Tuesday, September 02, 2008

Early Controls Increase Project Efficiency

Build in a brief compliance review early in an IT project to avoid costly rework later in the execution phase. ...

... "As stakeholders in the management of risk, when corporate legal departments provide their input in advance, i.e., during the design phase of an IT project, the resulting controls can be most cost-effectively designed and deployed. " ...


Via Metropolitan Corporate Counsel: Compliance Function

Labels: , , , , , ,

Monday, March 26, 2007

Project Sabotage

If you wanted to sabotage a project even if leadership showed support for it, what would you do? Leadership support is necessary, but not sufficient. Look out for these signals. Have a strong change plan than purely compliance-driven, unless absolutely necessary. ...

... "Confuse meetings with plausible, but pointed, questions. Be too busy to do what's expected of you, e.g., fail to supply data or other resources. Or send a subordinate in your stead " ...


Management Support: Panacea?

Labels: , , , , , ,

Tuesday, February 27, 2007

Critical Success Factors - Executive Support

A common approach to projects involving information technology before the 1990s was for the MIS department (as it was then) to lead and sponsor the project. This applied even when there were significant business process changes involved. That worked well enough when the technical components were the most significant aspects of new systems and formal O&M methods could be applied.
Now the design issues are less to do with technology than with business responsiveness, speed of implementation and compliance. Business leadership becomes increasingly important. The responses have been for IT leadership to take on the character of business leaders - and for business leaders to become expert at change management.
What this means for a project manager working on an IT project is that there must be business sposorship. Pure infrastructure projects may exist, although some organisations insist that even these have a business sponsor. The following article shows the danger of focusing on the technology at the expense of the business requirements. The message is - the business representing the beneficiaries of the project must have 'skin in the game'!
Why Projects Fail to Deliver - Business Reasons

Labels:

Monday, January 15, 2007

Governance Compliance ITIL: CIO 2007 Priority List

2007 CIO priorities are surfaced, with ITIL making the list this year ...

... "Last year IT governance and compliance were the top CIO spending priorities and both are still of high importance with just over half (52 per cent) looking at governance and 42 per cent looking at compliance in 2007. " ...


Via Silicon.com: 2007 CIO Priorities ...

Labels: , , , ,

Sunday, October 22, 2006

IT Project Managers: On Board?

We need IT project managers to be on-board with project management tools. What works? Compliance or coaching? ...

... "We get more buy-in on using the new tools from IT's customers than from the IT project managers. How do I help get them on board? " ...


Via ComputerWorld: Read

Labels: , , , ,

Tuesday, October 17, 2006

SOX IT Compliance: Verizon Exemplar ...

Verizon honored as an exemplar in IT SOX compliance. The company was noted for their use of work process and systems to enable the high-level of performance through its SOX program office. Best practices cited: strong finance dept partnership, leadership committment, and proactive auditing. ...

Verizon sets best practice for Sarbanes Oxley SOX compliance in IT ...

... "Verizon Business strives to be a role model in IT governance and compliance, said Judy Spitz, Verizon Business chief information officer. Spitz heads the company's Sarbanes-Oxley Compliance Program Office, which is responsible for maintaining and improving IT controls and monitors more than 30 of the company's largest revenue and transaction volume applications. " ...


Judy Spitz, Verizon CIO heads up the SOX program office

Via Verizon Business: Verizon Business Honored With Prestigious Technology Managers Forum Award ...

Labels: , , , , , , , ,

Wednesday, August 02, 2006

IT Governance Conference: Financial Controls Emphasis ...

IT Governance conference will focus on the financial compliance enablers of the IT organization. ...

... "Pink Elephant, the world's leading provider of IT service management conferences and education, will be presenting IT Governance 2006, a three-day symposium that will address the complex legislative environment dictating new organizational business practices, and offer strategies for meeting compliance challenges. Taking place from August 6 – 8, 2006 in Orlando, the Symposium's primary goal is to raise awareness of the crucial and now accountable role of IT in the financial reporting process. " ...

Via Pink Elephant: Less Than 2 Weeks To IT Governance 2006

Labels: , , , , ,

Wednesday, July 19, 2006

ITIL Business Case ...

Evergreen offers whitepaper on the business value associated with ITIL implementation, with benefits seen in operational efficiency, customer satisfaction, and risk minimization. ...

... "The white paper references a number of data points taken from current research and enterprise IT process improvement case studies consistently documenting a 20-40% reduction in the effort required for ongoing IT operations, powered by the implementation of ITIL process improvements. The same research clearly links ITIL with strategic gains in customer service quality, accuracy and efficiency and IT risk and compliance work. The development of an ITIL strategy is also discussed and an incremental approach is recommended, one which starts with small steps but shows measurable gains quickly. " ...

Evergreen Systems Releases White Paper on Building the Business Case for ITIL ...

Labels: , , , , , , , , ,

Thursday, June 29, 2006

Inverse of ITIL Compliance Described ...

Description of service desk that fits the "inverse of ITIL" performance capability. George Spafford shares experience of what not to do and what could be better. This poor level of service is pretty common, not just in IT service desks, but especially acute in retail businesses. Good customer service is a differentiator, and it is not hard to differentiate yourself in that space, given the overall poor performance in many industries. ...

... "From an ITIL perspective, the Service Desk (SD) function is a vital one. It should serve as the single point of contact with customers and users to collect and distribute information both reactively and proactively, plus it should own the incident tickets to make sure they are properly managed. " ...

Inverse of ITIL Compliance Described: Via Datamation: Customer Disservice

Labels: , , , , , ,

Monday, June 12, 2006

IT Governance: Immediate Action Necessary ...

IT governance process needed to restore credibility ...
Effective IT governance is necessary to restore credibility to the VA information technology organization. ...

... "The department could pay a high price for its failure to establish effective IT governance in a timely fashion. It faces two class-action lawsuits over the data theft and a request for the Department of Health and Human Services to review its compliance with health data privacy guidelines. " ...

IT Governance: Immediate Action Necessary: Via Government Health IT: McFarland confident about VA changes

Labels: , , , ,

Wednesday, April 26, 2006

IT Governance Conference: Enron Watchdog Keynotes ...

Enron watchdog speaks at IT governance conference ...
Sherron Watkins, Enron, keynotes at upcoming IT governance conference ...

... "According to the IT Governance Institute (ITGI), IT governance is now considered as critical a board and management discipline as corporate or enterprise governance. Effective IT governance helps to ensure that IT supports business goals, maximizes business investment in IT, and appropriately manages IT-related opportunities and risks. Such risks include legal and financial consequences stemming from non-compliance with corporate accounting legislation; namely, the Sarbanes-Oxley Act.

One key figure recognized by TIME magazine for her courageous actions during a high-profile corporate scandal that triggered the landmark Sarbanes-Oxley Act is Sherron Watkins, former Enron VP. Pink Elephant is pleased to welcome Ms. Watkins as one of the symposium’s keynote speakers. " ...

Via Pink Elephant: Sarbanes-Oxley Challenges Meet IT Best Practice ...

Labels: , , , ,

Monday, April 24, 2006

Project Failure Case Study; Maine's Medicaid System

Talk about a project disaster. As reported in an excellent article in CIO Magazine, the Maine Medicaid Claims System project is a case study of a project gone awry.

The project was undertaken to switch from their legacy systems to a new web-based system to process Medicaid claims and facilitate HIPAA compliance (Health Insurance Portability and Accountability Act of 1996). As a result of the failed project, Maine is now the only state in the union not in compliance with HIPAA.

System problems led to many claims ending up in limbo, leading to hundreds of calls from health care practitioners, nearly 300,000 patients being turned away, several dentists and therapists going out of business, and destroying Maine’s finances and credit rating.

So what went wrong?

Mistakes included the following:

  • Deciding to develop an entire system from scratch using unproven technology, while other states built a front-end onto their legacy systems
  • Caving to pressure from management to meet tight deadlines with inadequate resources instead of pushing for a realistic plan to begin with
  • Failing to notice why other bidders either didn’t bid or came in way higher (a sign that the schedule was unrealistic)
  • Hiring a vendor with no experience in developing Medicaid claims systems because they were the lowest bidder
  • Not having a Medicaid expert on the team, leading to errors in judgment
  • Underestimating the time needed to meet with subject matter experts
  • Competing with another major initiative (a department merger) for executives’ attention and resources
  • Skipping project management basics (including piloting, adequate end-to-end testing, staff and user training, etc.) due to looming deadline pressures
  • Failing to stop, regroup, and analyze the risks
  • Taking a “big bang” approach to cutover with no contingency or backup should something go wrong

Management’s response, of course, was to switch program managers, and issue stronger demands to have a smooth system, but none of the changes or demands made much of a difference. Consultants were brought in to prioritize the many problems, but still, the complexities proved too much. It wasn’t until a Medicaid expert was brought in that things began to gel.

Like many project failures, it’s easy to point to the project management (and certainly there are many shortcomings there in this case), but the organization must share the blame as well if it insists on unrealistic deadlines and leads by fear (fear of shareholders, fear of competition, fear of management, etc.). None of these variables can make an unrealistic schedule more realistic.

It's really very simple. Either adequate resources must be committed, the expectations lowered, or a more piecemeal approach taken (or all three, if applicable). In any case, the schedule must be realistic and risks need to be managed.

Here's the full article. It's well worth reading, as are the reader comments.

Maine's Medicaid Mistakes - Editorial - CIO

Labels: , , , , , , , , , , , , , , , ,

Tuesday, March 28, 2006

Outsourcing Project: Lessons Learned

I would like to have been at this project close-out briefing, at the completion of the outsourcing transition. ... Let's see ... what lessons have we learned? ... Update code of business conduct?

... "Indian outsourcer Wipro selected Morgan Stanley as the lead underwriter in its ADR listing on the New York Stock Exchange. Later, Morgan Stanley tapped Wipro for some IT work. " ...

Via InformationWeek Weblog: Morgan Stanley E-Mails Reveal Outsourcing's Dirty Little Secret

Via Wipro Code of Business Conduct (PDF): "A conflict of interest exists where the interests or benefits of one person or entity conflict with the interests or benefits of the Company. ... "

Via Morgan Stanley Code of Ethics: "Employees and officers should promptly report any potential relationships, actions or transactions (including those involving family members) that reasonably could be expected to give rise to a conflict of interest to Law or Compliance. ... "

Project Managers: Learn lessons before they repeat themselves ...

Labels: , , , , , , ,

Wednesday, March 22, 2006

ITIL Best Practice Projects Accelerating ...

Voyence's survey results on ITIL adoption shows that approximately half of those surveyed expect to accelerate ITIL best practice projects over the next 18 months. Change and configuration management were selected as the most important ITIL implementation. The next most important ITIL-candidate processes were incident and problem management. ...

... "Voyence, a pioneer in automated change and configuration management solutions, announced the results of a survey taken at Pink Elephant's 10th Annual International IT Service Management Conference from Feb. 12-14, 2006. Voyence sampled 83 random IT administrators at the show to determine the industry's readiness for regulatory compliance demands and how quickly the industry is adopting IT Infrastructure Library (ITIL) best practices. " ...

ITIL Best Practice Projects Accelerating: Via Voyence: Survey Reveals More Than 90 Percent of IT Managers Cannot Prove Network Compliance With Government Regulations: Survey Indicates ITIL Best Practice Projects Accelerating Due To Compliance Requirements ...

ITIL best-practice implementation projects are accelerating.  Ride the wave.  ...

Labels: , , , , , , ,

Saturday, March 18, 2006

IT Governance Framework Announced

IT Governance Limited has announced a new IT governance framework (titled the Calder-Moir IT Governance Framework) that brings together multiple disciplines, including information technology, risk management, project management, strategy, intellectual property, business design and compliance.

"Until today, no single tool has provided a full picture of IT governance”, says Alan Calder, CEO of IT Governance Limited. “Collectively, existing tools have often given a confusing impression that actually hinders the purpose of IT governance, which is to equip boards with information and levers for directing, evaluating and monitoring how well IT supports their core businesses. The newIT Governance Framework directly addresses this concern.”

To view the framework, visit http://www.itgovernance.co.uk/page.framework. It's based upon Alan Calder’s book, IT GovernanceToday – A Practitioner’s Handbook, which is available at Link.

In addition to the framework and the book, the IT Governance Toolkit, which, according to Calder, will provide "a comprehensive suite of policies, procedures and task sheets" will be launched in Q2 2006.

Labels: , , , , , , , ,

Monday, March 06, 2006

Records Retention: Not an IT Project ...

Records retention processes are becoming critical to an enterprise, as legal actions require ability to search and retrieve electronic records. Implementation of enabling software can be seen as an IT project, but effective records retention is a set of work process and practices that require cultural change to be successful. ...

... "A proper understanding and deployment of archiving skills and processes would address the problem and, in turn, ensure that record storage and retention is no longer an IT project but a compliance project using IT skills and resources. " ...

Records Retention: Not an IT Project: Via IT-Director.com: Greater discrimination about archiving

Labels: , ,

Sunday, February 26, 2006

Project Management Office: PMO Approach to Basel II ...

Just like SOX compliance, banks are wise to implement the PMO, or project management office, approach to Basel II compliance. Article explores Basel II and the approach to risk management projects ...

... "Once an approach has been chosen, the bank will need to put in place a project management office (PMO) to address the approach-specific requirements of Basel II. " ...


Project Management Office: PMO Approach to Basel II: Compliance with Basel II: Via Express Computer

Labels: , , ,

Tuesday, February 14, 2006

Project Management: Virtual Decision Making

Struggling with enabling and sustaining project decisions? Bill Thomas promotes effective decision-making through a process that considers the level of decision-making participation and measures performance. The decision roles of participants should be understood, documented, and monitored (helpful with compliance, such as SOX). Graphical visualization of key measures is recommended, in combination with the appropriate commentary to provide the color and texture of the business context. ...

... "Effective group decision making within performance management has always been a challenge, but traditional decision-making approaches do not consider the speed and complexity of dynamic virtual work teams regularly employed at this time. They also neglect recent compliance regulations that have a direct impact on defining current business processes. Ten years ago, an organization could employ loose guidelines and/or project management techniques because group decision making was less complicated. " ...

Via Business Intelligence Network: Decision Making and Risk within the Performance Management Process ...

Labels: , , , , , , , ,

Tuesday, January 31, 2006

IT Governance Educational Experience ...

The Open Compliance and Ethics Group (OCEG) announces launch of the OCEG IT Forum, which integrates multiple events and publications to create an annual experience where leaders collaborate on best practices and confront their governance challenges together. ...

... "The 2006 OCEG IT Forum program will include a Spring conference on May 9th and 10th at the Harvard Club in Boston, MA; a dedicated issue of GRC 360°, August’s edition of OCEG’s magazine distributed to over 40,000 subscribers and, lastly, a closing conference on November 14th & 15th at the Marine Club in San Francisco, CA. These three components of the IT Forum are integrated to provide a year-long educational experience where participants will investigate, benchmark and validate a broad range of IT governance and compliance practices. " ...


Via OCEG: OCEG ANNOUNCES LAUNCH OF OCEG IT FORUM: Annual Program Will Focus on IT Best Practices, Technologies and Architectures Required to Automate and Sustain Governance, Risk and Compliance Management Operations ...

Labels: , , , , ,

Monday, January 30, 2006

IT Projects: Front-End-Load Software Service ...

Software service augments enterprise project management tools to support the front-end-load (FEL) of IT projects: estimates, resource plans, and schedules. ...

... "SCOPE iT Inc., a provider of IT project planning software services, today announced the latest version of its flagship product, SCOPE iT v.5. SCOPE iT is a web-based software service that helps CIOs and CFOs develop more accurate IT project plans, including cost estimates, resource requirements and time schedules. According to the 2004 Standish Group Chaos Report, $55 million annually is wasted on failed IT projects, which represents 22 percent of an average organization’s IT project budget. SCOPE iT is designed to reduce that number and can help double an organization’s project success rate, saving up to 10 percent or more of its IT project budget, while improving compliance with governance initiatives and frameworks such as Sarbanes-Oxley (SOX), ITIL, CMMI, COBIT and Six Sigma.

This latest version of SCOPE iT – v.5 – provides important up-front project planning capabilities – including estimating, forecasting, resourcing, scoping and scheduling – that complement project management and PPM applications. SCOPE iT v.5 includes a number of new features tailored toward large enterprise organizations, including support for project portfolios, user definable cost categories and enhanced management, organization and customization capabilities. " ...


IT Projects: Front-End-Load Software Service: Via ScopeIT: SCOPE IT INC. INTRODUCES NEW IT PROJECT PLANNING SOFTWARE SERVICE: SCOPE iT v.5 Provides Expanded Capabilities To Increase IT Governance Success ...

Labels: , , , , , , , , ,

Monday, January 16, 2006

Alan Calder Hosts SOX Webinar

Alan Calder, the leading IT Security and Governance guru, will be hosting a webinar on January 25th to talk about ISO 27001 (the new security standard) and how it creates a full-range solution for Sarbanes-Oxley compliance, drawing from CobiT, ITIL and ISO 17799.

For more, here's the info...

Alan Calder on IT Governance, information security and ISO 27001 (BS7799): SOX webinar

Labels: , , , , ,

Project Portfolio Management: IT Business Management Solution ...

Touchpaper introduces new project portfolio management (PPM) system that drives IT business alignment. ...

... "Touchpaper has launched a new product portfolio underlining the company’s IT Business Management (ITBM) strategy and its vision for an ITBM enabled organisation where the IT and customer service departments measure themselves against the strategic and operational goals of the business. Aimed at commercial and government organisations, the Touchpaper ITBM suite is available through the company’s direct sales channels and via its international network of Value Added Reseller (VAR) partners. Many customers have already committed to the new Touchpaper ITBM solution including Hachette Livre UK Books Group, London Borough of Hillingdon, London School of Economics and Political Science, Newport City Council and Sanimed.

Specifically, Touchpaper’s ITBM suite can help deliver projects that drive business growth and value; meet customer needs and pre-defined levels of service; achieve governance and regulatory compliance; link business and IT strategies, plans and relationships; demonstrate the business value of IT; apply metrics to IT; budget and manage IT spending; foster change in business processes and manage risk. " ...

Project Portfolio Management: IT Business Management Solution: Via Touchpaper: Touchpaper Launches New Solution for IT Business Management ...

Labels: , , , , , , , , , , , ,

Tuesday, January 03, 2006

Project Management Biggest Challenge for 2006

According to a Computerworld survey, 33% of respondents rated project management as their #1 management challenge of 2006, even ahead of budget constraints and regulatory compliance. Specifically, the biggest challenges, according to Computerworld are:

1) Managing Global Teams (understanding cultural differences, language and calendar differences, offshore resources, etc.)
2) Moving Parts (i.e. managing complex projects with multiple threads, multiple sponsors, outsourced resources, and multiple phases)
3) Iterative Development (adjusting to more agile approaches, which have proven to be more effective)
4) Vendor Partners (managing outsourced resources, integrating managed service providers, etc.)
5) Project Portfolio Management (i.e. categorizing projects and focusing on the most important work)

It looks to be a busy year for project management consultants. For more info, read on ...

What's Next: Project Management - Computerworld

Labels: , , , , , ,

Tuesday, December 20, 2005

Earned Value: Government EVMS Progress, Targets Raised ...

OMB provides status update for agency progress against electronic government targets. Metrics show modest progress in adoption of earned value management system, EVMS. 2006 targets raise the bar to drive further adoption. ...

... "As of September 30, 2005, 28% of agencies have fully implemented EVMS (7 out of 25) and on average are achieving at least 90% of their cost, schedule, and performance goals. Another 52% of agencies are using some level of EVMS (13 out of 25) to track the cost and schedule status of their major investments and do not have cost overruns or schedule delays exceeding 30%. Those agencies are taking the appropriate actions, including developing comprehensive agency policies and incorporating requirements into contracts for using EVMS, to bring the management of all of their major IT development efforts into full compliance with the industry standard for EVMS. Together these two groups of agencies account for over 75% of Federal agencies being able to measure progress toward milestones in an independently verifiable basis, in terms of cost, capability of the investment to meet specified requirements, timeliness, and quality. The remaining six agencies have a plan of action and milestones to incorporate the use of earned value management into their Capital Planning and Investment Control Process.

For FY 06, the goal is for at least 50% of the agencies managing their IT portfolio in accordance with the standard and averaging 10% of cost, schedule and performance. " ...

Earned Value: Government EVMS Progress, Targets Raised: Via OMB: Expanding E-Government: Improved Service Delivery for the American People Using Information Technology ...

OMB updates government targets for EVMS adoption ...

Labels: , , , , , , , , , , ,

Tuesday, December 06, 2005

SOX SarbanesOxley: IT Asset Management: Webinar

Peregrine and Protiviti collaborate in Web Seminar, Dec 8, on driving SOX Sarbanes-Oxley compliance through better management of information technology assets. ...

Via Peregrine: Peregrine Systems and Protiviti to Participate in InformationWeek TechWebCast on Sarbanes-Oxley and the Role of IT Asset Management ...

... "The WebCast will take place on Thursday, December 8 at 9:00 a.m. PST, and will discuss how organizations can minimize the total cost of ownership for IT assets and mitigate the risks associated with software audits. Although a number of major milestones have been met since Sarbanes-Oxley regulations were enacted in 2002, there is still a long way to go to achieve effective long-term compliance, especially within the IT organization. During this discussion, experts from Peregrine and Protiviti will draw on their experience working with business and technology leaders to offer advice on what's necessary to meet Sarbanes-Oxley compliance requirements and discuss a fast track approach to establishing leading IT Asset Management practices. " ...

IT asset management can drive an enterprise to higher levels of quality management and Sarbanes-Oxley SOX compliance ...

Labels: , , , , , , ,

Wednesday, November 30, 2005

Microsoft Security: Risk Govern Audit ...

Microsoft is making concerted effort on security management, appealing to technology independent partners with services focused on security policy, governance, compliance, risk assessment, risk management and auditing, while balancing its focus on infrastructure security, the technical perspective. ...

Microsoft Security: Risk Govern Audit: Via ISACA: Microsoft Partner Program Includes ISACA Certification in Restructure of Its Security Solutions Competency ...

... "Having a skilled and innovative security partner ecosystem is central to the company’s approach and, therefore, a large part of the effort has been significant changes to the Microsoft Partner Program, Security Solutions Competency, announced this week in partnership with long-established certification programs from Information Systems Audit and Control Association® (ISACA®) and International Information Systems Security Certification Consortium (ISC)2. " ...


Michael Domingo provides update on Microsoft's updated approach to security, which balances the technical with the strategic security management: risk, govern, audit. ...

Via Microsoft Certified Professional Magazine: Security Competency Gets Revamped

... "Microsoft says it has taken a technology agnostic approach within its Security Solutions competency, splitting it into two specializations that address technical issues and the other that looks at security policy and risk management, governance, and auditing. " ...


With more than 47,000 members who live and work in more than 140 countries, the Information Systems Audit and Control Association® (ISACA®) is a recognized worldwide leader in IT governance, control, security and assurance. Founded in 1969, ISACA sponsors international conferences, publishes the Information Systems Control Journal®, develops international information systems auditing and control standards, and administers the globally respected Certified Information Systems Auditor™ (CISA®) designation, earned by more than 40,000 professionals since inception, and the Certified Information Security Manager® (CISM®) designation, a groundbreaking credential earned by 5,200 professionals.

Labels: , , , , , , , , , , ,

Wednesday, November 23, 2005

SarbanesOxley SOX Project: Sustainable Process ...

Sarbanes-Oxley SOX compliance is transitioning from a project management effort to an embedded sustainable process. Nancy Beacham, PWC, offers her perspective on the evolution of Sarbanes-Oxley compliance in year two. ...

SarbanesOxley SOX Project: Sustainable Process: Via IT Business Edge: From Project to Process ...

... "Companies have since realized that they can't do Sarbanes-Oxley compliance under a project mode, so they are moving it into a process that is embedded within the organization. " ...


Last year's Sarbanes-Oxley SOX projects must transition to sustainable process compliance ...

Labels: , , , ,

The New ISO 27001 Security Standard; Get Prepared! Listen to Alan Calder's Podcast

As I've mentioned before, the perfect storm is headed our way. As more companies move toward hosted solutions and the threat of a pandemic computer virus looms, organizations worldwide could be crippled.

Enter the new ISO 27001 Security Standard.

Alan Calder, the leading IT Governance and Security expert and CEO of IT Governance, Ltd., issued a podcast last week talking about ISO 27001 and its impacts. Best of all, Calder offers several eBooks for all levels of audiences, as well as an ISO 27001 toolkit, which allows organizations to become ISO 27001-compliant without expensive consultants.

Here's what Calder's company, IT Governance Ltd. has to say about the new standard:

  • ISO 17799:2005 and BS 7799 are the international best practice information security management standards, defining and guiding Information Security Management System (ISMS) development.
  • BS7799 is the basis for the new international standard ISO 27001, which was introduced in October 2005. Internationalisation will create a global upsurge in demand for ISMS certification.
  • ISO 27001 will become the international touchstone for effective, secure information management practices that protect organisations and ensure their compliance with data protection, privacy and computer misuse regulations.
  • As with ISO 9000, the new standard will become a prerequisite for many businesses wishing to secure new customers and contracts. It is therefore as much a business issue as an IT issue.

    To learn more, check out Alan Calder's podcast below...

    Alan Calder on IT Governance, information security and ISO 27001 (BS7799): Talking ISO 27001

Labels: , , , , , , , ,

Friday, November 18, 2005

Information as a Service: Transition From Project Environment ...

IBM has launched software that transforms data into information to be aimed at increased insight and visibility of business operations. ...

Information as a Service: Transition From Project Environment: Via Sarbanes-Oxley Compliance Journal: IBM's Deep Insight ...

... "Helping organizations to leverage information as a service allows them to move from a project-based environment to a flexible architecture which is crucial for business agility and responsiveness, said Ambuj Goyal, general manager, IBM Information Management. " ...


Labels: , ,

Tuesday, November 15, 2005

IT Governance: COSO Cobit Integration with ESAS ...

IT governance needs to manage the risks associated with SOX compliance. Doug Henschen explores the ESAS methodology employed by Chevron information technology organization to manage its complexity and risks. ...

IT Governance: COSO Cobit Integration with ESAS: Via Intelligent Enterprise: Chevron IT Risk Initiative Spurs Corporate Compliance

... "ESAS is compatible with some of the open frameworks now emerging for IT governance. For example, Chevron is an ITIL shop, and Brabeion says it's incorporating the COSO and CobiT frameworks into ESAS ... " ...

Labels: , , , , , , ,

Monday, November 14, 2005

Construction Project Management: LEED Green Building Certification ...

Johnson Controls introduces software-enabled process for simplifying sustainable green building construction. The software supports the U.S. Green Building Council’s Leadership in Energy and Environmental Design (LEED) Green Building Rating System. ...

Construction Project Management: LEED Green Building Certification: Via Johnson Controls: Johnson Controls Launches Leedspeed Software to Expedite Environmental Green Building Certification ...

... "Leedspeed is divided into two sections: Assessment/ROI Planner and Project Management/Certification. In the Assessment/ROI Planner Section, the Leedspeed software automatically scores a project against the most current LEED-NC (new construction) or LEED-EB (existing building) standards. It then ranks potential LEED credits so building owners can determine the best green features to help them maintain budgets and gain environmental and social returns. ... In the Project Management/Certification Section, Leedspeed provides comprehensive project development and management functions by organizing tasks and responsibilities to properly manage workflow, maintains electronic work schedules for subcontractors, and archives building data. Finally, Leedspeed acts as an electronic repository of all the documentation needed to submit a LEED certification application using the required USGBC letter templates that can be loaded onto the tool. " ...

Construction Project Management: LEED Green Building ...

Leedspeed is powered by Enverity, industry leaders of Web-enabled software applications that corporations and municipalities use to improve their environmental compliance management. Enverity is managed by a former chief technology officer and co-founder of MarketXT, an online securities exchange, and a former U.S. Environmental Protection Agency and World Bank environmental compliance expert.

Labels: , , , ,

Tuesday, November 08, 2005

IT Governance: Manage IT Like A Business: Transparency ...

Tideway Systems sponsors research that shows operational efficiency is still the strongest business driver of information technology in the banking sector. There is a fair amount of diversity in approach to managing IT like a business and adopting the various best practice frameworks, like ITIL. ...

IT Governance: Manage IT Like A Business: Transparency: Via Tideway Systems: Confusion Remains While Compliance Remains ...

... "Due to the intrinsic role that technology is playing in financial services the need for effective IT governance, measurability, accountability and simultaneously cost savings, have become critical. Compliance pressures on the financial services sector have served to accelerate the focus on governance capabilities within the IT department, but have not addressed the fundamental need for a fully transparent, holistic view of the IT organisation that will allow IT to achieve the ultimate goal of managing itself like a business. A variety of best practice guidelines, including the IT Infrastructure Library (ITIL) and COBIT (often applied to Sarbanes Oxley compliance), provide frameworks for how this is to be achieved, but the major incentives driving most projects still remain the need to achieve cost savings and provide cost transparency. " ...


Study examines managing IT like a business ...

Labels: , , , , ,

Thursday, October 27, 2005

ITIL ITSM Software Market Competition Grows: Maximo ...

Software vendor MRO Software repurposes their Maximo solution to support IT service management based on the ITIL principles. Competition in the ITSM software market continues to grow as firms shift their products to address this hot space. ...

ITIL ITSM Software Market Competition Grows: Maximo: Via MRO Software: MRO SOFTWARE'S MAXIMO ENTERPRISE SUITE ON DISPLAY AT GARTNER'S 2005 SYMPOSIUM ITXPO: IT Service Management Suite Shows Early Momentum ...

... "MRO Software, Inc. (Nasdaq: MROI), the leading provider of asset and service management solutions, today announced that the company's Maximo Enterprise Suite (MXES) will be on display at the Gartner Symposium ITxpo. MXES combines asset and service management functionality with an IT infrastructure library (ITIL)-based solution for IT Service Management. Companies are shifting from simply managing assets to managing the service they perform and the strategic contribution they make to the business. MRO Software's Maximo Enterprise Suite builds on the Company's core expertise in asset management to deliver an expanded, comprehensive IT Service Management solution encompassing IT Asset Management and Service Desk functionality. " ...

Competition in the ITIL ITSM software market is raging.  Maxmio enters the market. ...

MRO Software is the leading provider of asset and service management solutions. Maximo Enterprise Suite, the Company's flagship solution, is delivered on a web-architected platform and increases productivity, optimizes asset performance, and service levels, reduces costs and enables asset-related sourcing and procurement across the entire spectrum of strategic assets. The Company's asset management solutions allow customers to manage the complete lifecycle of strategic assets including: planning, procurement, deployment, tracking, maintenance and retirement. Using MRO Software's solutions, customers improve production reliability, labor efficiency, material optimization, software license compliance, lease management, warranty and service management across the asset base. MRO Software (Nasdaq: MROI) is a global company based in Bedford, Mass., with approximately 900 employees, and more than 300,000 end-users. The Company markets its products through a direct sales organization in combination with a network of international distributors. MRO Software has sales offices throughout North America, Europe, Asia/Pacific and Latin America.

Labels: , , , , , , , , ,

Friday, October 21, 2005

IT Governance: New Initiatives Executive Alignment

IT Governance still requires a degree of executive alignment before significant investments can be approved. Any delay can seem bureaucratic, however it is necessary to build an executive support network, or coalition, to align behind a major multi-year investment program. Lawrence M Walsh explores the challenges vendors face when they must align their sales cycles with public sector governance processes.

IT Governance: New Initiatives Executive Alignment: Via CRN: VARs Must Play Politics To Expedite Government Sales

... "Even with centralized IT governance, such as Takai's in Michigan, in which the CIO has budget and oversight of all IT deployments, it still takes time to build consensus for new initiatives. " ...

PMThink references on IT governance:

Labels: , , , , , , , , , , , , , , , , , ,

Wednesday, October 12, 2005

IT Service Delivery Management: Excellence Model

Ah!, the sweet taste of ITSM IT services management ... Hershey's adopt Sun Micro's service excellence model to improve the delivery of business value. Sun has developed a portfolio of aligned IT services, called SunTone. ...

IT Service Delivery Management: Excellence Model: Via Sun Microsystems: The Hershey Company Continues To Use Sun Microsystems' SunTone Service Excellence Model to Improve IT Service Delivery Management ...

... "Sun Tone is part of Sun's integrated portfolio of aligned services that provide IT infrastructure planning, assessments, and resolution services for customer business issues. SunTone helps enterprises derive greater business value from IT, transforming IT from a support function to a provider of business-led services that create competitive advantage. SunTone Service Excellence Model provides guidance and a measurement system for Sun Tone users. The new SunTone Service Excellence Model 3.0 brings advancements in industry standard and regulatory compliance, major enhancements in security, greater manageability, and requirements for financial management.

By adopting the SunTone Service Excellence Model and consistently operating enterprise data center services in accordance with SunTone certification requirements, Hershey was able to improve service availability and operational efficiency. Hershey was also able to reduce the time and effort required to meet requirements for IT governance. Hershey's experience is representative of a current global market trend to adopt IT service management (ITSM) principles to improve IT governance, compliance, drive operational efficiencies and derive greater business value from IT. The SunTone Service Excellence Model covers all the elements involved in delivering IT services -- system architecture, operational processes, and human skills. " ...


The Hershey Company (NYSE: HSY) is a leading snack food company and the largest North American manufacturer of quality chocolate and non-chocolate confectionery products. With revenues of over $4 billion and more than 13,000 employees worldwide, The Hershey Company markets such well-known brands as Hershey's, Reese's, Hershey's Kisses, Kit Kat, Almond Joy, Mounds, Jolly Rancher, Twizzlers, Ice Breakers, and Mauna Loa, as well as innovative new products such as Take 5 and Hershey's Cookies.

Labels: , , , , , , , , , , , ,

Tuesday, October 11, 2005

Governance Software: OMB A123 Compliance

Governance technology software supports government compliance with OMB A123 requirements ...

Governance Software: OMB A123 Compliance: Via Protiviti: Protiviti Releases Cost-Effective Technology Solution that Enables Government Agencies to Comply with OMB A-123 Requirements ...

... "Protiviti Inc., a leading risk consulting and internal audit services firm, today announced the release of a new product extension for the Protiviti Governance Portal designed to help the federal sector achieve complete, sustainable and cost-effective compliance with OMB A-123 requirements. This extension leverages functionality from Protiviti's SarbOx Portal, which launched in April 2003 and emerged as one of the market's leading solutions for Sarbanes-Oxley compliance with nearly 300 commercial client installations worldwide. " ...

Labels: , , ,

IT Governance: Service Portfolio Management Applications ...

It's raining, it's pouring ... EPM software vendors are accelerating their delivery of new service portfolio management applications in support of IT governance processes. Troux delivers IT Governance software to the marketplace, with a service portfolio management module. ...

IT Governance: Service Portfolio Management Applications: Via Troux: Troux Announces IT Governance Applications ...

... "Services Portfolio Management offers a centralized repository for digital service cataloging, built-in workflow and automated SLA compliance analysis. The application allows IT managers to accelerate IT services planning, delivery and management to better demonstrate the value to the business. " ...


Troux Technologies (pronounced "true") is a global provider of IT Governance software that accelerates IT and business transformation. Troux's IT Governance solutions enable organizations to strategically plan the enterprise, capture and analyze critical IT and business data and deliver actionable decisions to transform the business. Troux's breakthrough technology provides the enterprise-class information, policies, and analytics critical for IT excellence. With Troux, organizations succeed in breaking the traditional IT silos and effectively aligning IT with core business goals. Based in Austin, Texas, Troux Technologies serves the Global 1000 and government marketplaces.

Labels: , , , , , , , , , ,

Saturday, October 08, 2005

OMB EVM Rules: Software Supports Capital Project Oversight ...

Software enables compliance with OMB earned value management EVM rules, which supports better oversight of capital projects ....

OMB EVM Rules: Software Supports Capital Project Oversight: Via xpdoffice - A Division of SSSI - Offering Web-Based Timesheet and Project Management Software

... "xpdient, Inc., a division of Scientific Systems and Software International (SSSI), announced the release of a new module of its successful xpdoffice solution to address new Earned Value Management (EVM) rules propagated by the federal government's Office of Management and Budget (OMB) via circular A-11, Part 7, titled Planning, Budgeting, Acquisition, and Management of Capital Assets. The release occurs as OMB officials are becoming increasingly persistent in urging agencies and agency contractors to adopt EVM oversight of major capital projects.

Becoming effective in the near future, rule changes to the Federal Acquisition Regulations will standardize EVM execution and use for all major federal government acquisitions, including information technology services. Widely used in commercial markets, earned value management is a standard way to measure a project's progress, forecast its completion date and final cost, and provide schedule and budget variances along the way. By integrating these capabilities, xpdoffice provides consistent indicators enabling project evaluation and comparison. " ...


xpdoffice is a web based Business Automation Software (BAS) solution that streamlines enterprise management and delivers improved project financial reporting. xpdoffice modules include HR, Contracts Administration, Time Management, Document Management, Knowledge Management, Purchase and Inventory, Project Management, and Expense Management.

Labels: , , , , , , , , , , ,

Buridan and portfolio management


From one of those interesting search chains, Buridan's Ass came to our attention. Buridan's Ass refers to a paradox based on the impossibility of choosing between two equally appealing alternatives. The research theme was portfolio management and the process for prioritisation and selection.

For making a choice within a project, for instance between two packages, there are some well established evaluation techniques such as Kempner Tregoe. These depend on evaluation criteria than can be compared across alternatives - cost, performance, functionality, user acceptability, regulatory compliance, etc.
Portfolio selections frequently don't have such easy measures for comparison which is why clarity of portfolio goals is so important. This is where tying in to corporate goals is crucial and strategies such as balanced score card help to integrate performance goals with portfolio decision making. This paper gives some interesting descriptions and refrerences in this area.
Decision Model based on Balanced Score Card

Labels: , , , ,

Wednesday, September 28, 2005

SOA Governance: Best Practice Strategies Webinar ...

SOA Governance: Best Practice Strategies Webinar: Via Service Integrity: Real-Time Business Intelligence for Service Oriented Enterprises

Upcoming webinar explores best practices and strategy for SOA Service Oriented Architecture in leading enterprises ...

... "Service Integrity, a provider of real-time Business Intelligence (BI) software for Service-Oriented Architectures (SOA), and Systinet, the leader in SOA governance and lifecycle management, announced they will co-host a webinar, Creating a Policy and Practice Blueprint for SOA, on Tuesday, October 4. The online event will present best practices and strategies for building today's service-oriented enterprises, including the critical steps for establishing a system of record for SOA policies and how to secure real-time visibility into the implementation of best practices. " ...

SOA Governance requires best practices and a service strategy ...

Systinet is a leading software provider of the foundation for SOA governance and business service lifecycle management. Founded in 2000, Systinet's award-winning, proven, and standards-based products enable IT organizations to rapidly leverage existing technology investments, provide interoperability between heterogeneous systems, and better align business processes with IT. Customers receive the benefits of a simpler, faster, standards-based way to dramatically improve IT responsiveness and technology asset reuse, while maximizing the ROI for SOA. Systinet's customer base of over 150 Global 2000 clients includes Amazon.com, BMC Software, Interwoven, JP Morgan, Motorola, Defense Information Systems Agency (DISA), and SAIC. Headquartered in Burlington, Mass., Systinet is a privately held company with over 100 employees.

Service Integrity provides patent-pending, real-time Business Intelligence (BI) software for Service-Oriented Architectures (SOA). As a consequence of implementing SOA, more business critical data is “in-flight” than ever, and it’s moving at the speed of light. Service Integrity’s SIFT™ software uniquely resolves the challenge of harnessing and leveraging Information-in-Motion™ to achieve optimal business execution. With SIFT, companies like Pfizer, Novell, and Fidelity National Financial achieve the insight, agility, and predictability they need to gain increased regulatory compliance, continuous risk management, and seamless operational performance. Service Integrity is headquartered in Boston, MA.

Labels: , , , , , , , , , , ,

Monday, September 26, 2005

Project Management: Accelerate New Product Design in Semicon Industry ...

Project Management: Accelerate New Product Design in Semicon Industry: Via MatrixOne: MatrixOne and Leading Analyst Firm to Discuss How to Accelerate Chip Design Through Better Project Management ...

MatrixOne and AMR Research join forces in webcast to explore acceleration of project management for designing and delivering new products to the marketplace in the semicon industry. Eric Karofsky has published recent research on accelerating innovation ("Reach Innovation Utopia With Project Management Tools") ...

... "MatrixOne, Inc. (NASDAQ: MONEE), a leading provider of collaborative product lifecycle management (PLM) solutions for the value chain , announced that it will present a webcast aimed at helping project managers in semiconductor companies learn how they can use better project planning, execution and tracking solutions to better meet today's chip design challenges and deliver new products faster. The webcast will feature a presentation by Eric Karofsky, senior research analyst for AMR Research, who will discuss the latest industry trends and best practices for speeding product development. The live webcast will take place on Thursday, September 29, 2005 at 1:00 pm ET. " ...

Acceleration of new product design through project management is a key differentiator in the semiconductor industry ...

AMR Research provides world class research and actionable advice for executives tasked with delivering enhanced business process performance and cost savings with the aid of technology. Five thousand leaders in the Global 1000 put their trust in AMR Research's integrity, depth of industry expertise, and passion for customer service to support their most critical business initiatives, including supply chain transformation; new product introduction, customer profitability, compliance and governance, and IT benefit realization.

MatrixOne, Inc. (NASDAQ: MONEE), a leading global provider of collaborative product lifecycle management (PLM) software and services, enables companies to accelerate product innovation to achieve top line revenue growth and improve bottom line profitability. With world-class PLM solutions and a commitment to customer success, MatrixOne is focused on helping companies across the automotive, aerospace & defense, consumer, machinery, medical device, semiconductor and high-tech industries solve their most challenging new product development and introduction problems. More than 800 companies use MatrixOne's solutions to drive business value and gain a competitive advantage, including industry leaders such as BAE Systems, Bosch, Comau, General Electric, Honda, Johnson Controls, Linde AG, NCR, Nokia, Philips, Porsche, Procter & Gamble, Sony Ericsson, STMicroelectronics and Toshiba. MatrixOne is headquartered in Westford, Massachusetts, with locations throughout North America, Europe and Asia-Pacific.


Labels: , , , , , , , , , , , , , , , , , , , ,

Friday, September 23, 2005

Project Management Process Compliance

A familiar question surfaced again recently during an assessment - does a process count towards the maturity score if nobody's following it. Or if only some project teams are? Or if you don't know how many teams are? This presentation gives some useful and interesting pointers for determining process compliance. One key concept is that the process should produce some direct evidence of its execution - a 'tangible artifact'. Gary Natwick then goes on to describe a system for for managing the processes themselves including monitoring compliance.
Automated Monitoring of Process Compliance

Labels: ,

Saturday, September 17, 2005

Process Governance Tool Upcoming ...

Process Governance Tool Upcoming: Via Business Engine: Business Engine Forms New Company, Appoints New CEO: New Company Purchases Assets of Old Company, Announces New Customer Wins and New Product ...

... "Business Engine - has also announced that it will be releasing a new product in October codenamed Cascade. Cascade simplifies process governance, compliance and management decision-making and will be formally unveiled at Business Engine's upcoming Global User Summit in Orlando, FL September 25-27, 2005 " ...

Process Governance Tool to be announced shortly at upcoming summit ...

Established in 1985, Business Engine is a leading provider of enterprise software for 'running the business of IT'. The Business Engine Network allows global IT organizations to manage IT strategy, financial governance and operational execution within a single Web-based solution, creating enterprise transparency that dramatically improves IT investment decisions, business alignment and delivery results. Business Engine serves over 80,000 end-users at global organizations including 20 Fortune 100 customers such as Boeing, Lehman Brothers, Merrill Lynch, Northrup Grumman, Pfizer, and Siemens.

Labels: , , , , , , , , ,

Tuesday, August 30, 2005

Automate Portfolio Management Process: Neilsen ...

Automate Portfolio Management Process: Neilsen: Via Mercury: Mercury IT Governance Center Rates High with Nielsen Media

Neilsen leverages Mercury ITG to automate their portfolio management process ...

... "Nielsen was looking for a way to improve customer response time and transform their time-consuming manual portfolio management process to an automated process across business units. They wanted a portfolio management process to provide increased visibility and efficiency to quickly get proposals and requests for different audience rating services into the work flow. Nielsen was also looking to gain a more strategic approach to matching daily demand versus tactical demand. " ...


Mercury IT Governance Center™ helps customers automate IT business processes from demand management to portfolio, program and resource management, to change management. Mercury IT Governance Center is comprised of integrated applications, a real-time dashboard and an enterprise foundation. Mercury IT governance products and services help customers with compliance regulations such as Sarbanes-Oxley, and it supports quality programs and process control frameworks such as Six-Sigma, CMMI (Capability Maturity Model Integration), ITIL (IT Infrastructure Library), ISO-9000, and COBIT (Control Objectives for Information and related Technologies).

Nielsen Media Research is the world’s leading provider of television audience measurement and advertising information services. In the United States, Nielsen’s National People Meter service provides audience estimates for all national program sources, including broadcast networks, cable networks, Spanish language networks, and national syndicators. Local ratings estimates are produced for television stations, regional cable networks, MSOs, cable interconnects, and Spanish language stations in each of the 210 television markets in the U.S., including electronic metered service in 56 markets.

Labels: , , , , , , , , , ,

Monday, August 15, 2005

CIO Council: Enterprise Information Board

Via VA Office of Information and Technology: The Enterprise Information Board

VA leverages an enterprise information board as their CIO council to perform project and portfolio governance of the enterprise architecture ...

... "The information technology planning process supports the review of information technology investment proposals for compliance with VA's Enterprise Architecture. The Enterprise Information Board (EIB) oversees this process. The Assistant Secretary for Information and Technology (who is also VA's Chief Information Officer), as the process owner of VA's information technology planning process, is the steward responsible and accountable for creating, leveraging, coordinating, and implementing VA's Enterprise Architecture. " ...

Labels: , , , ,

Monday, August 08, 2005

Software Supports ITGovernance CorporateGovernance

Software Supports ITGovernance CorporateGovernance: BWise Sets New Compliance Standard with New Product Release: Pioneering Solution Combines IT Governance and Corporate Governance for Full Internal Control ...

BWise software enables integrated IT governance leveraging internal process controls, such as the COBIT, COSO and ITIL standards ...

... "The newest version of the BWise product suite provides the most comprehensive internal control and risk management framework available, with a fully integrated IT and Corporate Governance solution. The flexible solution helps ensure compliance with such key regulatory requirements as those mandated by Sarbanes-Oxley (SOX) and BASEL II. " ...


BWise is a global leader in compliance and enterprise risk management (ERM) software, with a strong heritage in business process management. Established in 1994, BWise delivers proven solutions to help organizations become “in control” by increasing corporate accountability; strengthening financial, strategic and operational efficiencies; and maximizing performance and ROI. BWise has developed a sustainable presence in the compliance sector with quick start templates for SOX, Basel II, SAS70 COSO, COBIT, and others. BWise has more than 1,200 customers in more than 80 countries worldwide, like AEGON, VNU/AC Nielsen, TNT, Bouwfonds/ABN AMRO and 125,000 users in virtually all markets.

Labels: , , , , , , , , ,

Sunday, August 07, 2005

CA Niku ITGovernance Growth Engine?

CA Niku ITGovernance Growth Engine?: CA Completes Niku Acquisition to Extend Leadership in IT Governance

Will the CA Niku deal ($350MM) drive growth for CA in the IT governance space or limit the growth of a good EPM tool? Time will tell ...

... "With the acquisition of Niku, whose revenue grew 45 percent in its last fiscal year, CA gains a best-in-class offering in a market segment that is growing faster than the software industry as a whole. Niku's ITG solutions will be integrated with CA's BSO unit. CA's BSO solutions enable customers to align IT investments with business objectives, control IT costs, deliver IT as a service, and meet heightened compliance requirements. CA estimates the market for its BSO solutions at $7.9 billion in 2004 with an estimated compounded annual growth rate of 8 percent through 2008. " ...


Computer Associates International, Inc. (NYSE:CA), one of the world's largest management software companies, delivers software and services across operations, security, storage, life cycle and service management to optimize the performance, reliability and efficiency of enterprise IT environments. Founded in 1976, CA is headquartered in Islandia, N.Y., and serves customers in more than 140 countries.

Labels: , , , , , ,