IT governance and IT management are linked

Opinion
Sep 4, 20064 mins

* IT management's role in IT governance

Governance in IT is one of the last things most IT professionals want to hear about. For most, structure and control are far from the reasons for being in IT. IT “gurus” are innovators, creators and free-thinkers, not the type that wants to fit neatly into a package and be moved around and tracked using RFID or the like. Yet, governing IT is exactly what IT needs to effectively manage itself and be credible within the enterprise.

Governance is intimidating, yet at the same time can be used as a tool for the growth and improved stature of IT. It has risen over the past years in parallel with the scrutiny on corporate governance and IT spending. The definition of IT governance for most is that it provides a means for managing risk, personnel, projects, and finances within IT so that IT is a credible and strategic business function. Control, process, compliance, and service are the central themes. Security and compliance with security policies is also a big part of the story.

Much has happened in the world to drive interest in IT governance and compliance. Obvious drivers include increased need for security in all aspects of our lives. Government regulatory pressures are also a driving force. Between these issues and stress on the corporate bottom line, there are many reasons why IT needs to respond and behave as a business unit itself and IT governance is way to make sure IT is being managed as planned.

Prior to all of this attention around IT governance, IT management has been slowly changing for the past decade. IT executives are making service quality commitments for internal and external services and these commitments are often culminated in a service-level agreement (SLA) and managed to its quality level using a process and tool set designed for service-level management (SLM). This approach is a departure point from the traditional silo-based management where technology types are managed individually.

Process models are being adopted by IT to support this changing culture. They provide a means to an end for service management, IT governance, and compliance. Process models help IT to define “how it will manage itself as a business” and they can serve as guidance to IT shops that are apprehensive about unfamiliar pressures. There are many in use ranging from homegrown process models to the IT Infrastructure Library (ITIL) to Control Objectives for Information Technology (COBIT).

Enterprise Management Associates (EMA) conducted a Web survey recently to get a handle on priorities and perspectives for IT governance in 2006. Suffice it to say that IT governance is a pretty hot topic across all of IT management according to the 68 participants in this survey. Fifty-five percent felt that IT governance is important and another 22% believe that it is critical for the years 2006-2007. CIOs are most concerned. It was nearly unanimous that IT governance will be increasingly important over time. Beyond 2008, 51% felt that IT governance would be important and another 42% thought that it would critical. A small group of IT and non-IT respondents indicated that IT governance would be “not so important” beyond the year 2008.

Driving forces for IT governance are very similar to those of IT service management and as such, parallels can be drawn. The top drivers identified by survey participants included better service delivery (24%), better IT-to-business alignment (19%), cost management (13%), compliance with legal initiatives (12%), and security (9%), and improved project prioritization (9%). Low on the list of drivers were things like pressure from executive management (1%) and improvement of IT’s reputation (2%). Other factors are important in the implementation of IT governance. Many survey responses noted the need for “business participation in the governance process” and cultural changes in the organization more generally. Some specifics included were quantitative management for IT, resource allocation modeling, and skill development within IT.

Managing IT like a business through proper controls and process is a natural evolution of the maturity of IT organizations. Many IT shops are very reactive today. However, investments are being made across the industry and all research including this study suggest that IT will continue in its efforts to be run more like a business, putting controls in place where needed, establishing policies and service quality levels that balance business goals with appropriate investment thresholds. As demonstrated in this survey, service management and IT governance are in fact linked. Growth in one area will help IT to mature more generally and necessarily support growth in the other.