IT Governance, Risk, and Compliance:

Goals


January 11, 2011  5:07 PM

Governing IT: Policy Formulation and Enforcement – Part VIII



Posted by: Robert Davis
Decision Making, Feedback Control, Fuzzy Logic, Goals, Internal Control Systems, ITG, Linear Control, Logic Control, Management, Monitoring, Objectives, Organizing, Planning, Policy Enforcement, Policy Formation, Sequential Control

Without clear policies that define acceptable IT related behavior, sustaining an effective and efficient internal control system is a remote possibility. Conversely, the formulation of clear IT policies is a mechanism for creating and propagating transparent plans for the achievement of adopted IT...

January 8, 2011  12:26 AM

Governing IT: Policy Formulation and Enforcement – Part VII



Posted by: Robert Davis
Decision Making, Feedback Control, Fuzzy Logic, Goals, Internal Control Systems, ITG, Linear Control, Logic Control, Management, Monitoring, Objectives, Organizing, Planning, Policy Enforcement, Policy Formation, Sequential Control

Due to the continuous adoption of new or improved hardware, firmware and software, IT threat vectors are likely to remain a business risk for the foreseeable future. Once an entity understands what information needs to...


January 4, 2011  5:14 PM

Governing IT: Policy Formulation and Enforcement – Part VI



Posted by: Robert Davis
Decision Making, Feedback Control, Fuzzy Logic, Goals, Internal Control Systems, ITG, Linear Control, Logic Control, Management, Monitoring, Objectives, Organizing, Planning, Policy Enforcement, Policy Formation, Sequential Control

Performance measurement is a control activity.” Measurement techniques are the means for achieving effective performance monitoring. Manually monitoring...


December 31, 2010  6:10 PM

Governing IT: Policy Formulation and Enforcement – Part V



Posted by: Robert Davis
Decision Making, Feedback Control, Fuzzy Logic, Goals, Internal Control Systems, ITG, Linear Control, Logic Control, Management, Monitoring, Objectives, Organizing, Planning, Policy Enforcement, Policy Formation, Sequential Control

Management’s intentions for IT can be implemented manually and/or technologically. Nevertheless, effective IT policy enforcement ultimately depends on the actions of individuals and control systems responsible for monitoring assigned activities. IT policy...


December 28, 2010  7:33 PM

Governing IT: Policy Formulation and Enforcement – Part IV



Posted by: Robert Davis
Decision Making, Feedback Control, Fuzzy Logic, Goals, Internal Control Systems, ITG, Linear Control, Logic Control, Management, Objectives, Organizing, Planning, Policy Formation, Sequential Control

IT policies should be deployed based on assessed effectiveness and efficiency in addressing managements’ risk appetite for an adopted strategy. As previously suggested in this article, control policies can be considered high-level governance documentation guiding operational activities. ...


December 24, 2010  3:11 PM

Governing IT: Policy Formulation and Enforcement – Part III



Posted by: Robert Davis
Decision Making, Goals, Internal Control Systems, ITG, Management, Objectives, Organizing, Planning, Policy Formation

Developing and implementing IT Governance design effectiveness and efficiency can be a multidirectional, interactive, iterative, and adaptive process. Normally,


December 21, 2010  6:42 PM

Governing IT: Policy Formulation and Enforcement – Part II



Posted by: Robert Davis
Decision Making, Goals, Internal Control Systems, ITG, Management, Objectives, Organizing, Planning, Policy Formation

After completion of governance planning and organizing; policies direct employee activity to ensure management’s intentions are implemented throughout the entity. Strategically; IT policies are definite...


December 17, 2010  8:34 PM

Governing IT: Policy Formulation and Enforcement – Part I



Posted by: Robert Davis
Decision Making, Goals, Management, Objectives, Policy Formation

IT policies are general written statements or understandings that prescribe organizational choices. Entity-centric policies typically impose guidelines enabling the execution of fairly routine judgments, consistent with current goals. Policy activation enables leadership, authority, motivation,...


August 31, 2009  8:57 PM

Synchronizing Balanced Scorecards – Part IV



Posted by: Robert Davis
Baseline, Continuous Improvement, Delivery Value, Goals, ITG, Key Indicators, Management System, Monitoring, Service Measurement, Strategic Performance, Strategic Planning

Balanced Scorecards are considered an effective means to assist the entity's oversight committee and operational management in achieving information security,


August 27, 2009  8:16 PM

Synchronizing Balanced Scorecards – Part III



Posted by: Robert Davis
Baseline, Continuous Improvement, Delivery Value, Goals, ITG, Key Indicators, Management System, Monitoring, Service Measurement, Strategic Performance, Strategic Planning

Balanced Scorecard is a strategic planning and management system that can be utilized in for-profit and not-for-profit entities for business activities alignment to the organizational mission, communication...