Governance, Risk & Compliance Advisory Blog
Insights on best practices related to IT Audit & Compliance

Delivering IT Governance - A Toss-Up

October 8, 2010 14:27 by nirav

IT Governance implementation has become indispensable for organizations aiming to manage their regulatory compliance as well as broader business governance functions. However the number of organizations actually implementing a formal IT Governance program and reaping benefits out of it is relatively modest. What makes it so?

We often hear these statements – Don’t we?

“We see IT Governance as an important issue, and we are carrying on an assessment of what is needed”

“We have put ad hoc measures in place till we decide on the final IT Governance framework”

“We are not getting the expected results; hence we are optimizing our IT Governance processes”

“We already have some well-defined IT Governance processes in place and are working on establishing a IT Governance program”

Wrong Processes

Wrong definition, interpretation, and implementation of processes that are in-built in the IT Governance framework may lead to scary results. Hence before deciding on your IT governance design, make sure to inspect your core work processes first. Lack of a solid core process is often the root of the problem.  IT governance does work, but only when it is not clogged up with the processes that don’t fit its goals and when it is designed along with the processes it is supposed to help. Here’s a close look on possible mistakes and ways to avoid them:

IT governance as a separate set of overlays on the top of core day-to-day processes

Remediation

IT Governance should not be treated as a separate area needing attention; instead it should be integrated and managed consistently across the business. One should follow a bottom-up approach, not a top-down approach while implementing it.

Improper authorization management

Remediation

SOX Compliance has enforced strong internal controls to operational levels but the big gap of provisioning still remains. A gap between pre-emptive and detective approach. There is control on the assignment of users to groups/roles/profiles in the IT systems. But the functions these groups, roles or profiles are allowed to do is defined and managed by someone else – the operator/administrator of these IT systems. These authorized people (operator/administrator/senior executives) are not under strong controls even now. Remember, who did wrong activities at Satyam/Enron/WorldCom? Operational level or Executive level?

You should always keep that in mind, that internal controls for executive level are as important as they are for operational level and hence there should not be just a single level but a multi-level authorization, starting with the system admin (who confirms that groups, roles, or profiles) whether he has the correct access rights at that level? This will avoid the occurring of an instance where any access right is granted which later on has to be revoked.

Over-reliance on a single preventive or detective control

Remediation

Instead of stacking more of a particular type of control regime, the organization should focus on developing and implementing a portfolio of controls. That way, if one control fails or is subverted, an independent control serves as a safety net.
For instance organizations should augment manual review of user account and access rights provisioning/re-provisioning/de-provisioning with a detective control. This enables them to compare actual user access with authorized users and permissions thus eliminating the possibility of any security breach.


Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Related posts

Comments

October 14. 2010 08:31

Gravatar

Hey there, thank you for the Toss up, much appreciate it...

Pump in style advanced

October 14. 2010 08:41

Gravatar

Glad you took us through delivering IT governance!!

Ipods maplin lacoste clarins for sale uk

December 17. 2010 13:26

Gravatar

Like your Posts.Thanks Keep Posting.

retractable car charger

December 21. 2010 06:04

Gravatar

We are a smallish band of volunteers and getting into a new related web-site. This web page

provided us all helpful information to work with.You have made a marvellous work!

silver circle earrings

January 11. 2011 12:00

Gravatar

This is a really good read for me, Must admit that you are one of the best bloggers I ever saw.Thanks for posting this informative article.

laser cutting machinery

January 13. 2011 02:10

Gravatar

I have been looking around #hostname and really am impressed by the great content material here. I work the nightshift at my job and it really gets boring. I've been coming here for the previous couple nights and reading. I simply needed to let you know that I've been enjoying what I have seen and I look forward to reading more.

hot tub enclosure

January 25. 2011 09:49

Gravatar

Hrmm that was weird, my comment got eaten. Anyway I wanted to say that it's nice to know that someone else also mentioned this as I had trouble finding this same info elsewhere. This was this first place that told me this answer. Thanks.

knee high leather boots

January 25. 2011 10:20

Gravatar

I am writing a report on this subject and your post is very helpful and informative. Thank you

Craig Gee!.

white gold studs

January 25. 2011 14:45

Gravatar

Hi, i must say fantastic blog you have, i stumbled across it in Google. Does you get much traffic?

quilted down jacket

January 26. 2011 06:12

Gravatar

Thanks,have a good time in diablo 2!

diablo 2 cd key

February 7. 2011 12:25

Gravatar

Interesting article. Were did you got all this information from...

pendant lights

February 21. 2011 06:44

Gravatar

Organizations are always uneager to introduce new things. It has always been so.

online casinos

March 5. 2011 08:23

Gravatar

Excellent read, I just passed this onto a colleague who was doing a little research on that. And he actually bought me lunch because I found it for him smile So let me rephrase that: Thanks for lunch!

ghs strings

March 18. 2011 07:23

Gravatar

ile So let me rephrase that: Thanks for lunch!

thomas sabo

March 23. 2011 19:47

Gravatar

There is no legal obligation to perform impossibilities.

cashback credit cards

March 24. 2011 00:55

Gravatar

Fantastic post, I really look forward to updates from you..

flowers in japan

March 24. 2011 00:55

Gravatar

Nice blog, this is very detailed and informative article.

send flower poland

March 24. 2011 00:58

Gravatar

Wow! Great post. Thanks again...

flower to japan

March 24. 2011 00:58

Gravatar

This website is pretty cool!

send flower to poland

March 24. 2011 19:47

Gravatar

Today we have a good deal of information about web design, but not every piece of it can turn to be helpful or interesting, unfortunately.

web design

April 8. 2011 05:41

Gravatar

Thank you for the toss up, must say this helps a lot.

Wooden Playsets

May 27. 2011 11:42

Gravatar

I am very glad to read the article that you posted here. The article is an interesting and very relevant to today. In addition to the creative, interesting articles, it is informative too. I will be thankful to you. I hope you will write more good articles in future as well.

Dumpster rental

June 20. 2011 18:39

Gravatar

Glad you took us through delivering IT governance!!

Pandora Beads

June 29. 2011 15:38

Gravatar

I have to tell you that this is such an awesome tutorial! I wish everyone would be so detailed! I love your blog and adore your style.....

name pendant

July 5. 2011 06:39

Gravatar

It is great article. It’s possible to detect the term paper writing services that would like to do the essay writing and custom writing

Pandora UK

July 5. 2011 06:39

Gravatar

Custom essay writing companies state that they provide high quality original paper

Pandora Bracelets

July 5. 2011 06:40

Gravatar

I never afraid to order research papers at the essays help uk service because I understand that only experts are able to assist me!

Pandora Beads

July 5. 2011 06:40

Gravatar

nice blog, I like it
Thanks, it helps.

Monster Beats

July 5. 2011 06:41

Gravatar

Really like the newest look. I enjoyed this write-up. Thanks for the excellent work.

Beats Headphones

July 8. 2011 03:57

Gravatar

This is the first time I decided to comment here. I often read your blog and find a lot of interesting information here. Thanks for your efforts of improving your blog!

term paper writing

July 20. 2011 14:05

Gravatar

Really good! I wish I had the same thought in my brain in the mornings))

DNA Essay Topics

August 20. 2011 21:38

Gravatar

Hammocks come in a variety of shapes and styles, all off which can be seen as a comfortable relaxation medium. Let us help you find the perfect hammock to suit...

free standing hammock

September 15. 2011 17:45

Gravatar

I am just read your post and come from across to your blog,i think that is really interesting and enjoyable post.
keep it up.

Universities in Dubai

October 2. 2011 09:46

Gravatar

Just want to say your article is striking. The clearness in your post is simply spectacular and I can take for granted you are an expert on this field.
IONIC INTERNATIONAL Interior Design(http://tw.qbid.com/) is a full service commercial and residential design practice operation from Hong Kong and have sister design studio in Los Angeles, CA and representive office in New York, USA.

interior designer hong kong

October 8. 2011 20:03

Gravatar

If you plan to run a Traffic from Twitter campaign yourself then it requires a lot of efforts and time. You should certainly save time efforts involved and Traffic from Twitter from www.fanbullet.com that are 100% result oriented and are real. You will surely get better results in less cost, less time and less efforts.

Traffic from Twitter

November 18. 2011 22:08

Gravatar

Benefit of starting a soup diet (http://soupaday.com) regimen is that soup can be made from almost anything, and many soups can be made in minutes. Making soup regulary is also a great way to get rid of leftovers!

Soup diet

November 19. 2011 04:38

Gravatar

Great information. Thanks for providing us such a useful information. Keep up the good work and continue providing us more quality information from time to time.

Buffet Ideas

November 19. 2011 16:14

Gravatar

Fine information, many thanks to the author. It is puzzling to me now, but in general, the usefulness and significance is overwhelming. Very much thanks again and good luck!

home daycare

November 21. 2011 05:11

Gravatar

Zune and iPod: Most people compare the Zune to the Touch, but after seeing how slim and surprisingly small and light it is, I consider it to be a rather unique hybrid that combines qualities of both the Touch and the Nano. It's very colorful and lovely OLED screen is slightly smaller than the touch screen, but the player itself feels quite a bit smaller and lighter. It weighs about 2/3 as much, and is noticeably smaller in width and height, while being just a hair thicker.

Shampoo

November 21. 2011 06:16

Gravatar

Great blog!! You should start many more. I love all the info provided.

web design Brisbane

November 22. 2011 03:48

Gravatar

Apple now has Rhapsody as an app, which is a great start, but it is currently hampered by the inability to store locally on your iPod, and has a dismal 64kbps bit rate. If this changes, then it will somewhat negate this advantage for the Zune, but the 10 songs per month will still be a big plus in Zune Pass' favor.

Sulfate Free Shampoo

November 27. 2011 12:42

Gravatar

Hey my friends! I truly am in agreement. Amazing blog post and additionally for sure plenty of superb suggestions at this site! You actually completely got it and I personally am completely happy We have come across your terrific study. I really am pretty much working regarding a new research material for the program and the points may perhaps have introduced right up unquestionably are extremely beneficial.

custom book reports

November 29. 2011 22:23

Gravatar

Nice blog post. I used to be checking continuously to this website & I am very inspired! (http://www.aquashoes.org.uk/)

Aqua Shoes

November 29. 2011 22:26

Gravatar

Your articles always have a lot of really up to date information. Where do you come up with this? Just saying you are very creative. Thanks again.(http://www.ukuleletuner.co.uk)

Ukulele Tuner

November 29. 2011 22:48

Gravatar

Hey there, thank you for the Toss up, much appreciate it...

moncler uk

December 9. 2011 12:04

Gravatar

The uniqueness that I was looking for is already in this site. Thanks.
(http://www.cars4backpackers.com.au)

Campervan Sales

December 9. 2011 12:10

Gravatar

In my point of view, blog makers should have a unique way in making their site. Thanks.
(http://www.travellers-autobarn.com.au)

backpack Australia

December 13. 2011 00:46

Gravatar

This is my first time I visit here. I found so many interesting stuff in your blog!! especially its discussion Laughing From the tons of comments on your articles Smile I guess I am not the only one having all the enjoyment here Smile Keep up the excellent work!!

web design sunshine coast

December 28. 2011 08:36

Gravatar

For additional information on wholesale headphones and its types, visit http://www.gobuyele.com/ and know more information for you.

wholesale headphones

January 1. 2012 04:50

Gravatar

Resources like the one you mentioned here will be very useful to me! I will post a link to this page on my blog. I am sure my visitors will find that very useful.

Iran Sanctions

January 1. 2012 06:41

Gravatar

My partner and I enjoyed reading this write-up; I just wanted to know do you trade featured articles or blog posts? I am always trying to find somebody to make trades with and simply thought I'd ask.

kerala tours

January 6. 2012 20:39

Gravatar

Your blog article is very interesting and fanatic,at the same time the blog theme is unique and perfect,great job.To your success, one of the more impressive blogs I’ve seen. Thanks so much for keeping the internet classy for a change.

Houston Home Security

February 6. 2012 02:40

Gravatar

thanks for sharing...

plagiarism checker

February 18. 2012 22:23

Gravatar

SOX Compliance has enforced strong internal controls to operational levels but the big gap of provisioning still remains. A gap between pre-emptive and detective approach. There is control on the assignment of users to groups/roles/profiles in the IT systems. But the functions these groups, roles or profiles are allowed to do is defined and managed by someone else – the operator/administrator of these IT systems. These authorized people (operator/administrator/senior executives) are not under strong controls even now. Remember, who did wrong activities at Satyam/Enron/WorldCom? Operational level or Executive level?

Jake Gyllenhaal

February 21. 2012 04:37

Gravatar

GKFJAFGZACBZLA I like it very much!

pandora bracelets

March 6. 2012 17:06

Gravatar

ZSQLYXYLDCDSSHNZ
Trouver Sacs à main Lancel bon marché fabriqués en cuir de Lancel

sac Lancel

March 28. 2012 21:17

Gravatar

It is important that Information systems are in compliance with government regulations so as to avoid any problems in the future.

It is important to always check with government policies before doing business.

Custom essays

April 12. 2012 23:27

Gravatar

natural increase sperm count

increase sperm count

April 22. 2012 12:40

Gravatar

vigrx

vigrx plus

April 24. 2012 06:54

Gravatar

treatment for ibs

ibs treatment

April 24. 2012 18:40

Gravatar

This IT Governance should be known by people considering what will be the pros and cons.

Click here

May 8. 2012 00:50

Gravatar

J'ai été shoping pour l'Internet plus de 3 minutes ce matin, jusqu'à présent je n'ai jamais heurté une intéressante publication sous la forme de la vôtre. Il ya beaucoup un peu la peine pour moi. À mon avis, si tous les propriétaires de sites et des blogueurs fait un bon contenu que vous avez fait, le net pourrait être beaucoup plus que informatif que, à tout moment.

abercrombie france

Add comment


(Will show your Gravatar icon)  

  Country flag




Live preview

May 19. 2012 07:13

Gravatar