Modules / KM-04
KT0105 - Domains of IT governance
Intoduction to Cybersecurity Governance | KT01: Governance
IT governance is an element of corporate governance, aimed at improving the overall management of IT and deriving improved value from investment in information and technology.
IT governance frameworks enable organisations to manage their IT risks effectively and ensure that the activities associated with information and technology are aligned with their overall business objectives.
The five domains of IT governance
Value delivery.
Strategic alignment.
Performance management.
Resource management.
Risk management.
What are the three aspects of IT governance?
The IT governance framework should be multi-tiered, ideally across three levels: executive, commercial and operational. This not only ensures effective decision-making but also provides a clear escalation path for dispute resolution.
Components of an IT Governance Framework
Elements of an IT Governance FrameworkAn IT Governance Framework based on three major elements:
Structure: Who makes the decisions? What structural organizations will be created, who will take part in these organizations, and what responsibilities will they assume?
Process: How are IT investment decisions made? What are the decision-making processes for proposing investments, reviewing investments, approving investments, and prioritizing investments?
Communication: How will the results of these processes and decisions be monitored, measured, and communicated? What mechanisms will be used to communicate IT investment decisions to the board of directors, executive management, business management, IT management, employees, and shareholders
Common IT Governance Frameworks
Widely Used IT Governance FrameworksThere are three widely recognized, vendor-neutral, third-party frameworks that are often described as 'IT governance frameworks'. While on their own they are not completely adequate to that task, each has significant IT governance strengths:
ITIL®: ITIL, or IT Infrastructure Library®, was developed by the UK's Cabinet Office as a library of best-practice processes for IT service management. Widely adopted around the world, ITIL is supported by ISO/IEC 20000:2011, against which independent certification can be achieved. On our ITIL page, you can access a free briefing paper on ITIL, IT service management and ISO 20000.
COBIT®: Control Objectives for Information and Related Technology (COBIT) is an IT governance control framework that helps organizations meet today’s business challenges in the areas of regulatory compliance, risk management and aligning IT strategy with organizational goals. COBIT is an internationally recognized framework. In particular, COBIT's Management Guidelines component contains a framework for the control and measurability of IT by providing tools to assess and measure the enterprise’s IT capability for the 37 identified COBIT processes.
Val IT: Val IT is a governance framework that can be used to create business value from IT investments.
Calder-Moir IT Governance Framework: This framework provides structured guidance on how to approach IT governance, and can be useful for benchmarking the balance and effectiveness of IT governance practices within an organization.