Towards a Reference Model for Integrated Governance, Risk and Compliance
|
|
|
- Rachel Walters
- 10 years ago
- Views:
Transcription
1 Towards a Reference Model for Integrated Governance, Risk and Compliance Pedro Vicente 1, Nicolas Racz 2 and Miguel Mira da Silva 1 1 Instituto Superior Técnico, Universidade Técnica de Lisboa, Avenida Rovisco Pais, 1, Lisboa, Portugal {pedro.vicente,mms}@ist.utl.pt 2 TU Vienna, Institute for Software Technology and Interactive Systems, Favoritenstr. 9-11, 1040, Vienna, Austria [email protected] Abstract. More regulations are on the way, along with demanding transparency, accurate information about company operations, robust and comprehensive risk management, regulatory compliance and efficient governance. Consequently, organizations are seeking to improve their GRC activities, by implementing integrated GRC solutions that provide a holistic view of the organization and help in the automation of activities. After analysing and researching the emerging domain of integrated GRC, the lack of references that provide guidance to organizations in the implementation and optimization of processes, activities and information is an alarming issue. In this paper we propose a reference model for GRC, combining two architectural layers - Business and Information Systems - modelled with ArchiMate. The reference model is presented and described through several viewpoints. We then apply a framework to evaluate the quality of the reference model and discuss the obtained results. Keywords: GRC, reference model, integrated, archimate, information systems architecture 1 Introduction The myriad of activities, processes and behaviours that lay on the Governance, Risk and Compliance (GRC) domain can be overwhelming. Although each area is well defined separately, the integration of the three areas is known to be a major challenge, since they became truly complex [1]. Traditional siloed GRC activities reinforced decreasing transparency, and hence governance agility, impacting effectiveness of decision making [2]. To better address GRC requirements such as internal policies, external regulations and risks, a holistic view of the organizations is needed to enhance efficiency and effectiveness. This view can be accomplished by integrating certain processes and activities that are common across the GRC functions, such as risk assessments, or functions that work better together, such as agreeing on the
2 most significant risks or compiling one consensus list of the most critical open issues across the GRC units. Also, by better sharing knowledge, data and technology, a collaborative culture in organizations is enhanced. The ultimate goal is to identify, integrate and optimize processes and activities that are common across the GRC domain. Vendors and organizations all agree on the paramount importance of GRC activities and the significance of taking an integrated and holistic view of these activities, not only from an internal perspective, but also from an outward perspective. However, asking organizations to define or describe governance, risk and compliance, is getting very distinct definitions [3, 4]. There are probably as many definitions of GRC as there are companies that provide technology or professional services to address GRC challenges [5]. The absence of references for integrated GRC is alarming. A study performed by Racz et al. showed that vendors perceptions of GRC functionalities are diverse and present a low degree of congruence [6]. This study also showed that the scope of the existing market research GRC frameworks (AMR, Forrester and Gartner) varies enormously. Additionally, technology architectures differ in their degree of integration. Nonetheless, vendors and organizations strongly agree on the benefits delivered through integrated GRC suites. Disagreements and inconsistencies between vendors and organizations are not positive, but it is not an abnormal circumstance. The more alarming issue is the absence of scientific research on GRC as an integrated concept, in a market that is controlled by vendors, analysts and consultancies [7]. Thus, the incongruence in this domain increased considerably and organizations may not be taking full advantage of integrated GRC systems. Much of the problem about GRC is a lack of standardized guidance [4]. A complete reference for the GRC domain is missing; mainly, the need for a reference, non-market-driven, is paramount to make progress in this domain. To address this set of problems, the ultimate goal of our research is to develop a reference model for integrated GRC, representing an architecture with a main focus on the context of Information Systems and aligned with processes. In this paper we present part of our research, focusing on the information systems architectural layer. A reference architecture can be seen as a specialization of a reference model. A reference model is a generic abstract representation for understanding the entities and their significant relationships in a defined domain; it defines a common basis for understanding and explaining (at least at a high level of abstraction) the different manifestations of the paradigm [8]. In this specific case, a reference architecture can help organizations develop and optimise their information management systems that may be more suitable than standard GRC solutions [9]. In order to facilitate this understanding, we use an independent and well-accepted modelling language - ArchiMate - to represent the architecture. Architecture is positioned between business and IT [10], and in the GRC domain the gap between business and IT is a major concern since vendors are very focused on standard technological solutions and business knowledge is frag-
3 mented and inconsistent [3, 4]. Having said this, a complete architecture definition is paramount to align and serve both business and IT. 2 Research Methodology During this research we used the Design Science Research (DSR) methodology, based on a continuous build and evaluate cycle. Our research began with the analysis and selection of GRC artefacts present in the knowledge base of the domain (Fig. 1). We opted for scientific research that addressed GRC as an integrated topic. The chosen reference was a business process viewpoint, based on several valid reasons. First, the viewpoint is based on the combination of two models that address integrated GRC (a process model [11] and a conceptual model [12]. Additionally, the viewpoint was designed using the ArchiMate modelling language - that we have chosen to use in this paper. Moreover, a business process viewpoint is a central piece in the business layer, and can be very useful to develop the subsequent layer (information systems architecture). Finally, the design by reuse is a well accepted practice in DSR consisting in adapting and/or extending them to create one or more artefacts [13]. Figure 1 represents the stages conducted throughout this research. Fig. 1. Research Methodology
4 The information objects from the business viewpoint were separated from the processes in order to construct an information structure. Using information objects and processes, application components were identified. Additionally, the application services realized by these components and used by the processes were identified. We also mapped the relations between application components through sharing of information and services. Finally, we evaluated all the viewpoints (or artefacts) using the data model quality framework from Moody and Shanks [14]. 3 Theoretical Background 3.1 ArchiMate A high-level modelling language is needed to describe the architecture. Archi- Mate represents a standard language and vendor-independent concepts [15]. The architectural layers used in this paper are the business and application layers. The selected concepts from ArchiMate are present in Fig. 2. We also highlighted the viewpoints described in this research. Viewpoints define abstractions on the set of models representing the enterprise architecture, each aimed at particular set of concerns [16]. We will use viewpoints to represent the concepts in isolation, and for relating two or more concepts. Fig. 2. Selected concepts and viewpoint examples from ArchiMate [16] Each concept has its meaning. Business processes describe the internal behaviour that is required to achieve certain objectives. A business object is defined
5 as a unit of information that has relevance from a business perspective. A data object is defined as a coherent, self-contained piece of information suitable for automated processing. An application service is defined as an externally visible unit of functionality. An application component is defined as a modular, deployable, and replaceable part of a system. It performs one or more application functions. 4 Reference Model In this Section we present our proposed reference model that encompasses concepts from both business and information systems architecture. Following the selected viewpoints presented in the previous Section we will start by using and complementing the business process viewpoint [17], followed by the information structure, application usage and application structure viewpoints. 4.1 Business Process Viewpoint The business process viewpoint is used to show the relations of one or more business processes with each other and/or their surroundings. In this case it is used to create a high-level design of business processes within their context and to describe the use of shared information [16]. A business process viewpoint [17] (see Fig. 3) has already been developed through the combination of two models from the knowledge base of this domain: a conceptual model for GRC [12] and a process model for ITGRC [11]. Although the viewpoint was developed for a particular domain of GRC - ITGRC - it is applicable for the overall enterprise GRC. A point in favour lies with the fact that the viewpoint is already modelled using the ArchiMate structure. However, the viewpoint presented in Fig. 3 was modified and some business objects were added and removed. The Reporting process was extended through the three macro processes of governance, risk and compliance. This viewpoint is crucial for the development of the remaining viewpoints. It presents an important baseline for defining business objects and the necessary applications to support the processes. 4.2 Information Structure Viewpoint The information structure viewpoint is identical to the traditional information models created in the development of almost any information system. It shows the structure of the information used in the enterprise or in a specific business process or application [16]. This viewpoint aggregates concepts from both the business and application layer. Given the abstraction chosen for this research there is no practical distinction between data and business objects. The objects presented in Fig. 4 represent
6 Fig. 3. Integrated GRC - Business Process Viewpoint adapted from [17] business objects that can be seen as information entities or concepts that are necessary to support the business. A description of the viewpoint follows; Policies may encompass a wide range of aspects of an organization. Internal policies reflect key objectives, strategy, risk appetite, culture, etc. of an organization. External policies are linked with external requirements - regulations, laws or standards. While policies define the what, procedures define the how and who will implement the policy. Policies and procedures are, in a certain extent, controls established to ensure the fulfilment of requirements and achievement of strategic objectives [18]. To each control, control objectives are defined and embedded in business processes. Usually controls are established to mitigate risks that menace the achievement of objectives or affect the normal function of business processes [18]. To business processes and risks, key performance and key risk indicators are developed to measure the
7 Fig. 4. Information Structure Viewpoint performance of processes and the risk levels of certain activities. Risk reports are produced regularly and presented to the board. Maturity criteria may be defined to measure the maturity level of controls. Normally auditors classify controls using this pre-defined criteria (e.g. COBIT maturity model, pass/fail criteria, etc.). Additionally, control tests may be specified to increase efficiency in controls assessments. During the execution of audits, audit findings are produced (a specific type of issues), along with evidences that prove it. Surveys and checklists are also associated with audits. For each audit, audit reports are produced, and include all the identified inconsistencies and the associated recommendation. 4.3 Application Usage Viewpoint The application usage viewpoint describes how applications are used to support one or more business processes. It can be used in designing an application by identifying the services needed by business processes [16]. This viewpoint also presents itself as the connection between the business and information systems architectural layers. To establish this connection some other concepts need to be defined - application services and components. In order to define consistently the necessary applications to support the processes, we present a CRUD (Create Read Update Delete) matrix (see Fig. 5) that relates processes (or actions) with informational entities described below.
8 CRUD Matrix This matrix was built in order to identify clusters that represent application solutions. The relation between processes and information entities provides a more structured approach to the identification of application components and services needed to support the processes. We opted not to include all information entities in order to simplify the matrix. For example, the entity Report represents all type of reports - audit, risk and compliance. Additionally, the entity Requirement aggregates the entities Law, Standard and Regulation. The same applies to the Policy entity. Fig. 5. CRUD Matrix Fig. 6. Application Components
9 Through the analysis of the obtained clusters (see Fig. 5) some optimization could be suggested by integrating some systems. For example, issue and risk management are very similar, but they manage information entities that are, by definition, distinct, so we opted to maintain both. The integration between applications was explicitly represented in the form of arrows. The matrix also came to support the expansion of both reporting and monitoring processes across Governance, Risk and Compliance proposed in Fig. 3, because the processes manage the same information. In Fig. 6 the proposed application components are listed. Some applications match some references [6, 12]. With all the necessary components defined, the application usage viewpoint can be described. In this viewpoint (see Fig. 7) we chose to maintain the original processes, i.e. not expanding the monitor and report processes through the governance, risk and compliance processes, in order to simplify the viewpoint. Fig. 7. Application Usage Viewpoint
10 According to the ISO/IEC38500 [19], the Direct process is based on the assignment of responsibilities, direct preparation and implementations of policies. In order to support this process, a Policy Life Cycle Service should be defined to support all actions needed to manage policies across the organization. On the other hand, the Evaluate process is based on the current and future organizational objectives, thus the service provided by the risk management application - Risk appetite calculation service - is an important method to evaluate the readiness of the organization to apply new strategies and proposals. An automated monitoring service should also be present to support the monitoring process of governance and risk management. During this research, we defined an event as a risk or an issue. Following the same line of thought, the Event Identification process, uses two separate application services from two different application components, but with the same behaviour: risk and issue creation. Similarly, to support the assessment of these events, assessments or analysis should be supported by application components, using once again, two separate application services to risks and issues. Risk Response and Control Activities processes are closely related to the treatment of the identified and assessed events, in order to address and resolve the event. Consequently, both processes use the risk and issue treatment service. Controls may also need to be created, thus a control creation service is needed. The Control Activities process also has a direct relation with audits, since their function is to improve internal controls. For that reason, the audit execution and follow-up services are used by this process. These two services, may assist the Deviation Analysis and Deficiency Management processes, in order to support the execution and follow-up of audits. The Requirement Analysis process, should be simplified through an application service, in order to ease the management of requirements and its relations across other information components in the organization. As stated before, reporting is truly a common and important factor in integrated GRC, mainly due to the extensive relation among information structures. A reporting service may aid the documentation and communication of important information across the organization, and facilitate the implementation of a dashboarding service, that is much valued in organizations. 4.4 Application Structure Viewpoint The application structure viewpoint shows the structure of one or more application components. This viewpoint is useful in designing or understanding the main structure of applications and the associated information [16]. The viewpoint presented in Fig. 8 describes the structure of the applications through the sharing of information. This view re-enforces the problem that integrated GRC addresses. Traditionally, the application components present in this viewpoint, represent departments, that usually do not communicate effectively and efficiently because they are isolated. The usage of mutual information between at least seven out of nine application components is impressive, and an
11 integrated and holistic approach to all GRC activities makes indeed much more sense. Fig. 8. Application Structure Viewpoint 5 Evaluation To evaluate the reference model we opted for the quality factors proposed by the framework for data models from Moody and Shanks [14]. This framework is applicable not only to data models, but also to reference and conceptual models. Reference and conceptual models share common evaluation issues concerning their (re-)usability, testing and analysis [20, 21]. Another issue that difficult the evaluation of these models holds with the factor that reference or conceptual models often describe future domains, hence they cannot be evaluated against a user s perception of reality only [20]. The eight quality factors [14] are: Completeness, Integrity, Flexibility, Understandability, Correctness, Simplicity, Integration and Implementability. We will describe and discuss each individually: Completeness - refers to whether the model contains all user requirements: Concerning completeness for some organizations some processes or applications may be missing. However, since this research focus on the integration
12 of the three disciplines and not so much in deepening each discipline, it is our belief that the reference model describes the key integration points between governance, risk and compliance. Integrity - definition of business rules or constraints from the user requirements: Given the abstraction of the constructed model, no constraints are specified or mandatory. Nonetheless, the processes used in this paper respect accepted rules in governance, risk management and compliance. Flexibility - is defined as the ease with which the model can reflect changes in requirements without changing the model itself : This factor has paramount importance in reference models. A good reference model must be extensible and evolvable. Given the abstraction of the architectural layers, processes and applications can be easily deepened and adaptable to diversified environments. Understandability - is defined as the ease with which the concepts and structures in the model can be understood: A key claim from ArchiMate is based on the understandable structure and concepts that it encompasses. For that matter, the use of ArchiMate presents an advantage for modelling architectures. Also, the use of multiple viewpoints clarifies the rationale of the model. Correctness - is defined as whether the model conform to the rules of the modelling technique (i.e. whether it is a valid model). This includes diagramming conventions, naming rules, definition rules, rules of composition and normalisation: In the Theoretical Background section we described the elements that have been used in this research. We have followed best practices from the ArchiMate specifications to design and relate elements using the viewpoints that better portray the structure of the architecture. Based on this arguments, we can affirm that the model is valid. Simplicity - means that the model contains the minimum possible entities and relationships: Although it was our objective to build a model containing the minimum, yet correct, concepts and relations, no measures were taken to ascertain this quality. A possible solution would be to discuss the obtained model with practitioners. Integration - is defined as the consistency of the model with the rest of the organisation: The model presents several viewpoints from different parts of the organization, and successfully relates them at the business and application level. Additionally, the application components were identified taking into account their modularity. Implementability - is defined as the ease with which the model can be implemented within the time, budget and technology constraints of the project: One of the claims of this research is to provide a reference concerning processes, applications and information. However, the reference architecture has not been implemented in any situation. Nonetheless, the use of reference processes, like COSO ERM and ISO 38500, ensures a certain level of applicability in specific situations.
13 6 Conclusion and Future Work In this research we proposed a reference model that encompasses two architectural layers - business and information systems. Using research from the information systems knowledge base, we reinforced that design research artefacts can and should be employed in order to build new ones [22]. Scientific research can act as a source of independent, reliable and validated references in order to make improvements in this domain. Our ultimate goal is to provide a generic reference for the implementation of integrated GRC. The use of ArchiMate facilitates the comprehension of the artefacts that compose the reference model, and was used to break down language barriers that often induce obstacles to progress in some areas [23]. As future work, we will focus in exploring the detail level of the architecture, by describing in more detail how he application layer provides the mentioned services and drilling down the processes from the business layer. Additionally, we will conduct surveys and interviews with practitioners to evaluate the pragmatic qualities of the proposed reference model. References 1. Dittmar, L., Vogel, P.: Integrating GRC with Performance Management Demands Enterprise Solutions (2008) 2. Gill, S., Purushottam, U.: Integrated GRC - Is your Organization Ready to Move? In: Governance, Risk and Compliance. SETLabs Briefings (2008) Hagerty, J., Kraus, B.: GRC in 2010: $29.8B in Spending Sparked by Risk, Visibility, and Efficiency. GRC-in-2010.pdf (2009) 4. Rasmussen, M.: GRC 2011: Gripes & Directions. (2011) 5. Mccuaig, B.: Building a Business Case For Governance, Risk and Compliance (GRC). (2010) 6. Racz, N., Weippl, E., Seufert, A.: Governance, risk & compliance (grc) software - an exploratory study of software vendor and market research perspectives. In: HICSS, IEEE Computer Society (2011) Racz, N., Weippl, E., Seufert, A.: A Frame of Reference for Research of Integrated Governance, Risk and Compliance (GRC). In Decker, B.D., Schaumüller-Bichl, I., eds.: Communications and Multimedia Security. Volume 6109 of LNCS., Springer (2010) Shen, W., Camarinha-Matos, L., Afsarmanesh, H.: Towards a Reference Model for Collaborative Networked Organizations. In: Information Technology For Balanced Manufacturing Systems. Volume 220 of IFIP International Federation for Information Processing. Springer Boston (2006) Dameri, R.P.: Improving the benefits of it compliance using enterprise management information systems. Information Systems Journal 12 (2009) Schelp, J., Winter, R.: Language communities in enterprise architecture research. In: Proceedings of the 4th International Conference on Design Science Research in Information Systems and Technology. DESRIST 09, ACM (2009) 23:1 23:10
14 11. Racz, N., Seufert, A., Weippl, E.: A Process Model for Integrated IT Governance, Risk, and Compliance Management. In: Proceedings of the Ninth Baltic Conference on Databases and Information Systems (DB&IS 2010), Riga, Latvia (2010) Vicente, P., Mira da Silva, M.: A Conceptual Model for Integrated Governance, Risk and Compliance. In Mouratidis, H., Rolland, C., eds.: 23rd International Conference on Advanced Information Systems Engineering. Volume 6741 of LNCS., London, CAiSE 11, Springer (2011) Brocke, J.V., Buddendick, C.: Reusable Conceptual Models - Requirements Based on the Design Science Research Paradigm. In: First International Conference on Design Science Research in Information Systems and Technology. (2006) 14. Moody, D.L., Shanks, G.G.: Improving the Quality of Data Models: Empirical Validation of a Quality Management Framework. Inf. Syst. 28 (2003) Lankhorst, M., van Drunen, H.: Combining TOGAF and ArchiMate. (2007) 16. Iacob, M.E., Jonkers, H., Lankhorst, H.M., Proper, E.: ArchiMate 1.0 Specification. Technical report, The Open Group (2009) 17. Vicente, P., Mira da Silva, M.: A Business Viewpoint for integrated IT Governance, Risk and Compliance. In: Proceedings of the 1st International Workshop on IT GRC held in Conjunction with the 7th World Congress on Services (SERVICES 2011), Washington, IEEE (2011) 18. Moerdler, M.L., Boswell, C.S., Datskovsky, G., Swaminathan, M., Diebold, B.R., Ding, Y., Benton, J.D.: System and Method for Governance, Risk, and Compliance Management. Patent Application (2009) US 2009/ A ISO/IEC38500: Corporate governance of information technology (2008) 20. Frank, U.: Evaluation of Reference Models. In Fettke, P., Loos, P., eds.: Reference Modeling for Business Systems Analysis, Idea Group (2006) Frank, U.: Conceptual Modelling as the Core of the Information Systems Discipline: Perspectives and Epistemological Challenges. In: Proceedings of the Fifth America s Conference on Information Systems (AMCIS99), Milwaukee, Association for Information Systems (1999) Aier, S., Gleichauf, B.: Applying Design Research Artifacts for Building Design Research Artifacts: A Process Model for Enterprise Architecture Planning. In Winter, R., Zhao, J.L., Aier, S., eds.: Design Science Research in Information Systems and Technology. Volume 6105 of LNCS., Springer (2010) Lang, M.: Communicating Academic Research Findings to IS Professionals: An Analysis of Problems. Informing Science 6 (2003) 21 29
An ISO Compliant and Integrated Model for IT GRC (Governance, Risk Management and Compliance)
An ISO Compliant and Integrated Model for IT GRC (Governance, Risk Management and Compliance) Nicolas Mayer 1, Béatrix Barafort 1, Michel Picard 1, and Stéphane Cortina 1 1 Luxembourg Institute of Science
Governance, Risk and Compliance in BPM - A Survey of Software Tools
Governance, Risk and Compliance in BPM - A Survey of Software Tools Falko Koetter, Monika Kochanowski, Jens Drawehn Fraunhofer Institute for Industrial Engineering IAO and University of Stuttgart IAT Stuttgart,
A Variability Viewpoint for Enterprise Software Systems
2012 Joint Working Conference on Software Architecture & 6th European Conference on Software Architecture A Variability Viewpoint for Enterprise Software Systems Matthias Galster University of Groningen,
Run-time Variability Issues in Software Product Lines
Run-time Variability Issues in Software Product Lines Alexandre Bragança 1 and Ricardo J. Machado 2 1 Dep. I&D, I2S Informática Sistemas e Serviços SA, Porto, Portugal, [email protected] 2 Dep.
COBIT 5 and the Process Capability Model. Improvements Provided for IT Governance Process
Proceedings of FIKUSZ 13 Symposium for Young Researchers, 2013, 67-76 pp The Author(s). Conference Proceedings compilation Obuda University Keleti Faculty of Business and Management 2013. Published by
IT Governance: framework and case study. 22 September 2010
IT Governance: framework and case study Presenter Yaowaluk Chadbunchachai Advisory Services Ernst & Young Corporate Services Limited Presentation topics ERM and IT governance IT governance framework IT
Governance, Risk and Compliance (GRC) software Business needs and market trends
Governance, Risk and Compliance (GRC) software Business needs and market trends David Cau Director Business Risk Deloitte The importance of a holistic view of risk and compliance issues and the difficulty
Enterprise Architecture at Work
Marc Lankhorst et al. Enterprise Architecture at Work Modelling, Communication and Analysis Third Edition 4y Springer Contents 1 Introduction to Enterprise Architecture 1 1.1 Architecture 1 1.2 Enterprise
Clarifying a vision on certification of MDA tools
SCIENTIFIC PAPERS, UNIVERSITY OF LATVIA, 2010. Vol. 757 COMPUTER SCIENCE AND INFORMATION TECHNOLOGIES 23 29 P. Clarifying a vision on certification of MDA tools Antons Cernickins Riga Technical University,
MODELING UNIVERSITY METROPOLITAN ONLINE LEARNING SYSTEM ARCHITECTURE - THE TOGAF/ ARCHIMATE WAY
The Fourth International Conference on e-learning (elearning-2013), 26-27 September 2013, Belgrade, Serbia MODELING UNIVERSITY METROPOLITAN ONLINE LEARNING SYSTEM ARCHITECTURE - THE TOGAF/ ARCHIMATE WAY
Integrated Risk Management:
Integrated Risk Management: A Framework for Fraser Health For further information contact: Integrated Risk Management Fraser Health Corporate Office 300, 10334 152A Street Surrey, BC V3R 8T4 Phone: (604)
Applying Integrated Risk Management Scenarios for Improving Enterprise Governance
Applying Integrated Risk Management Scenarios for Improving Enterprise Governance János Ivanyos Trusted Business Partners Ltd, Budapest, Hungary, [email protected] Abstract: The term of scenario is used
A process model for integrated IT governance, risk, and compliance management
A process model for integrated IT governance, risk, and compliance management Nicolas Racz 1, Edgar Weippl 1, Andreas Seufert 2 1 TU Vienna, Institute for Software Technology and Interactive Systems, Favoritenstr.
Enterprise Architecture and ITIL
Enterprise Architecture and ITIL Marco Vicente [email protected] Instituto Superior Técnico, Lisboa, Portugal July 2013 Abstract Business/IT alignment has become one of the most relevant concerns
Understanding governance, risk and compliance information systems (GRC IS): The experts view
DOI 10.1007/s10796-015-9572-3 Understanding governance, risk and compliance information systems (GRC IS): The experts view Anastasia Papazafeiropoulou 1 & Konstantina Spanaki 2 # The Author(s) 2015. This
Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire. P3M3 Project Management Self-Assessment
Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire P3M3 Project Management Self-Assessment Contents Introduction 3 User Guidance 4 P3M3 Self-Assessment Questionnaire
Design Specification for IEEE Std 1471 Recommended Practice for Architectural Description IEEE Architecture Working Group 0 Motivation
Design Specification for IEEE Std 1471 Recommended Practice for Architectural Description IEEE Architecture Working Group 0 Motivation Despite significant efforts to improve engineering practices and technologies,
A Frame of Reference for Research of Integrated Governance, Risk and Compliance (GRC)
A Frame of Reference for Research of Integrated Governance, Risk and Compliance (GRC) Nicolas Racz 1, Edgar Weippl 1, and Andreas Seufert 2 1 TU Vienna, Institute for Software Technology and Interactive
NASCIO EA Development Tool-Kit Solution Architecture. Version 3.0
NASCIO EA Development Tool-Kit Solution Architecture Version 3.0 October 2004 TABLE OF CONTENTS SOLUTION ARCHITECTURE...1 Introduction...1 Benefits...3 Link to Implementation Planning...4 Definitions...5
Case Study: ICICI BANK INTERNAL AUDIT DEPARTMENT PENTANA AUDIT WORK SYSTEM IMPLEMENTATION
Introduction Emerging trends in the banking sector due to globalisation, liberalisation, increasing environment complexity, regulatory requirements & accountability is driving banks in India to adopt &
Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA
Volume 3, July 2014 Come join the discussion! Alberto León Lozano will respond to questions in the discussion area of the COBIT 5 Use It Effectively topic beginning 21 July 2014. Mapping COBIT 5 with IT
Linking BPMN, ArchiMate, and BWW: Perfect Match for Complete and Lawful Business Process Models?
Linking BPMN, ArchiMate, and BWW: Perfect Match for Complete and Lawful Business Process Models? Ludmila Penicina Institute of Applied Computer Systems, Riga Technical University, 1 Kalku, Riga, LV-1658,
An Information Systems Reference Architecture for the CRM domain
An Information Systems Reference Architecture for the CRM domain Summary of dissertation for the degree of Master in Information Systems and Computer Engineering André Cruz 1 1 Instituto Superior Técnico,
Questions? Assignment. Techniques for Gathering Requirements. Gathering and Analysing Requirements
Questions? Assignment Why is proper project management important? What is goal of domain analysis? What is the difference between functional and non- functional requirements? Why is it important for requirements
Analysing The Governance, Risk And Compliance (Grc) Implementation Process: Primary Insights
Association for Information Systems AIS Electronic Library (AISeL) ECIS 2013 Completed Research ECIS 2013 Proceedings 7-1-2013 Analysing The Governance, Risk And Compliance (Grc) Implementation Process:
Enterprise Architecture (EA) is the blueprint
SETLabs Briefings VOL 6 NO 4 2008 Building Blocks for Enterprise Business Architecture By Eswar Ganesan and Ramesh Paturi A unified meta-model of elements can lead to effective business analysis Enterprise
The role of Information Governance in an Enterprise Architecture Framework
The role of Information Governance in an Enterprise Architecture Framework Richard Jeffrey-Cook, MBCS, CITP, FIRMS Head of Information and Records Management In-Form Consult Ltd, Cardinal Point Park Road,
Governance, Risk, and Compliance (GRC) White Paper
Governance, Risk, and Compliance (GRC) White Paper Table of Contents: Purpose page 2 Introduction _ page 3 What is GRC _ page 3 GRC Concepts _ page 4 Integrated Approach and Methodology page 4 Diagram:
ESS EA TF Item 2 Enterprise Architecture for the ESS
ESS EA TF Item 2 Enterprise Architecture for the ESS Document prepared by Eurostat (with the support of Gartner INC) 1.0 Introduction The members of the European Statistical System (ESS) have set up a
Module 6 Essentials of Enterprise Architecture Tools
Process-Centric Service-Oriented Module 6 Essentials of Enterprise Architecture Tools Capability-Driven Understand the need and necessity for a EA Tool IASA Global - India Chapter Webinar by Vinu Jade
Using COSO Small Business Guidance for Assessing Internal Financial Controls
Using COSO Small Business Guidance for Assessing Internal Financial Controls By János Ivanyos, Memolux Ltd. (H), IIA Hungary Introduction New generation of general models referring to either IT or Internal
An Integrated Quality Assurance Framework for Specifying Business Information Systems
An Integrated Quality Assurance Framework for Specifying Business Information Systems Frank Salger 1, Stefan Sauer 2, Gregor Engels 1,2 1 Capgemini sd&m AG, Carl-Wery-Str. 42, D-81739 München, Germany
Enterprise Architecture with TOGAF 9.1 and ArchiMate 2.0 1. Henk Jonkers, Dick Quartel, Bas van Gils and Henry Franken
White Paper Publication date: May 31 st, 2012 Enterprise with TOGAF 9.1 and ArchiMate 2.0 1 Henk Jonkers, Dick Quartel, Bas van Gils and Henry Franken Executive summary With the appearance of Version 2.0,
A DESIGN SCIENCE APPROACH TO DEVELOP A NEW COMPREHENSIVE SOA GOVERNANCE FRAMEWORK
A DESIGN SCIENCE APPROACH TO DEVELOP A NEW COMPREHENSIVE SOA GOVERNANCE FRAMEWORK Fazilat Hojaji 1 and Mohammad Reza Ayatollahzadeh Shirazi 2 1 Amirkabir University of Technology, Computer Engineering
COBIT 5 For Cyber Security Governance and Management. Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE)
COBIT 5 For Cyber Security Governance and Management Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE) Cybersecurity Governance using COBIT5 Cyber Defence Summit Riyadh, KSA
Five best practices for deploying a successful service-oriented architecture
IBM Global Services April 2008 Five best practices for deploying a successful service-oriented architecture Leveraging lessons learned from the IBM Academy of Technology Executive Summary Today s innovative
White Paper. An Introduction to Informatica s Approach to Enterprise Architecture and the Business Transformation Toolkit
White Paper An Introduction to Informatica s Approach to Enterprise Architecture and the Business Transformation Toolkit This document contains Confidential, Proprietary and Trade Secret Information (
P3M3 Portfolio Management Self-Assessment
Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire P3M3 Portfolio Management Self-Assessment P3M3 is a registered trade mark of AXELOS Limited Contents Introduction
How to bridge the gap between business, IT and networks
ericsson White paper Uen 284 23-3272 October 2015 How to bridge the gap between business, IT and networks APPLYING ENTERPRISE ARCHITECTURE PRINCIPLES TO ICT TRANSFORMATION A digital telco approach can
INTERNATIONAL STANDARD
INTERNATIONAL STANDARD ISO/IEC/ IEEE 42010 First edition 2011-12-01 Systems and software engineering Architecture description Ingénierie des systèmes et des logiciels Description de l'architecture Reference
fs viewpoint www.pwc.com/fsi
fs viewpoint www.pwc.com/fsi June 2013 02 11 16 21 24 Point of view Competitive intelligence A framework for response How PwC can help Appendix It takes two to tango: Managing technology risk is now a
perspective Progressive Organization
perspective Progressive Organization Progressive organization Owing to rapid changes in today s digital world, the data landscape is constantly shifting and creating new complexities. Today, organizations
Implementing COBIT based Process Assessment Model for Evaluating IT Controls
Implementing COBIT based Process Assessment Model for Evaluating IT Controls By János Ivanyos, Memolux Ltd. (H) Introduction New generations of governance models referring to either IT or Internal Control
The Role of the Software Architect
IBM Software Group The Role of the Software Architect Peter Eeles [email protected] 2004 IBM Corporation Agenda Architecture Architect Architecting Requirements Analysis and design Implementation
SOA and BPO SOA orchestration with flow. Jason Huggins Subject Matter Expert - Uniface
SOA and BPO SOA orchestration with flow Jason Huggins Subject Matter Expert - Uniface Objectives Define SOA Adopting SOA Business Process Orchestration Service Oriented Architecture Business Level Componentisation
ASSESSMENT OF THE IT GOVERNANCE PERCEPTION WITHIN THE ROMANIAN BUSINESS ENVIRONMENT
Accounting and Management Information Systems Vol. 11, No. 1, pp. 44 55, 2012 ASSESSMENT OF THE IT GOVERNANCE PERCEPTION WITHIN THE ROMANIAN BUSINESS ENVIRONMENT Pavel NĂSTASE 1 and Simona Felicia UNCHIAŞU
Introducing Reference Models in ERP Development
Introducing Reference Models in ERP Development Signe Ellegård Borch IT University of Copenhagen [email protected] Introduction Business process reference modelling is not a new topic in the ERP software
DEPARTMENT OF INFORMATICS. Scenario-based Analysis of Collaborative Enterprise Architecture Management Tools
DEPARTMENT OF INFORMATICS TECHNISCHE UNIVERSITÄT MÜNCHEN Master s Thesis in Information Systems Scenario-based Analysis of Collaborative Enterprise Architecture Management Tools Nikolaus Katinszky DEPARTMENT
An Enterprise Architecture and Data quality framework
An Enterprise Architecture and quality framework Jerome Capirossi - NATEA-Consulting [email protected] http://capirossi.org, Pascal Rabier La Mutuelle Generale [email protected] Abstract:
SOA: The missing link between Enterprise Architecture and Solution Architecture
SOA: The missing link between Enterprise Architecture and Solution Architecture Jaidip Banerjee and Sohel Aziz Enterprise Architecture (EA) is increasingly being acknowledged as the way to maximize existing
ITC 19 th November 2015 Creation of Enterprise Architecture Practice
ITC 19.11.15 ITC 19 th November 2015 Creation of Enterprise Architecture Practice C Description of paper 1. As part of a wider strategy of Digital Transformation of the University s core services, ISG
MDE Adoption in Industry: Challenges and Success Criteria
MDE Adoption in Industry: Challenges and Success Criteria Parastoo Mohagheghi 1, Miguel A. Fernandez 2, Juan A. Martell 2, Mathias Fritzsche 3 and Wasif Gilani 3 1 SINTEF, P.O.Box 124-Blindern, N-0314
White Paper What Solutions Architects Should Know About The TOGAF ADM
White Paper What Solutions Architects Should Know About The TOGAF ADM WP0015 October 2011 The Open Group Architecture Framework 1 (TOGAF) is the most widely referenced architecture framework currently
Kunal Jamsutkar 1, Viki Patil 2, P. M. Chawan 3 (Department of Computer Science, VJTI, MUMBAI, INDIA)
Software Project Quality Management Kunal Jamsutkar 1, Viki Patil 2, P. M. Chawan 3 (Department of Computer Science, VJTI, MUMBAI, INDIA) ABSTRACT Quality Management is very important in Software Projects.
UNITED NATIONS OFFICE FOR PROJECT SERVICES. ORGANIZATIONAL DIRECTIVE No. 33. UNOPS Strategic Risk Management Planning Framework
UNOPS UNITED NATIONS OFFICE FOR PROJECT SERVICES Headquarters, Copenhagen O.D. No. 33 16 April 2010 ORGANIZATIONAL DIRECTIVE No. 33 UNOPS Strategic Risk Management Planning Framework 1. Introduction 1.1.
TOWARDS A METHOD FOR ENTERPRISE INFORMATION SYSTEMS INTEGRATION (Extended version)
TOWARDS A METHOD FOR ENTERPRISE INFORMATION SYSTEMS INTEGRATION (Extended version) Silveira, R. W.; Pastor, J.A.; Mayol, E. Facultat d Informàtica de Barcelona, Universitat Politècnica de Catalunya {silveira;
Master Data Management Architecture
Master Data Management Architecture Version Draft 1.0 TRIM file number - Short description Relevant to Authority Responsible officer Responsible office Date introduced April 2012 Date(s) modified Describes
IT Governance. What is it and how to audit it. 21 April 2009
What is it and how to audit it 21 April 2009 Agenda Can you define What are the key objectives of How should be structured Roles and responsibilities Key challenges and barriers Auditing Scope Test procedures
COMPARATIVE STUDY OF ERP IMPLEMENTATION METHODOLOGY CASE STUDY: ACCELERATED SAP VS DANTES & HASIBUAN METHODOLOGY
COMPARATIVE STUDY OF ERP IMPLEMENTATION METHODOLOGY CASE STUDY: ACCELERATED SAP VS DANTES & HASIBUAN METHODOLOGY M. Hilman, F. Setiadi, I. Sarika, J. Budiasto, and R. Alfian Faculty of Computer Science,
A Pattern-based Framework of Change Operators for Ontology Evolution
A Pattern-based Framework of Change Operators for Ontology Evolution Muhammad Javed 1, Yalemisew M. Abgaz 2, Claus Pahl 3 Centre for Next Generation Localization (CNGL), School of Computing, Dublin City
, Head of IT Strategy and Architecture. Application and Integration Strategy
IT Strategy and Architecture Application DOCUMENT CONTROL Document Owner Document Author, Head of IT Strategy and Architecture, Enterprise Architect Current Version 1.2 Issue Date 01/03/2013 VERSION CONTROL
Successful Outsourcing of Data Warehouse Support
Experience the commitment viewpoint Successful Outsourcing of Data Warehouse Support Focus IT management on the big picture, improve business value and reduce the cost of data Data warehouses can help
Information Management Advice 35: Implementing Information Security Part 1: A Step by Step Approach to your Agency Project
Information Management Advice 35: Implementing Information Security Part 1: A Step by Step Approach to your Agency Project Introduction This Advice provides an overview of the steps agencies need to take
How To Understand The Role Of Enterprise Architecture In The Context Of Organizational Strategy
Enterprise Architecture in the Context of Organizational Strategy Sundararajan Vaidyanathan Senior Enterprise Architect, Unisys Introduction The Presidential Management Agenda (PMA) 1 is geared towards
Open S-BPM: Goals and Architecture
Open S-BPM: Goals and Architecture Albert Fleischmann Werner Schmidt Table of Content 1 Introduction... 2 2 Mission, Vision and Objectives... 2 3 Research and Development Areas... 3 4 Open S-BPM Architecture...
DATA QUALITY MATURITY
3 DATA QUALITY MATURITY CHAPTER OUTLINE 3.1 The Data Quality Strategy 35 3.2 A Data Quality Framework 38 3.3 A Data Quality Capability/Maturity Model 42 3.4 Mapping Framework Components to the Maturity
Network Rail Infrastructure Projects Joint Relationship Management Plan
Network Rail Infrastructure Projects Joint Relationship Management Plan Project Title Project Number [ ] [ ] Revision: Date: Description: Author [ ] Approved on behalf of Network Rail Approved on behalf
White Paper. Business Analysis meets Business Information Management
White Paper BABOK v2 & BiSL Business Analysis meets Business Information Management Business Analysis (BA) and Business Information Management (BIM) are two highly-interconnected fields that contribute
SOA + BPM = Agile Integrated Tax Systems. Hemant Sharma CTO, State and Local Government
SOA + BPM = Agile Integrated Tax Systems Hemant Sharma CTO, State and Local Government Nothing Endures But Change 2 Defining Agility It is the ability of an organization to recognize change and respond
From Capability-Based Planning to Competitive Advantage Assembling Your Business Transformation Value Network
From Capability-Based Planning to Competitive Advantage Assembling Your Business Transformation Value Network Marc Lankhorst, BiZZdesign Iver Band, Cambia Health Solutions INTRODUCTIONS 2 1 Marc Lankhorst
ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES
THOMSON REUTERS ACCELUS ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES PROACTIVE. CONNECTED. INFORMED. THOMSON REUTERS ACCELUS Compliance management Solutions Introduction The advent of new and pending
Enterprise Architect for an Enterprise Architecture
Enterprise architect is an architecture repository used by many organisations. In this paper I describe a project for introducing an Enterprise Architecture with Archimate 2.0 in a repository based solution.
OPTIMUS SBR. Optimizing Results with Business Intelligence Governance CHOICE TOOLS. PRECISION AIM. BOLD ATTITUDE.
OPTIMUS SBR CHOICE TOOLS. PRECISION AIM. BOLD ATTITUDE. Optimizing Results with Business Intelligence Governance This paper investigates the importance of establishing a robust Business Intelligence (BI)
Governance, Risk & Compliance (GRC) Software An Exploratory Study of Software Vendor and Market Research Perspectives
Governance, Risk & Compliance (GRC) Software An Exploratory Study of Software Vendor and Market Research Perspectives Nicolas Racz TU Vienna [email protected] Edgar Weippl TU Vienna [email protected]
Introduction to SOA governance and service lifecycle management.
-oriented architecture White paper March 2009 Introduction to SOA governance and Best practices for development and deployment Bill Brown, executive IT architect, worldwide SOA governance SGMM lead, SOA
EVALUATION FRAMEWORK FOR SERVICE CATALOG MATURITY IN INFORMATION TECHNOLOGY ORGANIZATIONS
EVALUATION FRAMEWORK FOR SERVICE CATALOG MATURITY IN INFORMATION TECHNOLOGY ORGANIZATIONS Carlos Moreno Martínez Information Systems Department, Universidad Europea de Madrid Spain Email: [email protected]
Three Fundamental Techniques To Maximize the Value of Your Enterprise Data
Three Fundamental Techniques To Maximize the Value of Your Enterprise Data Prepared for Talend by: David Loshin Knowledge Integrity, Inc. October, 2010 2010 Knowledge Integrity, Inc. 1 Introduction Organizations
Data-Aware Service Choreographies through Transparent Data Exchange
Institute of Architecture of Application Systems Data-Aware Service Choreographies through Transparent Data Exchange Michael Hahn, Dimka Karastoyanova, and Frank Leymann Institute of Architecture of Application
Open Certification Framework. Vision Statement
Open Certification Framework Vision Statement Jim Reavis and Daniele Catteddu August 2012 BACKGROUND The Cloud Security Alliance has identified gaps within the IT ecosystem that are inhibiting market adoption
A Methodology for Development of Enterprise Architecture of PPDR Organisations W. Müller, F. Reinert
A Methodology for Development of Enterprise Architecture of PPDR Organisations W. Müller, F. Reinert Fraunhofer Institute of Optronics, System Technologies and Image Exploitation IOSB 76131 Karlsruhe,
EU CUSTOMS BUSINESS PROCESS MODELLING POLICY
EUROPEAN COMMISSION MASP Revision 2014 v1.1 ANNEX 4 DIRECTORATE-GENERAL TAXATION AND CUSTOMS UNION Customs Policy, Legislation, Tariff Customs Processes and Project Management Brussels, 03.11.2014 TAXUD.a3
The Age of Audit: The Crucial Role of the 4 th A of Identity and Access Management in Provisioning and Compliance
The Age of Audit: The Crucial Role of the 4 th A of Identity and Access Management in Provisioning and Compliance Consul risk management, Inc Suite 250 2121 Cooperative Way Herndon, VA 20171 USA Tel: +31
A Guide to Successfully Implementing the NIST Cybersecurity Framework. Jerry Beasley CISM and TraceSecurity Information Security Analyst
TRACESECURITY WHITE PAPER GRC Simplified... Finally. A Guide to Successfully Implementing the NIST Cybersecurity Framework Jerry Beasley CISM and TraceSecurity Information Security Analyst TRACESECURITY
Visualizing the Business Impact of Technical Cyber Risks
Visualizing the Business Impact of Technical Cyber Risks May 21, 2014 Henk Jonkers Senior Research Consultant, BiZZdesign Agenda Introduction and problem statement Enterprise Architecture with ArchiMate
INFORMATION TECHNOLOGY FLASH REPORT
INFORMATION TECHNOLOGY FLASH REPORT ISACA Releases COBIT 5: Updated Framework for the Governance and Management of IT May 18, 2012 In April, ISACA released COBIT 5 as a replacement for its current globally
ArchiMate Extension for Modeling the TOGAF Implementation and Migration Phases
ArchiMate Extension for Modeling the TOGAF Implementation and Migration Phases A White Paper by: Henk Jonkers, Harmen van den Berg, Maria-Eugenia Iacob, and Dick Quartel December 2010 Copyright 2010 The
Holistic Development of Knowledge Management with KMMM
1 Karsten Ehms, Dr. Manfred Langen Holistic Development of Knowledge Management with KMMM Siemens AG / Corporate Technology Knowledge Management & Business Transformation If knowledge management is to
Operational Risk Management - The Next Frontier The Risk Management Association (RMA)
Operational Risk Management - The Next Frontier The Risk Management Association (RMA) Operational risk is not new. In fact, it is the first risk that banks must manage, even before they make their first
Corporate Performance Management Framework
Version 1.0 Copyright 2004 Answerport, Inc. Table of Contents Table of Contents... 2 Conceptual Overview... 3 Conceptual Overview Diagram... 4 The Foundation... 4 Analytic Presentation Layer... 5 Reports...
Building a Data Quality Scorecard for Operational Data Governance
Building a Data Quality Scorecard for Operational Data Governance A White Paper by David Loshin WHITE PAPER Table of Contents Introduction.... 1 Establishing Business Objectives.... 1 Business Drivers...
Development of Enterprise Architecture of PPDR Organisations W. Müller, F. Reinert
Int'l Conf. Software Eng. Research and Practice SERP'15 225 Development of Enterprise Architecture of PPDR Organisations W. Müller, F. Reinert Fraunhofer Institute of Optronics, System Technologies and
Family Evaluation Framework overview & introduction
A Family Evaluation Framework overview & introduction P B Frank van der Linden O Partner: Philips Medical Systems Veenpluis 4-6 5684 PC Best, the Netherlands Date: 29 August, 2005 Number: PH-0503-01 Version:
DESIGNING A DATA GOVERNANCE MODEL BASED ON SOFT SYSTEM METHODOLOGY (SSM) IN ORGANIZATION
DESIGNING A DATA GOVERNANCE MODEL BASED ON SOFT SYSTEM METHODOLOGY (SSM) IN ORGANIZATION 1 HANUNG NINDITO PRASETYO, 2 KRIDANTO SURENDRO 1 Informatics Department, School of Applied Science (SAS) Telkom
1.1 The Nature of Software... Object-Oriented Software Engineering Practical Software Development using UML and Java. The Nature of Software...
1.1 The Nature of Software... Object-Oriented Software Engineering Practical Software Development using UML and Java Chapter 1: Software and Software Engineering Software is intangible Hard to understand
