{"id":3515,"date":"2016-12-29T07:54:57","date_gmt":"2016-12-29T07:54:57","guid":{"rendered":"http:\/\/itges.rg.telkomuniversity.ac.id\/?p=3515"},"modified":"2016-12-29T07:54:57","modified_gmt":"2016-12-29T07:54:57","slug":"using-cobit-for-it-organizational-design","status":"publish","type":"post","link":"https:\/\/itges.rg.telkomuniversity.ac.id\/?p=3515","title":{"rendered":"Using COBIT for IT Organizational Design by Azhar Zia-ur-Rehman, CISA, CRISC, CISM, ISO 27001 LA"},"content":{"rendered":"<p style=\"text-align: justify\">The organizational structure of an IT department is usually the result of a series of changes, trials, experiments and political manipulations. It is often adjusted to suit or accommodate individuals. As a result, the organization is sometimes cumbersome and the cause of problems, inefficiency, and excess cost. The process described herein has been developed from experience gained by participating in numerous efforts to redesign and transform IT organizations.<\/p>\n<p style=\"text-align: justify\"><strong>Step 1: Select the Standards<\/strong><br \/>\nThe primary objective is to deliver value to stakeholders from IT-enabled investments. The organizational design should follow standards and good practices so that the resulting design is easy to defend and noncontroversial. Start by selecting from the following set of frameworks, standards, and good practices:<\/p>\n<ul>\n<li style=\"text-align: justify\">COBIT 5\u2014Ensures that all aspects of IT are covered in terms of processes as well as tasks. COBIT 5 also provides the structure needed to ensure that alignment exists from stakeholder requirements through the enterprise and IT-related goals to all enablers.<\/li>\n<li style=\"text-align: justify\">Skills Framework for the Information Age (SFIA V6)\u2014Ensures that all skills that are required have been included and are reflected in the design of job descriptions<\/li>\n<li style=\"text-align: justify\">ISO\/IEC 38500:2015\u2014Covers the IT governance aspects in detail<\/li>\n<li style=\"text-align: justify\">ISO\/IEC 20000:2011\u2014Covers the service management aspects in detail<\/li>\n<li style=\"text-align: justify\">ISO\/IEC 27001:2013\u2014Covers the information security aspects in detail<\/li>\n<\/ul>\n<p>Some organizations may prefer to add more standards, good practices or local regulations, codes or laws. One of the very helpful codes in this regard is King III (soon to be King IV), which is the corporate governance code from South Africa. It can be used anywhere to design a robust IT governance system. Of the 5 previously listed frameworks, standards and good practices, the first 2 cannot be neglected. Senior management may decide not to consider the remaining 3.<\/p>\n<p><strong>Step 2: The First Iteration<\/strong><br \/>\nThe first iteration of the functional organization comes straight from COBIT 5 and consists of the following functional elements:<\/p>\n<ul>\n<li>Board of directors (BoD)<\/li>\n<li>Strategy executive committee of the BoD<\/li>\n<li>Steering committee (reporting to the chief executive officer [CEO])<\/li>\n<li>CEO<\/li>\n<li>Chief information officer (CIO)<\/li>\n<li>Evaluate, Direct and Monitor (EDM) domain<\/li>\n<li>Align, Plan and Organize (APO) domain<\/li>\n<li>Build, Acquire and Implement (BAI) domain<\/li>\n<li>Deliver, Service and Support (DSS) domain<\/li>\n<li>Monitor, Evaluate and Assess (MEA) domain<\/li>\n<\/ul>\n<p style=\"text-align: justify\">The accountabilities and responsibilities of these are listed in the various responsible, accountable, consulted and informed (RACI) charts in COBIT 5: Enabling Processes. The accountabilities and responsibilities of the BoD, the strategy committee, the steering committee and all the chief officers (CxOs) can be compiled at this stage from the various RACI charts. The &#8220;Activities&#8221; listed under the respective processes in the EDM domain spell out the activities in which these entities have to be involved. SFIA V6 can then be used to ensure that all skills needed by these entities have been accounted for and are possessed by various stakeholders. At the conclusion of this step, the accountabilities, responsibilities, and activities of the BoD, the strategy committee, the steering committee and the CxOs have been decided and documented.<\/p>\n<p style=\"text-align: justify\"><strong>Step 3: Design the APO, <\/strong>BAI<strong> and DSS Sections<\/strong><br \/>\nThe APO, BAI and DSS domains consists of many subdomains (called processes in COBIT 5). These COBIT 5 processes may need to be grouped to reduce the number of sections and, therefore, the head count. However, in large organizations, each process may be a section by itself. The following are just logical suggestions for possible groupings:<\/p>\n<ul>\n<li style=\"text-align: justify\">APO01 and APO02 may be combined to form a section titled \u201cIT Strategy.\u201d<\/li>\n<li style=\"text-align: justify\">APO03 and APO04 can be combined in a section titled \u201cIT Innovation.\u201d<\/li>\n<li style=\"text-align: justify\">APO05, APO06 and APO07 can, ideally, form the \u201cIT Project Management Office (PMO)\u201d section.<\/li>\n<li style=\"text-align: justify\">APO08, APO09 and APO10 can be combined to form the \u201cService Level Management\u201d section.<\/li>\n<li style=\"text-align: justify\">APO11 and APO12 can be grouped under the \u201cIT Assurance\u201d section.<\/li>\n<li style=\"text-align: justify\">APO13 forms the \u201cInformation Security\u201d (not \u201cIT Security\u201d) section.<\/li>\n<li style=\"text-align: justify\">BAI01 joins the \u201cIT PMO\u201d section, along with APO05, APO06 and APO07 in a medium-sized IT setup. However, it may be a separate section where in-house development is done on a large scale.<\/li>\n<li style=\"text-align: justify\">BAI02, BAI03 and BAI04 should ideally join under a section possibly titled \u201cApplication Design.\u201d<\/li>\n<li style=\"text-align: justify\">BAI05, BAI06 and BAI07 form the \u201cIT Change Management\u201d section.<\/li>\n<li style=\"text-align: justify\">BAI08, BAI09 and BAI10 go under the \u201cAsset and Configuration Management\u201d section.<\/li>\n<li style=\"text-align: justify\">DSS01 forms the very important \u201cIT Operations\u201d section.<\/li>\n<li style=\"text-align: justify\">DSS02 and DSS03 combine in the \u201cIncident and Problem Management\u201d section.<\/li>\n<li style=\"text-align: justify\">DSS04 becomes the \u201cContinuity Management\u201d section.<\/li>\n<li style=\"text-align: justify\">DSS05 becomes the \u201cIT Security\u201d (not \u201cInformation Security\u201d) section.<\/li>\n<li style=\"text-align: justify\">DSS06 forms the \u201cControls Management\u201d section.<\/li>\n<\/ul>\n<p style=\"text-align: justify\">In small IT organizations, these processes may be combined further, taking care that some segregation is maintained and all listed activities and all related metrics have been assigned.<\/p>\n<p style=\"text-align: justify\"><strong>Step 4: Design the MEA Section<\/strong><br \/>\nMedium-sized and large IT setups should preferably have an IT assurance section that ensures that IT governance is being done within the IT setup. It should coordinate with internal audit in the planning and conduct of technology audits. It should also coordinate with the corporate compliance department in the planning, implementation and monitoring of laws, codes, standards and good practices.In small IT shops, the MEA section can be either part of internal audit or split between internal audit and corporate compliance.However, in any case, the activities and the related metrics need to be assigned completely.<\/p>\n<p style=\"text-align: justify\"><strong>Step 5: Design the Job Descriptions<\/strong><br \/>\nHaving designed the organization structure, it is necessary to design the respective job descriptions. Job descriptions can be created as a combination of the activities and the related metrics given by COBIT 5 and the activities listed in SFIA V6. The following has to be ensured to finalize the job descriptions:<\/p>\n<ul>\n<li style=\"text-align: justify\">All activities in COBIT 5 have been assigned.<\/li>\n<li style=\"text-align: justify\">All related metrics in COBIT 5 have been assigned.<\/li>\n<li style=\"text-align: justify\">All skills at all levels of responsibility listed in SFIA V6 have been assigned.<\/li>\n<li style=\"text-align: justify\">Any activities, related metrics and skills (at any level of responsibility) that have not been assigned should be listed and their nonassignment justified.<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><strong>Step 6: Revise the IT Processes<\/strong><br \/>\nThe job descriptions should be synchronized with the IT processes. Therefore, it is necessary that all IT processes are reviewed and the responsibilities therein reassigned to conform to the new job descriptions. IT organization design and maintenance is best done using proper tools. The capabilities required include:<\/p>\n<ul>\n<li style=\"text-align: justify\">Process management<\/li>\n<li style=\"text-align: justify\">Enterprise architecture<\/li>\n<li style=\"text-align: justify\">Risk management<\/li>\n<li style=\"text-align: justify\">Many governance, risk management and compliance (GRC) tools have been assessed and analyzed from the perspective of using them for organization design. A GRC tool that has strong process management capabilities integrated with risk management and enterprise architecture is a must. It is ideal if, in addition, that suite of tools supports a maturity assessment.<\/li>\n<\/ul>\n<p style=\"text-align: justify\">The 6-step process described in this article has been used in designing the organization structures in many organizations, big and small, and it works. The activity may take weeks in large organizations and can be as short as a week in small ones. In using this methodology, there is a need for synchronization between the activities listed in COBIT 5 and the skills described in SFIA V6 at different levels of responsibility.Any reorganization deals directly with humans and there is a human factor that may, at times, oppose the recommendations of this methodology. This factor needs to be considered only to the extent that it does not interfere with the requirements of segregation of duties.The final recommendation is that the organization design be done as per theory and then fine-tuned to accommodate the politics.<\/p>\n<p style=\"text-align: justify\"><strong>Referensi<\/strong><\/p>\n<p><a href=\"http:\/\/www.isaca.org\/COBIT\/focus\/Pages\/using-cobit-for-it-organizational-design.aspx?utm_campaign=ISACA+Main&amp;cid=sm_1208482&amp;utm_content=1482254075&amp;utm_source=facebook&amp;utm_medium=social&amp;appeal=sm\">http:\/\/www.isaca.org\/COBIT\/focus\/Pages\/using-cobit-for-it-organizational-design.aspx?utm_campaign=ISACA+Main&amp;cid=sm_1208482&amp;utm_content=1482254075&amp;utm_source=facebook&amp;utm_medium=social&amp;appeal=sm<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The organizational structure of an IT department is usually the result of a series of changes, trials, experiments and political manipulations. It is often adjusted to suit or accommodate individuals. As a result, the organization is sometimes cumbersome and the cause of problems, inefficiency, and excess cost. The process described herein has been developed from&#8230;<\/p>\n","protected":false},"author":31,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":0,"footnotes":""},"categories":[8],"tags":[],"class_list":["post-3515","post","type-post","status-publish","format-standard","hentry","category-articles"],"gutentor_comment":2,"_links":{"self":[{"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=\/wp\/v2\/posts\/3515","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3515"}],"version-history":[{"count":0,"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=\/wp\/v2\/posts\/3515\/revisions"}],"wp:attachment":[{"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3515"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3515"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itges.rg.telkomuniversity.ac.id\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3515"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}