Making Sense of
IT GOVERNANCE
Rudy Chouchany
Tuesday June 25, 2019 Gefinor Rotana
Understanding IT Governance
What is Governance
Governance is "the process of decision-
making and the process by which
decisions are implemented
Dictionary : the action or manner of
governing a state, organization, etc
First we need to understand
What is IT Governance?
IT Governance provides a structure for aligning IT strategy with business
strategy. By following a formal framework, organizations can produce
measurable results toward achieving their strategies and goals
IT GOVERNANCE, RISK & COMPLIANCE
IT Governance (ITG) is defined as the processes
that ensure the effective and efficient use of IT in
enabling an organization to achieve its goals.
ITG is a business investment decision-making and
oversight process, and it is a business management
responsibility.
5
What is IT Governance?
IT GOVERNANCE, RISK & COMPLIANCE
IT Governance
The responsibility of executives and the board of directors; consists of the
leadership, organizational structures and processes that ensure that the
enterprise’s IT sustains and extends the enterprise's strategies and objectives.
What is IT Governance?
IT Governance is also known as:
• Information technology governance ITG
• Information and communications technology governance (ICT
Governance)
• Corporate governance of information technology
• Corporate governance of information and communications technology
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
Why do we need IT Governance?
• Reliance of Technology,
• Fast Pace of Change in Technology,
• Failure of IT Projects,
• IT is the driver of competitive advantage,
• Making sure investments put in IT are Giving value and not wasted,
• Ensure the effective and efficient use of IT to achieve Company/Enterprise goals,
• For achieving alignment between IT and business,
• Ensuring that IT delivers value,
• Effective management of IT resources,
• Management and mitigation of IT risk,
• Measurement of performance.
IT GOVERNANCE, RISK & COMPLIANCE
Why do we need IT Governance?
• Widening gap between what IT think the business requires and what the business
thinks the IT is able to deliver.
• General lack of accountability and not enough shared ownership and clarity of
responsibilities for IT services and projects.
• A lot of spending on infrastructure that is not necessarily needed for business
IT GOVERNANCE, RISK & COMPLIANCE
What IT Governance IS NOT
Information Technology Governance should not be confused with IT management,
which is primarily concerned with making tactical decisions.
Think of governance as determining who is authorised and responsible for making
these related decisions.
It is not the implementation of the policy, but the oversight and creation of the
programme.
It is not the enforcing of the policy (IT management’s charter), but the
enactment/Performance of the policy.
In short, IT Governance focuses on the strategic, not the tactical.
IT GOVERNANCE, RISK & COMPLIANCE
The Differences Between IT Governance and Management
The two have different audiences, different realities, yet share a common goals.
IT GOVERNANCE, RISK & COMPLIANCE
Governance
-Strategies for organizational success
-Provides guidance and steering
-Usually driven by a steering or governance
committee consisting of various business
stakeholders and IT representatives
-Focuses on priorities and policies
-They’re typically a mix of technical and
non-technical individuals
-Their job is to assess and mitigate risk and
compliance with controls and regulation
Management
-Involves daily actions, decisions,
implementations and processes
-Works on upholding departmental and
organizational objectives
-Usually driven by technologists tasked with
implementation and support of IT systems
and applications.
-Their priorities and mission are consistent
and optimal IT service delivery
-Their backgrounds are typically in
technology and management
Benefits IT Governance?
Transparency and Accountability
• Improved transparency of IT costs, IT process, IT portfolio (projects and services).
• Clarified decision-making accountabilities and definition of user and provider
relationships.
Return on Investment/Stakeholder Value
• Improved understanding of overall IT costs and their input to ROI cases.
• Combining focused cost-cutting with an ability to reason for investment.
• Stakeholders allowed to see IT risk/returns. Improved contribution to stakeholder
return
IT GOVERNANCE, RISK & COMPLIANCE
Benefits IT Governance? contd..
Opportunities and Partnerships
• Provide route to realise opportunities that might not receive attention or
sponsorship.
• Positioning of IT as a business partner (and clarifying what sort of business partner
IT is).
• Facilitate joint ventures with other companies. Facilitate more businesslike
relationships with key IT partners (vendors and suppliers).
• Achieve a consistent approach to taking risks.
• Enables IT participation in business strategy (which is then reflected in IT strategy)
and vice versa.
• Improve responsiveness to market challenges and opportunities
IT GOVERNANCE, RISK & COMPLIANCE
Benefits IT Governance? contd..
Performance Improvement
• Achieve clear identification of whether an IT service or project supports “business
as usual” or is intended to provide future added value.
• Increased transparency will raise the bar for performance, and advertise that the
bar should be continuously raised.
• A focus on performance improvement will lead to attainment of best practices.
• Avoid unnecessary expenditures – expenditures are demonstrably matched to
business goals.
• Increase ability to benchmark
External Compliance
• Enables an integrated approach to meeting external legal and regulatory
requirements.
IT GOVERNANCE, RISK & COMPLIANCE
Framework of IT governance
There are many IT governance frameworks that are used by organizations worldwide
and the most widely used framework is COBIT or the Control Objectives for
Information and Related Technology). This framework prescribes a set of 37 different
IT processes now 40 and the means of managing these processes through identifying
the inputs and outputs along with key process activities, performance measures, and
process objectives to ensure that the IT systems are indeed delivering business value.
The key reasons why organizations use the IT frameworks are to ensure that they use
the IT systems in an efficient and effective manner. Further, risk mitigation and
performance management are key business imperatives, which the organization must
follow so that there are no surprises for its operations and that the business
objectives are being met.
IT GOVERNANCE, RISK & COMPLIANCE
TITLE OF TEXT
TEXT BOX SHOULD NOT HAVE ANY BACKGROUND COLOR OR BORDER
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
COBIT brings together the five
principles that allow the enterprise to
build an effective governance and
management framework based on a
holistic set of seven enablers that
optimises information and technology
investment and use for the benefit of
stakeholders.
IT GOVERNANCE, RISK & COMPLIANCE
Separating Governance from Management
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
The goals cascade is an important
concept in COBIT as it supports
the translation of stakeholder
needs into actionable strategy.
IT GOVERNANCE, RISK & COMPLIANCE
TITLE OF TEXT
TEXT BOX SHOULD NOT HAVE ANY BACKGROUND COLOR OR BORDER
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
Separating Governance from Management
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
Design Guide factors that should be considered by enterprises to build a best
fit, tailored governance system.
Where is this framework Adopted in Middle east:
• Jordan
• UAE
• Oman
• Kuwait
• Bahrain
• Iraq
IT GOVERNANCE, RISK & COMPLIANCE
IT GOVERNANCE, RISK & COMPLIANCE
ONE FINAL QUESTION
How do you see the role of Head of IT/CIO within your
organization?
THANK YOU!
RUDY CHOUCHANY
MAKING SENSE OF IT GOVERNANCE

MAKING SENSE OF IT GOVERNANCE

  • 1.
    Making Sense of ITGOVERNANCE Rudy Chouchany Tuesday June 25, 2019 Gefinor Rotana
  • 2.
  • 3.
    What is Governance Governanceis "the process of decision- making and the process by which decisions are implemented Dictionary : the action or manner of governing a state, organization, etc First we need to understand
  • 4.
    What is ITGovernance? IT Governance provides a structure for aligning IT strategy with business strategy. By following a formal framework, organizations can produce measurable results toward achieving their strategies and goals IT GOVERNANCE, RISK & COMPLIANCE
  • 5.
    IT Governance (ITG)is defined as the processes that ensure the effective and efficient use of IT in enabling an organization to achieve its goals. ITG is a business investment decision-making and oversight process, and it is a business management responsibility. 5 What is IT Governance?
  • 6.
    IT GOVERNANCE, RISK& COMPLIANCE IT Governance The responsibility of executives and the board of directors; consists of the leadership, organizational structures and processes that ensure that the enterprise’s IT sustains and extends the enterprise's strategies and objectives. What is IT Governance?
  • 7.
    IT Governance isalso known as: • Information technology governance ITG • Information and communications technology governance (ICT Governance) • Corporate governance of information technology • Corporate governance of information and communications technology IT GOVERNANCE, RISK & COMPLIANCE
  • 8.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 9.
    Why do weneed IT Governance? • Reliance of Technology, • Fast Pace of Change in Technology, • Failure of IT Projects, • IT is the driver of competitive advantage, • Making sure investments put in IT are Giving value and not wasted, • Ensure the effective and efficient use of IT to achieve Company/Enterprise goals, • For achieving alignment between IT and business, • Ensuring that IT delivers value, • Effective management of IT resources, • Management and mitigation of IT risk, • Measurement of performance. IT GOVERNANCE, RISK & COMPLIANCE
  • 10.
    Why do weneed IT Governance? • Widening gap between what IT think the business requires and what the business thinks the IT is able to deliver. • General lack of accountability and not enough shared ownership and clarity of responsibilities for IT services and projects. • A lot of spending on infrastructure that is not necessarily needed for business IT GOVERNANCE, RISK & COMPLIANCE
  • 11.
    What IT GovernanceIS NOT Information Technology Governance should not be confused with IT management, which is primarily concerned with making tactical decisions. Think of governance as determining who is authorised and responsible for making these related decisions. It is not the implementation of the policy, but the oversight and creation of the programme. It is not the enforcing of the policy (IT management’s charter), but the enactment/Performance of the policy. In short, IT Governance focuses on the strategic, not the tactical. IT GOVERNANCE, RISK & COMPLIANCE
  • 12.
    The Differences BetweenIT Governance and Management The two have different audiences, different realities, yet share a common goals. IT GOVERNANCE, RISK & COMPLIANCE Governance -Strategies for organizational success -Provides guidance and steering -Usually driven by a steering or governance committee consisting of various business stakeholders and IT representatives -Focuses on priorities and policies -They’re typically a mix of technical and non-technical individuals -Their job is to assess and mitigate risk and compliance with controls and regulation Management -Involves daily actions, decisions, implementations and processes -Works on upholding departmental and organizational objectives -Usually driven by technologists tasked with implementation and support of IT systems and applications. -Their priorities and mission are consistent and optimal IT service delivery -Their backgrounds are typically in technology and management
  • 13.
    Benefits IT Governance? Transparencyand Accountability • Improved transparency of IT costs, IT process, IT portfolio (projects and services). • Clarified decision-making accountabilities and definition of user and provider relationships. Return on Investment/Stakeholder Value • Improved understanding of overall IT costs and their input to ROI cases. • Combining focused cost-cutting with an ability to reason for investment. • Stakeholders allowed to see IT risk/returns. Improved contribution to stakeholder return IT GOVERNANCE, RISK & COMPLIANCE
  • 14.
    Benefits IT Governance?contd.. Opportunities and Partnerships • Provide route to realise opportunities that might not receive attention or sponsorship. • Positioning of IT as a business partner (and clarifying what sort of business partner IT is). • Facilitate joint ventures with other companies. Facilitate more businesslike relationships with key IT partners (vendors and suppliers). • Achieve a consistent approach to taking risks. • Enables IT participation in business strategy (which is then reflected in IT strategy) and vice versa. • Improve responsiveness to market challenges and opportunities IT GOVERNANCE, RISK & COMPLIANCE
  • 15.
    Benefits IT Governance?contd.. Performance Improvement • Achieve clear identification of whether an IT service or project supports “business as usual” or is intended to provide future added value. • Increased transparency will raise the bar for performance, and advertise that the bar should be continuously raised. • A focus on performance improvement will lead to attainment of best practices. • Avoid unnecessary expenditures – expenditures are demonstrably matched to business goals. • Increase ability to benchmark External Compliance • Enables an integrated approach to meeting external legal and regulatory requirements. IT GOVERNANCE, RISK & COMPLIANCE
  • 16.
    Framework of ITgovernance There are many IT governance frameworks that are used by organizations worldwide and the most widely used framework is COBIT or the Control Objectives for Information and Related Technology). This framework prescribes a set of 37 different IT processes now 40 and the means of managing these processes through identifying the inputs and outputs along with key process activities, performance measures, and process objectives to ensure that the IT systems are indeed delivering business value. The key reasons why organizations use the IT frameworks are to ensure that they use the IT systems in an efficient and effective manner. Further, risk mitigation and performance management are key business imperatives, which the organization must follow so that there are no surprises for its operations and that the business objectives are being met. IT GOVERNANCE, RISK & COMPLIANCE
  • 17.
    TITLE OF TEXT TEXTBOX SHOULD NOT HAVE ANY BACKGROUND COLOR OR BORDER IT GOVERNANCE, RISK & COMPLIANCE
  • 18.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 19.
    IT GOVERNANCE, RISK& COMPLIANCE COBIT brings together the five principles that allow the enterprise to build an effective governance and management framework based on a holistic set of seven enablers that optimises information and technology investment and use for the benefit of stakeholders.
  • 20.
    IT GOVERNANCE, RISK& COMPLIANCE Separating Governance from Management
  • 21.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 22.
    IT GOVERNANCE, RISK& COMPLIANCE The goals cascade is an important concept in COBIT as it supports the translation of stakeholder needs into actionable strategy.
  • 23.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 24.
    TITLE OF TEXT TEXTBOX SHOULD NOT HAVE ANY BACKGROUND COLOR OR BORDER IT GOVERNANCE, RISK & COMPLIANCE
  • 25.
    IT GOVERNANCE, RISK& COMPLIANCE Separating Governance from Management
  • 26.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 27.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 28.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 29.
    IT GOVERNANCE, RISK& COMPLIANCE
  • 30.
    IT GOVERNANCE, RISK& COMPLIANCE Design Guide factors that should be considered by enterprises to build a best fit, tailored governance system.
  • 31.
    Where is thisframework Adopted in Middle east: • Jordan • UAE • Oman • Kuwait • Bahrain • Iraq IT GOVERNANCE, RISK & COMPLIANCE
  • 33.
    IT GOVERNANCE, RISK& COMPLIANCE ONE FINAL QUESTION How do you see the role of Head of IT/CIO within your organization?
  • 34.