Está en la página 1de 86

BPKP IT Management Forum

Bandung, 14 December 2010

IT Governance in
Public Sector Organisations
by Phil Leifermann
MBA, CA, CIA, CCSA, CFSA, CGAP, CISA, CFE
President Director, Insight Consulting

CV

Phil Leifermann

24 years of experience related to management


assurance consulting services, including risk
management, internal audit and IT audit

Currently, Managing Director of Insight Consulting


10 years

Previously, Director in PricewaterhouseCoopers


14 years

Insight Consulting
2

CV (cont.)

Master of Business Administration from University


of Western Australia, Australia

Other qualifications, including:


 CA from ICAA
 CIA, CCSA, CFSA and CGAP from IIA
 CISA from ISACA
 CFE from ACFE

Insight Consulting
3

Introduction

www.isaca.org

Insight Consulting
4

Introduction (cont.)

Insight Consulting
5

Introduction (cont.)

Insight Consulting
6

Introduction (cont.)

Insight Consulting
7

Introduction (cont.)

Insight Consulting
8

Introduction (cont.)

Insight Consulting
9

Introduction (cont.)

Insight Consulting
10

Introduction (cont.)

Insight Consulting
11

Introduction (cont.)
COBIT

Strategic alignment

Value delivery

Resource management

Risk management

Performance management

Insight Consulting
12

Introduction (cont.)

Data

Organisations collect data

Insight Consulting
13

Introduction (cont.)

Data

Information

Organisations collect data

These organisations use information technology


to transform data into information

Insight Consulting
14

Introduction (cont.)

Input

Process /
Store

Output

In transforming data into information,


information technology involves:
-

Input data

Process / store data

Output information

Insight Consulting
15

Introduction (cont.)

Input

Process /
Store

Output

Primary objective of information technology is to


generate information, which allows management
to make better decisions:
-

Good information supports good decisions

Bad information supports bad decisions

Insight Consulting
16

Introduction (cont.)
Process /
Store

Input

Output

Secondary objectives of information technology


are to make organisations more effective and
effective:
-

More effective : complete tasks / complete


tasks better

More efficient : complete tasks quicker /


complete tasks with less effort and resources
Insight Consulting
17

Introduction (cont.)

Plan

Insight Consulting
18

Introduction (cont.)

Plan

Build

Insight Consulting
19

Introduction (cont.)

Plan

Build

Maintain

Insight Consulting
20

Introduction (cont.)

Plan

Build

Operate

Operate

Insight Consulting
21

Introduction (cont.)

Plan

Review

Build

Maintain

Review

Operate

Insight Consulting
22

Introduction (cont.)

Plan

Build

Maintain

Operate

Review

IT governance

Insight Consulting
23

Plan

Plan

Build

Maintain

Operate

Review

IT governance

Insight Consulting
24

Plan (cont.)
Plan

Insight Consulting
25

Plan (cont.)
Current
Status

Current status is where we are today

Insight Consulting
26

Plan (cont.)
Current
Status

Desired
Status

Current status is where we are today

Desired status is where we want to be tomorrow

Insight Consulting
27

Plan (cont.)
Current
Status

Strategic
Plan

Desired
Status

Current status is where we are today

Desired status is where we want to be tomorrow

 Strategic plan shows us how we move from


current status to desired status

Insight Consulting
28

Plan (cont.)
Vision

Insight Consulting
29

Plan (cont.)
Vision

Mission

Insight Consulting
30

Plan (cont.)
Vision

Mission

Values

Insight Consulting
31

Plan (cont.)
Vision

Mission

Values

Goals & Objectives

Insight Consulting
32

Plan (cont.)

Strategic Plan

Vision

Mission

Value

Goals & Objectives

Insight Consulting
33

Plan (cont.)

Strategic Plan

Vision

Mission

Values

Goals & Objectives

Tactical / Operational Plans

Insight Consulting
34

Plan (cont.)

Strategic Plan

Vision

Mission

Values

Goals & Objectives

Tactical / Operational Plans

Performance Management

Insight Consulting
35

Plan (cont.)

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Insight Consulting
36

Plan (cont.)
Strategic Plan

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Insight Consulting
37

Plan (cont.)
Strategic Plan

Strategic Alignment

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Insight Consulting
38

Plan (cont.)
Strategic Plan

Value Delivery

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Insight Consulting
39

Plan (cont.)

Resource Management

Strategic Plan

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Insight Consulting
40

Plan (cont.)
Strategic Plan

Risk Management

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Insight Consulting
41

Plan (cont.)

Performance Management

Strategic Plan

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Insight Consulting
42

Plan (cont.)

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Information
Strategy

Insight Consulting
43

Plan (cont.)

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Information
Strategy

Solutions
Strategy

Insight Consulting
44

Plan (cont.)

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Information
Strategy

Solutions
Strategy

Technology
Strategy

Insight Consulting
45

Plan (cont.)

IT Strategic Plan

IT Vision

IT Mission

IT Values

IT Goals & Objectives

Information
Strategy

Solutions
Strategic
Alignment
Strategy

Technology
Strategy

Insight Consulting
46

Build

Plan

Build

Maintain

Operate

Review

IT governance

Insight Consulting
47

Build (cont.)
Plan

Build

Insight Consulting
48

Build (cont.)
Project Management

Insight Consulting
49

Build (cont.)
Project Management

Planning

Insight Consulting
50

Build (cont.)
Project Management

Requirements

Planning

Insight Consulting
51

Build (cont.)

Foundation

Requirements

Insight Consulting
52

Build (cont.)
Project Management

Design

Requirements

Planning

Insight Consulting
53

Build (cont.)

Design

The Foundation

Requirements

Insight Consulting
54

Build (cont.)
Project Management

Development

Design

Requirements

Planning

Insight Consulting
55

Build (cont.)

Development

Design

The Foundation

Requirements

Insight Consulting
56

Build (cont.)
Project Management

Testing

Development

Design

Requirements

Planning

Insight Consulting
57

Build (cont.)

Project Management

Implementation

Testing

Development

Design

Requirements

Planning

Insight Consulting

58

Build (cont.)
Project Management

Implementation

Testing

Development

Design

Requirements

Planning

Quality Management

Insight Consulting
59

Build (cont.)
Project Management

Implementation

Testing

Development

Design

Requirements

Planning

Strategic Alignment

Quality Management

Insight Consulting
60

Build (cont.)
Project Management

Implementation

Testing

Development

Design

Requirements

Planning

Value Delivery

Quality Management

Insight Consulting
61

Build (cont.)
Project Management

Implementation

Testing

Development

Design

Requirements

Planning

Resource Management

Quality Management

Insight Consulting
62

Build (cont.)
Project Management

Implementation

Testing

Development

Design

Requirements

Planning

Risk Management

Quality Management

Insight Consulting
63

Build (cont.)
Project Management

Implementation

Testing

Development

Design

Requirements

Planning

Performance Management

Quality Management

Insight Consulting
64

Maintain

Plan

Build

Maintain

Operate

Review

IT governance

Insight Consulting
65

Maintain (cont.)
Plan

Build

Change
Management

Insight Consulting
66

Maintain (cont.)
Move to development environment

Production
Environment

Systems
Environment

Development
Environment

Move to production

Move to systems

environment

environment

Approved
change
request

Insight Consulting
67

Operate

Plan

Build

Maintain

Operate

Review

IT governance

Insight Consulting
68

Operate (cont.)
Plan

Build

Change
Management

Security
Management

Insight Consulting
69

Operate (cont.)

User-ids

Audit Logs

Security
Management

Passwords

Access Rights

Insight Consulting
70

Operate (cont.)
Plan

Build

Change
Management

Security
Management

Service
Management

Insight Consulting
71

Operate (cont.)

Users

Service
Desk

IT
Department

Insight Consulting
72

Operate (cont.)

Changes

Problems

Service
Desk

Releases

Incidents

Insight Consulting
73

Operate (cont.)

Users

Service
Desk

IT
Department

SLAs

Availability

Capacity

Others

Insight Consulting
74

Operate (cont.)
Plan

Build

Change
Management

Security
Management

Service
Management

Continuity
Management

Insight Consulting
75

Operate (cont.)

Assess

Implement

Continuity
Management

Design

Develop

Insight Consulting
76

Maintain / Operate (cont.)


Plan

Build

Change
Management

Service
Security
Strategic Alignment
Management
Management

Continuity
Management

Insight Consulting
77

Maintain / Operate (cont.)


Plan

Build

Change
Management

Service
Security
Value Delivery
Management
Management

Continuity
Management

Insight Consulting
78

Maintain / Operate (cont.)


Plan

Build

Change
Management

Service
Security
Resource Management
Management
Management

Continuity
Management

Insight Consulting
79

Maintain / Operate (cont.)


Plan

Build

Change
Management

Service
Security
Risk Management
Management
Management

Continuity
Management

Insight Consulting
80

Maintain / Operate (cont.)


Plan

Build

Change
Management

Service
Security
Performance Management
Management
Management

Continuity
Management

Insight Consulting
81

Review

Plan

Build

Maintain

Operate

Review

IT governance

Insight Consulting
82

Review (cont.)
Plan

Build

Maintain / Operate

Review

Insight Consulting
83

Conclusion
COBIT

Strategic alignment

Value delivery

Resource management

Risk management

Performance management

Insight Consulting
84

Conclusion (cont.)

Questions & answers ?

Insight Consulting
85

Conclusion (cont.)
Contact information:

Phil Leifermann

Phone:

+62 21 250-6696

Fax:

+62 21 250-6697

Email:

phil.leifermann@insight.co.id

Insight Consulting
86

También podría gustarte