topleft
topright






Lost Password?
CIOZone Points Beta

Featured Member

CIOs Online Now
IBM offers insights and perspectives to help CIOs with the issues that matter most
Dr. Arthur M. Langer

Sponsored Links


Predict the future with HP Insight Power Manager


Affordable technology-no compromise. HP server solutions.
Forrester Research: Defining IT GRC Print E-mail

By Khalid Kark, Marc Othersen, Chris McClean with Paul Stamp, Michael Rasmussen, Alex Cullen, Craig Symons, Alissa Dill


This is the first document in the "Fundamentals Of IT GRC" series from Forrester Research.


EXECUTIVE SUMMARY

IT governance, IT risk management, and IT compliance are three distinct disciplines that in the past have existed in silos within organizations. Today, many organizations no longer see these activities as individual, one-time projects handled in separate parts of the IT organization. Rather, they are finding that there are a lot of commonalities and interrelationships that exist between these three areas. Adopting a unified IT governance, risk management, and compliance (IT GRC) approach and managing the associated activities coherently will create efficiencies, provide a holistic view of the IT environment, and ensure accountability.


Defining The Component of IT GRC


Business imperatives, increased regulatory pressure, and customer demands are forcing many CIOs to adopt a structured, enterprisewide approach to IT GRC. Today, enterprises are acknowledging that a mishmash of technologies and processes working in silos inevitably leads to inefficiency, increased cost, and higher risk to the organization (see Figure 1).


There is currently a lot of confusion on what exactly IT GRC is and what subcomponents to consider while establishing a program. Although the specifics of the program vary based on the individual circumstances of an organization, having common definitions and broad objectives for each area will establish the high-level approach for the program.


IT Governance Establishes Decision Structures And Tracking Mechanisms

Forrester defines IT governance as:
The act of establishing IT decision structures, processes, and communication mechanisms in support of the business objectives and tracking progress against fulfilling business obligations efficiently and consistently.


At its most basic definition, IT governance primarily determines how decisions are made, who makes the decisions, who is held accountable, and how the results of decisions are measured and monitored.(see endnote 1) Although many organizations have some form of IT governance in place, the governance processes are ad hoc, siloed, and informal. Organizations need to first ensure that they have the appropriate governance structures in place; structures such as technology steering committees, architecture review boards, and project review boards fulfill this task. The second step is to ensure that the appropriate processes exist to guarantee consistency and transperancy, for example, processes for proposing new projects, processes for approving new IT investments, and processes for prioritizing IT projects would fit the bill. Third, organizations need to ensure that there is appropriate communication and accountability to measure the outcomes of IT decisions whether these decisions are technical, monitory, human resource, or any other type. Project status reports, ROI analysis, and Balanced Scorecards would be examples of such communication and monitoring (see Figure 2).(see endnote 2)


Download the rest of this report, including graphics, free of charge.




Comments (2)
RSS comments
1. 02-06-2008 02:50
 
It seems a great artile, but I wonder if there is more focused overview on the IT GRC implementation frameworks
Guest
 
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it
2. 07-08-2008 07:57
 
The download link does not bring you to this same Forrester report. Instead, Forrester sends a link to: Managing IT When Times Get Tough - Proactive CIOs Will Help Firms Amid Economic Uncertainties (March 25,2008). This is "...the first document in the “Managing IT In Uncertain Economic Conditions” series". Can Forrester update the link to provide a copy of "Defining IT GRC"? Thanks
Guest
 
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it

Write Comment
  • Please keep the topic of messages relevant to the subject of the article.
Name:
E-mail
Comment:

Code:* Code
I wish to be contacted by email regarding additional comments

 
< Prev   Next >





A CIO discussion forum around business and technology topics that matter most to CIOs today.

CIOZone Poll

What do CIOs really want for the Holidays?
 

CIOZone White Paper Library

Acronis

Riverbed

RSA

Tripwire

Must Watch Videos

CIOZone Select Video Center

News & Noteworthy Archive

Past News Items From Reuters