 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance, Risk, and Compliance &#187; Methodology</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-governance/tag/methodology/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-governance</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 00:56:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Supporting ISG Deployment &#8211; Part V</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-v/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-v/#comments</comments>
		<pubDate>Thu, 17 Sep 2009 19:15:47 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Benchmarking]]></category>
		<category><![CDATA[Budgeting]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[Gap Analysis]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[ITG]]></category>
		<category><![CDATA[Maturity Modeling]]></category>
		<category><![CDATA[Methodology]]></category>
		<category><![CDATA[Objectives]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=257</guid>
		<description><![CDATA[...the importance of effective and efficient ISG cannot be overlooked in the current global high technology environment.]]></description>
				<content:encoded><![CDATA[<p>What ever your perspective may be, the importance of effective and efficient ISG cannot be overlooked in the current global high technology environment. Considering what is at stake for most entities, when security is compromised, usually justifying <a href="http://www.pleier.com/itasecgovweb.htm">ISG deployment</a> based on one viewpoint narrows managerial suitability and expected benefits.  In the final analysis, combining the discussed individual abstraction level may provide the most appropriate support for institutionalizing ISG.</p>
<p>&#8220;<em>View Part I of the Supporting ISG Deployment series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-i/"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-v/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Supporting ISG Deployment &#8211; Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-iv/#comments</comments>
		<pubDate>Mon, 14 Sep 2009 18:19:24 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Benchmarking]]></category>
		<category><![CDATA[Budgeting]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[Gap Analysis]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[ITG]]></category>
		<category><![CDATA[Maturity Modeling]]></category>
		<category><![CDATA[Methodology]]></category>
		<category><![CDATA[Objectives]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=249</guid>
		<description><![CDATA[...potential stakeholders are presumed to rely upon governance elements prior to investing their time, talent, and/or money.]]></description>
				<content:encoded><![CDATA[<p>If, however, you assume ISG provides financial and/or reputational benefits, potential stakeholders are presumed to rely upon governance elements prior to investing their time, talent, and/or money. Therefore, ascertaining the effectiveness and efficiency of entity-centric information security <a href="http://itknowledgeexchange.techtarget.com/it-governance/developing-objectives-part-i/">objectives</a>, through <a href="http://www.pleier.com/infosecmgmt.htm">adequate monitoring</a>, is rudimentary to sound business practices for satisfying stakeholder safeguarding expectations. In this regard, effectiveness and efficiency evaluation requires measurement against established standards. The performance measures should be established when standards are created or adopted. Techniques utilized for ISG implementation include: <a href="http://searchsoftwarequality.techtarget.com/sDefinition/0,,sid92_gci930057,00.html#">maturity modeling</a>, <a href="http://www.investopedia.com/terms/z/zbb.asp">budgeting</a>, <a href="http://itknowledgeexchange.techtarget.com/it-governance/measuring-performance-part-i/">benchmarking</a>, and <a href="http://searchcio-midmarket.techtarget.com/sDefinition/0,,sid183_gci831294,00.html">gap analysis</a>. Base on the perceived opportunity for enrichment, with provable risk reductions, publicized superior ISG deployment may attract additional investors.</p>
<p>&#8220;<em>View Part I of the Supporting ISG Deployment series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-i/"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Supporting ISG Deployment &#8211; Part III</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-iii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-iii/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 21:01:48 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Framework]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[ITG]]></category>
		<category><![CDATA[Methodology]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=246</guid>
		<description><![CDATA[...the adopted ISG methodology should provide security assessments defining strategic, tactical, and operational risks.]]></description>
				<content:encoded><![CDATA[<p>Alternatively, if you perceive ISG as a descriptive prescription for achieving managerial objectives, the adopted <a href="http://www.pleier.com/itasecgovweb.htm">ISG methodology</a> should provide security assessments defining strategic, tactical, and operational risks. Management usually is vigilant regarding the cost of controls and the benefits that can be derived from controls deployment and utilization, while achieving an entity&#8217;s strategic direction. Concurrently, auditors are concerned with the impact of <a href="http://www.pleier.com/itassureiapweb.htm">information security controls</a> on an entity&#8217;s internal control system. To redress <a href="http://www.sjsu.edu/faculty/watkins/cba.htm">cost-benefit</a>, strategic direction as well as control impact issues, ISG effectiveness and efficiency directly related to managerial responsibility, accountability, and authority structure should be demonstrated through appropriate <a href="http://itknowledgeexchange.techtarget.com/it-governance/synchronizing-balanced-scorecards-part-i/">measurement tools</a>. Therefore, at the methodological root, understanding ISG roles are considered crucial to managing secure processes.</p>
<p>&#8220;<em>View Part I of the Supporting ISG Deployment series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-i/"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Supporting ISG Deployment &#8211; Part II</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-ii/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 18:56:07 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Framework]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[ITG]]></category>
		<category><![CDATA[Methodology]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=241</guid>
		<description><![CDATA[...ISG should be implemented as an organizational program with objectives...]]></description>
				<content:encoded><![CDATA[<p>If you envision ISG as a <a href="http://www.pleier.com/infosecmgmt.htm">framework</a> servicing entity and &#8216;<a href="http://it.toolbox.com/blogs/minimalit/what-is-it-governance-7301">IT governance</a>&#8216;, then structurally, ISG should be implemented as an organizational program with objectives, goals, policies, procedures, standards, and rules designed to accomplish management&#8217;s intentions. To drive <a href="http://itknowledgeexchange.techtarget.com/it-governance/safeguarding-information-assets-part-i/">safeguarding controls</a>, ISG should receive &#8216;significant program&#8217; status because other entity and IT programs are directly impacted by ISG effectiveness. Furthermore, efficiency of controls should be obtained through models available to assist in deploying <a href="http://www.pleier.com/itasecgovweb.htm">ISG</a>.</p>
<p>&#8220;<em>View Part I of the Supporting ISG Deployment series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-i/"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Supporting ISG Deployment &#8211; Part I</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-i/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 20:04:13 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Framework]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[ITG]]></category>
		<category><![CDATA[Methodology]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=236</guid>
		<description><![CDATA[...information security governance (ISG) can be viewed as a framework, methodology, or technique...]]></description>
				<content:encoded><![CDATA[<p>Traversing to and aligning with potential &#8216;<a href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm">Governance Tree</a>&#8216; third-tier abstraction levels; information security governance (ISG) can be viewed as a framework, methodology, or technique. Framing ISG enables a &#8220;<a href="http://www.enotes.com/business-finance-encyclopedia/internal-control-systems">system of controls</a>&#8221; assisting in assuring organizational goals and objectives are achieved effectively and efficiently. Methodologically, ISG furnishes descriptive details of the role direction and controls play in achieving entity-centric objectives. Lastly, as a technique, ISG provides processes and steps that can generate superior financial and/or reputational returns for stakeholders.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/supporting-isg-deployment-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Does Management Support Deploying IT Governance?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/how-does-management-support-deploying-it-governance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/how-does-management-support-deploying-it-governance/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 20:02:07 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[Control Self-assessment]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[ISACA]]></category>
		<category><![CDATA[ITGI]]></category>
		<category><![CDATA[Management Information Systems]]></category>
		<category><![CDATA[Methodology]]></category>
		<category><![CDATA[Quality Assurance Program]]></category>
		<category><![CDATA[Technique]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=59</guid>
		<description><![CDATA[Depending on your abstraction level, IT governance can be viewed as a framework, methodology, or technique.]]></description>
				<content:encoded><![CDATA[<p>Depending on your abstraction level, IT governance can be viewed as a framework, methodology, or technique.  As a framework, IT governance enables a “system of controls” assisting in assuring organizational goals and objectives are achieved effectively and efficiently.  As a methodology, IT governance furnishes a description of the role entity direction and controls play in achieving information systems objectives.  Lastly, as a technique, IT governance provides processes and steps that can generate superior financial and/or reputational returns for stakeholders.  </p>
<p>If you view IT governance as a framework for assisting in organizational governance, then structurally, IT governance should be implemented as an organizational program with objectives, goals, policies, procedures, standards, and rules designed to accomplish management’s intentions.  To drive controls, IT governance should subsequently receive ‘significant program’ status because other program results are directly impacted by IT governance effectiveness results &#8212; such as control self-assessment (CSA) and quality control (QC) programs.  Furthermore, efficiency of controls should be obtained through models available to assist in deploying IT governance; including The Institute of Internal Auditors’ Systems Auditability and Control (SAC) framework and the Information Systems Audit and Control Association’s Control Objectives for Information and related Technology (<a href="http://www.isaca.org/Template.cfm?Section=COBIT6&amp;Template=/TaggedPage/TaggedPageDisplay.cfm&amp;TPLID=55&amp;ContentID=7981">COBIT</a>) framework. </p>
<p>Alternatively, if you perceive IT governance as a description for achieving information systems objectives, the adopted <a href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm">IT governance methodology</a> should provide management with a series of assessments defining control usefulness and control deployment &#8212; with IT governance effectiveness and efficiency directly related to management’s responsibility, accountability, and authority structure demonstrated.  Management usually is concerned with the cost of controls and the benefits that can be derived from controls deployment and utilization while achieving an entity’s strategic direction.  Hence, understanding IT governance roles are considered key to managing information systems.   </p>
<p>If, however, you assume IT governance provides financial and/or reputational benefits, potential stakeholders are presumed to rely upon governance elements prior to investing their time, talent, and/or money.  Therefore, ascertaining IT objectives effectiveness and efficiency, through monitoring, is rudimentary to sound business practices for satisfying stakeholder expectations.  In this regard, effectiveness and efficiency evaluation requires measurement against established standards.  The performance measures should be established when standards are created or adopted.  Techniques utilized for IT governance implementation include capability maturity modeling, budgeting, benchmarking, and gap analysis.  Supporting the belief that IT governance is a financial enhancement technique, the <a href="http://mitsloan.mit.edu/cisr/itgovernance.php">Center for Information Systems Research</a> (CISR) has suggested that organizations with exceptional IT governance have higher profits than organizations with inferior governance, given the same strategic objective.  Based on financial opportunity, with an organization’s reputation enhanced through demonstrated profitability when employing IT governance, new stakeholders may be attracted to the organization as a corollary benefit.  </p>
<p>Whatever your perspective may be, the importance of effective and efficient IT governance cannot be overlooked in the current global high technology environment.  Considering what is at stake politically, economically and technically for most organizations; usually justifying IT governance deployment based on one viewpoint narrows suitability and expected benefits.  In the final analysis, combining the discussed individual abstraction levels may be the most appropriate support for implementing IT governance.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/how-does-management-support-deploying-it-governance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
