Manager WHITE PAPER knwledge t shape yur future The Imprtance Advanced Data Cllectin System Maintenance Cntents

More information

In-House Counsel Day Priorities for 2012. Cloud Computing the benefits, potential risks and security for the future

In-House Counsel Day Priorities for 2012. Cloud Computing the benefits, potential risks and security for the future In-Huse Cunsel Day Pririties fr 2012 Clud Cmputing the benefits, ptential risks and security fr the future Presented by David Richardsn Thursday 1 March 2012 WIN: What in-huse lawyers need Knwledge, supprt

More information

The actions discussed below in this Appendix assume that the firm has already taken three foundation steps:

The actions discussed below in this Appendix assume that the firm has already taken three foundation steps: MAKING YOUR MARK 6.1 Gd Practice This sectin presents an example f gd practice fr firms executing plans t enter the resurces sectr supply chain fr the first time, r fr thse firms already in the supply

More information

ISMF Standard 141 Endpoint Protection. OCIO/S4.6 Government standard on cyber security

ISMF Standard 141 Endpoint Protection. OCIO/S4.6 Government standard on cyber security ISMF Standard 141 OCIO/S4.6 Gvernment standard n cyber security Prepared by: Office f the Chief Infrmatin Officer Versin: v1.0 Date: 12 September 2014 GOVERNMENT STANDARD ON CYBER SECURITY OCIO/S4.6 Cnfidentiality:

More information

Research Report. Abstract: The Emerging Intersection Between Big Data and Security Analytics. November 2012

Research Report. Abstract: The Emerging Intersection Between Big Data and Security Analytics. November 2012 Research Reprt Abstract: The Emerging Intersectin Between Big Data and Security Analytics By Jn Oltsik, Senir Principal Analyst With Jennifer Gahm Nvember 2012 2012 by The Enterprise Strategy Grup, Inc.

More information

Delivering Business Value Through IT Cost Transparency Using IT CMF

Delivering Business Value Through IT Cost Transparency Using IT CMF Office f the CIO Delivering Business Value Thrugh IT Cst Transparency Using IT CMF Sharad Jshi Vice President, IT Business Management March 24 th, 2015 Abut the Depsitry Trust and Clearing Crpratin (DTCC)

More information

HEALTH INFORMATION EXCHANGE GRANTS CRITERIA

HEALTH INFORMATION EXCHANGE GRANTS CRITERIA 1 HEALTH INFORMATION EXCHANGE GRANTS CRITERIA INTRODUCTION On August, 20 th, the federal Office f the Natinal Crdinatr fr Health Infrmatin Technlgy (ONC) released an pprtunity fr states t apply fr between

More information

State of California California Technology Agency. Software Management Plan Guidelines

State of California California Technology Agency. Software Management Plan Guidelines State f Califrnia Califrnia Technlgy Agency Sftware Management Plan Guidelines Revised April 2011 Sectin 1 1.0 Overview INTRODUCTION TO SOFTWARE MANAGEMENT PLANNING The State Administrative Manual (SAM)

More information

THIRD PARTY PROCUREMENT PROCEDURES

THIRD PARTY PROCUREMENT PROCEDURES ADDENDUM #1 THIRD PARTY PROCUREMENT PROCEDURES NORTH CENTRAL TEXAS COUNCIL OF GOVERNMENTS TRANSPORTATION DEPARTMENT JUNE 2011 OVERVIEW These prcedures establish standards and guidelines fr the Nrth Central

More information

Environment Protection Authority

Environment Protection Authority Envirnment Prtectin Authrity EPA Cmplaints Management Plicy Intrductin This plicy sets ut the purpse, principles and prcess fr hw custmer feedback, including cmplaints, will be managed in the EPA t imprve

More information

South Australia Police POSITION INFORMATION DOCUMENT

South Australia Police POSITION INFORMATION DOCUMENT Suth Australia Plice POSITION INFORMATION DOCUMENT Stream: Career Grup: Discipline: Classificatin: Service: Branch: Psitin Title: Administrative Services Cnsultancy and Infrmatin AO ASO-6 Infrmatin Systems

More information

Basics of Supply Chain Management

Basics of Supply Chain Management The Champlain Valley APICS Chapter is a premier prfessinal assciatin fr supply chain and peratins management and wrking tgether with the APICS rganizatin the leading prvider f research, educatin and certificatin

More information

NHVAS Mass Management Spot Check Checklist

NHVAS Mass Management Spot Check Checklist Legal Entity Name f NHVAS Operatr: DTMR Representative: Lcatin: NHVAS Mass Management Spt Check Checklist Spt Check Date: Spt Check Number: DMS Number: 540/ The fllwing surces f evidence have been identified

More information

Software and Hardware Change Management Policy for CDes Computer Labs

Software and Hardware Change Management Policy for CDes Computer Labs Sftware and Hardware Change Management Plicy fr CDes Cmputer Labs Overview The cmputer labs in the Cllege f Design are clsely integrated with the academic needs f faculty and students. Cmputer lab resurces

More information

Zimbra Professional Services Portfolio, Purchasing Guide & Price List

Zimbra Professional Services Portfolio, Purchasing Guide & Price List In- Tuitin Netwrks Ltd Zimbra Prfessinal Services Prtfli, Purchasing Guide & Price List This dcument prvides an verview f In- Tuitin Netwrks Limited s range f Zimbra Prfessinal Services available n the

More information

Finance, Performance and Risk Committee 2014/2015

Finance, Performance and Risk Committee 2014/2015 Finance, Perfrmance and Risk Cmmittee 2014/2015 Date f Meeting: 17 December 2014 Agenda Item: Click here t enter text. Subject: Infrmatin Gvernance Plicy Reprting Officer: Paul Byrne Lead IG Manager Aim

More information

Christchurch Polytechnic Institute of Technology Access Control Security Standard

Christchurch Polytechnic Institute of Technology Access Control Security Standard CPIT Crprate Services Divisin: ICT Christchurch Plytechnic Institute f Technlgy Access Cntrl Security Standard Crprate Plicies & Prcedures Sectin 1: General Administratin Dcument CPP121a Principles Infrmatin

More information

WHAT YOU NEED TO KNOW ABOUT. Protecting your Privacy

WHAT YOU NEED TO KNOW ABOUT. Protecting your Privacy WHAT YOU NEED TO KNOW ABOUT Prtecting yur Privacy YOUR PRIVACY IS OUR PRIORITY Credit unins have a histry f respecting the privacy f ur members and custmers. Yur Bard f Directrs has adpted the Credit Unin

More information

VACANCY. SENIOR MANAGER: SPECIAL PROJECTS AND STAKEHOLDER MANAGEMENT x1 3 YEAR CONTRACT (WITH A POSSIBILITY OF BEING EXTENDED TO 5 YEARS) JOB LEVEL: 5

VACANCY. SENIOR MANAGER: SPECIAL PROJECTS AND STAKEHOLDER MANAGEMENT x1 3 YEAR CONTRACT (WITH A POSSIBILITY OF BEING EXTENDED TO 5 YEARS) JOB LEVEL: 5 VACANCY POSITION: DURATION REGION: PORTFOLIO: SENIOR MANAGER: SPECIAL PROJECTS AND STAKEHOLDER MANAGEMENT x1 3 YEAR CONTRACT (WITH A POSSIBILITY OF BEING EXTENDED TO 5 YEARS) NATIONAL OFFICE OCEO JOB LEVEL:

More information

SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM

SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM Audit Manual Sectin J SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM Ref. Plicy and Practice Requirements IIA Standards and Other references J 1 Plicy: The Head f Internal Audit shall develp and maintain

More information

Information Services Hosting Arrangements

Information Services Hosting Arrangements Infrmatin Services Hsting Arrangements Purpse The purpse f this service is t prvide secure, supprted, and reasnably accessible cmputing envirnments fr departments at DePaul that are in need f server-based

More information

Privacy Policy. The Central Equity Group understands how highly people value the protection of their privacy.

Privacy Policy. The Central Equity Group understands how highly people value the protection of their privacy. Privacy Plicy The Central Equity Grup understands hw highly peple value the prtectin f their privacy. Fr that reasn, the Central Equity Grup takes particular care in dealing with any persnal and sensitive

More information

Better Practice Guide Financial Considerations for Government use of Cloud Computing

Better Practice Guide Financial Considerations for Government use of Cloud Computing Better Practice Guide Financial Cnsideratins fr Gvernment use f Clud Cmputing Nvember 2011 Intrductin Many Australian Gvernment agencies are in the prcess f cnsidering the adptin f clud-based slutins.

More information

Solution. Industry. Challenges. Client Case Study. Legacy Systems too Costly to Maintain. Supply Chain Advantage. Delivered.

Solution. Industry. Challenges. Client Case Study. Legacy Systems too Costly to Maintain. Supply Chain Advantage. Delivered. Supply Chain Advantage. Delivered. Client Case Study MEBC Supprts the Federal Aviatin Administratin Manage Prject Risk during Majr ERP Implementatin thrugh Independent Verificatin and Validatin (IV&V)

More information

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy COPIES-F.Y.I., INC. Plicies and Prcedures Data Security Plicy Page 2 f 7 Preamble Mst f Cpies FYI, Incrprated financial, administrative, research, and clinical systems are accessible thrugh the campus

More information

Represent New College Stamford at both national and regional events and serve on appropriate external committees.

Represent New College Stamford at both national and regional events and serve on appropriate external committees. JOB DESCRIPTION Pst: Reprts t: Respnsible fr: Executive Directr Partnerships & Skills Principal and Chief Executive Apprenticeship Develpment Manager Head f Marketing Business Sales Team Salary: Attractive

More information

Chapter 7 Business Continuity and Risk Management

Chapter 7 Business Continuity and Risk Management Chapter 7 Business Cntinuity and Risk Management Sectin 01 Business Cntinuity Management 070101 Initiating the Business Cntinuity Plan (BCP) Purpse: T establish the apprpriate level f business cntinuity

More information

FINANCIAL SERVICES FLASH REPORT

FINANCIAL SERVICES FLASH REPORT FINANCIAL SERVICES FLASH REPORT Draft Regulatry Cmpliance Management Guideline Released by the Office f the Superintendent f Financial Institutins May 5, 2014 On April 30, 2014, the Office f the Superintendent

More information

Army DCIPS Employee Self-Report of Accomplishments Overview Revised July 2012

Army DCIPS Employee Self-Report of Accomplishments Overview Revised July 2012 Army DCIPS Emplyee Self-Reprt f Accmplishments Overview Revised July 2012 Table f Cntents Self-Reprt f Accmplishments Overview... 3 Understanding the Emplyee Self-Reprt f Accmplishments... 3 Thinking Abut

More information

G-CLOUD FRAMEWORK SERVICE DEFINITION. Solution Architecture for Cloud Service. Copyright: 2014 6point6 Ltd

G-CLOUD FRAMEWORK SERVICE DEFINITION. Solution Architecture for Cloud Service. Copyright: 2014 6point6 Ltd G-CLOUD FRAMEWORK SERVICE DEFINITION Slutin Architecture fr Clud Service Cpyright: 2014 6pint6 Ltd G-Clud Service Definitin Slutin Architecture fr Clud Service 1. SERVICE OVERVIEW 6pint6 is an innvative

More information

Business Plan 2014-15

Business Plan 2014-15 Cmmissin fr Lcal Administratin in England Business Plan 2014-15 All Business Plan activity is linked t ur fur Strategic Objectives LGO Business Plan 2014-2015 v web 3 Page 1 descriptin 1. Prvide a cmplaints

More information

Licensing the Core Client Access License (CAL) Suite and Enterprise CAL Suite

Licensing the Core Client Access License (CAL) Suite and Enterprise CAL Suite Vlume Licensing brief Licensing the Cre Client Access License (CAL) Suite and Enterprise CAL Suite Table f Cntents This brief applies t all Micrsft Vlume Licensing prgrams. Summary... 1 What s New in This

More information

Symantec User Authentication Service Level Agreement

Symantec User Authentication Service Level Agreement Symantec User Authenticatin Service Level Agreement Overview and Scpe This Symantec User Authenticatin service level agreement ( SLA ) applies t Symantec User Authenticatin prducts/services, such as Managed

More information

Guidelines on Data Management in Horizon 2020

Guidelines on Data Management in Horizon 2020 Guidelines n Data Management in Hrizn 2020 Versin 1.0 11 December 2013 Guidelines n Data Management in Hrizn 2020 Versin 16 December 2013 Intrductin In Hrizn 2020 a limited pilt actin n pen access t research

More information

Gravesham Borough Council

Gravesham Borough Council Classificatin: Part 1 Public Key Decisin: Please specify - N Gravesham Brugh Cuncil Reprt t: Perfrmance and Administratin Cmmittee Date: 12 Nvember 2015 Reprting fficer: Subject: Crprate Perfrmance Manager

More information