SlideShare uma empresa Scribd logo
1 de 26
Baixar para ler offline
Session S12
Implementing COBIT® in your
OrganizationOrganization
by
Debra Mallette, CISA, CGEIT, CSSBB
Implementing COBIT® in your organization
• Implementing COBIT Program:
– Organizational Change
– IT Governance Program
– Iterative approach to implementation
• Learning Objectives:
– definitions and context
– basic process
– lessons learned– lessons learned
– success factors
– risk mitigation
– how to adapt these for your organization.
• Pre-requisites:
– "COBIT Foundation Certificate"
– familiarity with ValIT and RiskIT
2
Why are you here (in this session)?
• Assignment?
• Champion?
• Career Advancement?
• Curiosity?• Curiosity?
• All of the above?
• Other?
3
Current COBIT®
4
COBIT5.0®Future-C
5
Why implement COBIT?
How to implement COBIT – Basic Process
7
1. What are the Drivers?
• Pain Points + Trigger Events -> Need for
Governance!
2. Where are we now?
• Define the Problems and Opportunities
• Form Powerful Guiding Team
• Assess the Current State
6. Did we get there?
• Realize the benefits
• Embed new approaches
• Operate and Measure
7. How do we keep momentum going?
• Review the Programme effectiveness
• Sustain
• Monitor and Evaluate
8
4. What needs to be done?
• Develop Programme Plan
• Empower Role Players and Identify Quick Wins
• Design and Build Improvements
5. How do we get there?
• Execute the Plan
• Enable Operation and Use
• Implement Improvements
3. Where do we want to be?
• Define the Roadmap
• Communicate (communicate, ….)
• Define Target State and Perform Gap
Analysis
1. What are the Drivers?
• Pain Points + Trigger Events -> Need for
Governance!
2. Where are we now?
• Define the Problems and Opportunities
• Form Powerful Guiding Team
• Assess the Current State
6. Did we get there?
• Realize the benefits
• Embed new approaches
• Operate and Measure
7. How do we keep momentum going?
• Review the Programme effectiveness
• Sustain
• Monitor and Evaluate
9
3. Where do we want to be?
• Define the Roadmap
• Communicate (communicate, ….)
• Define Target State and Perform Gap
Analysis
4. What needs to be done?
• Develop Programme Plan
• Empower Role Players and Identify Quick Wins
• Design and Build Improvements
5. How do we get there?
• Execute the Plan
• Enable Operation and Use
• Implement Improvements
Lessons Learned
Success Factors
RisksRisks
10
• Senior Management not bought in
• Lack of Enterprise policy and direction
• Cost of Improvements outweigh perceived benefits
• Lack of trust and good relations between business and IT
• Resistance to Change
• Lack of Understanding of IT Governance
1111
• Trying to do too much at once
• IT in fire-fighting mode, not able to prioritize tasks
• Lack of appropriate IT skills in place
• Improvements not adopted or applied
• Benefits difficult to show or prove
Lessons Learned: Deal with the People
• Must assure that people in the organization
adopt, use and sustain the practices
• People, employing the practices, generate the
benefits to the organization
• Must understand, communicate, influence• Must understand, communicate, influence
and persuade people with the case for change
• Failure to establish a measurable target
12
Lesson Learned: Failure is Likely
The Diffusion of Innovations Model
Laggards
Late
Majority
Early
Success
%ofPopulationUsingTechnology
50%
80%
13
Ref: Diffusion of Innovations, 3rd Ed.
by Everett Rogers; Simon & Schuster, 1995
Early
Majority
Innovator
Early
Adopter/
%ofPopulationUsingTechnology
Time
20%
Failure
Ref: Diffusion of Innovations, 3rd Ed.
by Everett Rogers; Simon & Schuster, 1995
Lesson Learned: People employing practices
generate benefits to organization
Highest ROI= Effectiveness &
Cycle Time to Use
Return = f (Use (Population,Effectiveness),Synergy(1/Time))
Investment = g (Infrastructure,Culture,Transition Process)
Return on Investment = (f - g ) / g
ReturnonInvestment
+
14
ReturnonInvestment
Time
+
-
O
Failed Transitions lose money
Lesson Learned: Improvements not sustained
SMART Implementation Goal:
• At least 80% of the target users in the
organization effectively & efficiently use the
improvement.
• There is evidence of sustained use and• There is evidence of sustained use and
improving effectiveness and efficiency.
• The organization has measurable results.
• People new to the organization, are told
what to do and learn how to do it.
15
Lesson Learned: Improvements not applied
Attributes of Effective Use
3
4
5
LevelofEffectiveUse
Formalized
Prevention
Focus
Org-wide
Standard
Looked for on
Major projects
Req’d on all
major projects
Valued in
organization
Par with
Industry
Prevention &
Optimization
Some
More
Formalized
Recognized
as value-added
Metrics drive
Improvements
16
Ref: “Key Lessons in Achieving Widespread Inspections Use”
by Grady & Van Slack, IEEE Software July 1994
Objectives ComplianceProcess Infrastructure
1
2
3
LevelofEffectiveUse
None
Formalized
“Guideline”
Major projects
Avoided with
Pride
Favorably
Noticed
None
Defined
Industry
None
Training for
Practitioners
Some
Documented
Lesson Learned: Benefits difficult to measure
Use => Benefits!
Question:
• Who is using it?
• How often?
• For what?
• Where in org?
Metric Source
l User id’s
l Hit rate
l Hit paths & operations
l Tie to org chart
17
• Where in org?
• How widespread?
• Users satisfied?
• Is the use making an
impact on the business?
l Tie to org chart
l Diffusion Curve
l User responses
l Correlation to business
information
Lesson Learned: Making the case is important
Process Paradox
Salience
Investment
Mandated
Background
Priority
Identity
The case made for this change
assures mind share & resources
when prioritized with everything
else
This is the case made
for most capability
improvements. Lack
of buy-in or support is
guaranteed.
18
Return
Investment
Mandated
Income Generated
Income Lost
Fixed Costs Reduced
Variable Costs Reduced
Insurance Small Medium Large
Lesson Learned: Resistance to Change
Middle Management Black Hole
19
Implementation follow-through in organization:
Development->Test->Production (Service Delivery)
• Each must be resourced and managed.
• Who has what accountability and responsibility for
sustaining or service delivery activities in the COBIT
implementation?
• How do you assure the implementation is sustained• How do you assure the implementation is sustained
through re-orgs?
• What is the SLA/OLA’s for delivering the IT
Governance service?
• How are sustaining / service delivery functions
resourced or financed?
20
Risk Mitigation – List, prioritize, plan
Risks/challenges Challenge for you? Plan to address?
• Senior Management not bought in
• Lack of Enterprise policy and direction
• Resistance to Change
• Lack of Understanding of IT Governance
• Trying to do too much at once
• IT in fire-fighting mode, not able to prioritize• IT in fire-fighting mode, not able to prioritize
• Lack of appropriate IT skills in place
• Improvements not adopted or applied
• Benefits difficult to show or prove
• Cost of Improvements outweigh perceived
benefits
21
Change Enablement:
Based on Cotter Model
Establish a sense of urgency
Form a powerful guiding coalition
Create and communicate a clear vision, expressed simply
Empower others to act on the vision, identifying and implementing quick-wins
Program Management:
1. Initiate program
2. Define problems and opportunities
3. Define roadmap
4. Develop program plan
5. Execute plan
6. Realize benefits
Empower others to act on the vision, identifying and implementing quick-wins
Enable use and implement improvements/produce more change
Institutionalize new approaches
Sustain
6. Realize benefits
7. Review program effectiveness
Adapting these to your organization
Please take 10 minutes to discuss amongst yourselves:
• Your role?
• What implementation phase to start at?
• What’s your target (big Why)?
• What risks need to be managed?
• What methods to use?
• What resourcing approach?
23
Discussion Report outDiscussion Report out
24
Wrap-up:
Implementing COBIT® in your organization
25
Smarts and action are on the same side of the equation where the sum is success.
~Garrett Hazel
Speaker Contact Information
Debra Mallette, CGEIT, CISA, CSSBB
4460 Hacienda Dr, Building F -1039
Pleasanton, CA 94588-2761
Office Phone: 925 924 5123
26
Office Phone: 925 924 5123
Cell: 510-295-3217
debra.mallette@kp.org

Mais conteúdo relacionado

Mais procurados

Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGoutama Bachtiar
 
Introduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT managementIntroduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT managementChristian F. Nissen
 
COBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdfCOBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdfMartinPatrici
 
IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5Eryk Budi Pratama
 
Cobit 2019 framework by ISACA
Cobit 2019 framework by ISACACobit 2019 framework by ISACA
Cobit 2019 framework by ISACAMDFazlaRabbiAbir
 
IT4IT and DevOps Tools Landscape (2020).
IT4IT and DevOps Tools Landscape (2020).IT4IT and DevOps Tools Landscape (2020).
IT4IT and DevOps Tools Landscape (2020).Rob Akershoek
 
Cobit 2019 foundation study material
Cobit 2019 foundation study materialCobit 2019 foundation study material
Cobit 2019 foundation study materialAnees Shaikh
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500Ramiro Cid
 
IT Architecture’s Role In Solving Technical Debt.pdf
IT Architecture’s Role In Solving Technical Debt.pdfIT Architecture’s Role In Solving Technical Debt.pdf
IT Architecture’s Role In Solving Technical Debt.pdfAlan McSweeney
 
Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGoutama Bachtiar
 
Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Managementjiricejka
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance FrameworkSherri Booher
 
What is ISO20000
What is ISO20000What is ISO20000
What is ISO20000Ben Kalland
 
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?PECB
 
COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)
COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)
COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)ISACA Riyadh
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?PECB
 

Mais procurados (20)

Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 Framework
 
Introduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT managementIntroduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT management
 
COBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdfCOBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdf
 
IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5
 
Cobit 2019 framework by ISACA
Cobit 2019 framework by ISACACobit 2019 framework by ISACA
Cobit 2019 framework by ISACA
 
IT4IT and DevOps Tools Landscape (2020).
IT4IT and DevOps Tools Landscape (2020).IT4IT and DevOps Tools Landscape (2020).
IT4IT and DevOps Tools Landscape (2020).
 
Cobit 2019 foundation study material
Cobit 2019 foundation study materialCobit 2019 foundation study material
Cobit 2019 foundation study material
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500
 
IT Architecture’s Role In Solving Technical Debt.pdf
IT Architecture’s Role In Solving Technical Debt.pdfIT Architecture’s Role In Solving Technical Debt.pdf
IT Architecture’s Role In Solving Technical Debt.pdf
 
Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 Framework
 
IT Governance
IT GovernanceIT Governance
IT Governance
 
Cobit 5 - An Overview
Cobit 5 - An OverviewCobit 5 - An Overview
Cobit 5 - An Overview
 
Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
 
Cobit_5_Checklist.pdf
Cobit_5_Checklist.pdfCobit_5_Checklist.pdf
Cobit_5_Checklist.pdf
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance Framework
 
What is ISO20000
What is ISO20000What is ISO20000
What is ISO20000
 
It governance & cobit 5
It governance & cobit 5It governance & cobit 5
It governance & cobit 5
 
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
 
COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)
COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)
COBIT 5.0 Vs ISO / IEC 38500 (IT Governance)
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 

Destaque

Thinking of COBIT implementation – Where to start?
Thinking of COBIT implementation – Where to start?Thinking of COBIT implementation – Where to start?
Thinking of COBIT implementation – Where to start?Vyom Labs
 
Cybersecurity for Energy: Moving Beyond Compliance
Cybersecurity for Energy: Moving Beyond ComplianceCybersecurity for Energy: Moving Beyond Compliance
Cybersecurity for Energy: Moving Beyond ComplianceEnergySec
 
Modeling Enterprise Risk Management and Security with the ArchiMate Language
Modeling Enterprise Risk Management and Security with the ArchiMate LanguageModeling Enterprise Risk Management and Security with the ArchiMate Language
Modeling Enterprise Risk Management and Security with the ArchiMate LanguageIver Band
 
COBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From ManagementCOBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From ManagementMohammad Reda Katby
 
Cobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder NeedsCobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder NeedsMohammad Reda Katby
 
COBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated FrameworkCOBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated FrameworkMohammad Reda Katby
 
iDialoghi - ICT Security Consulting
iDialoghi - ICT Security ConsultingiDialoghi - ICT Security Consulting
iDialoghi - ICT Security ConsultingiDIALOGHI
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachMohammad Reda Katby
 
COBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-EndCOBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-EndMohammad Reda Katby
 
RBI Cyber Security Guidelines- FixNix GRC
RBI Cyber Security Guidelines- FixNix GRCRBI Cyber Security Guidelines- FixNix GRC
RBI Cyber Security Guidelines- FixNix GRCFixNix Inc.,
 
IT4IT - itSMFUK v4 (3)
IT4IT - itSMFUK v4 (3)IT4IT - itSMFUK v4 (3)
IT4IT - itSMFUK v4 (3)Tony Price
 
COBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an IntroductionCOBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an Introductionaqel aqel
 

Destaque (20)

Thinking of COBIT implementation – Where to start?
Thinking of COBIT implementation – Where to start?Thinking of COBIT implementation – Where to start?
Thinking of COBIT implementation – Where to start?
 
Cybersecurity for Energy: Moving Beyond Compliance
Cybersecurity for Energy: Moving Beyond ComplianceCybersecurity for Energy: Moving Beyond Compliance
Cybersecurity for Energy: Moving Beyond Compliance
 
COBIT®5 - Assessor
COBIT®5 - AssessorCOBIT®5 - Assessor
COBIT®5 - Assessor
 
COBIT®5 - Foundation
COBIT®5 - FoundationCOBIT®5 - Foundation
COBIT®5 - Foundation
 
What is Cobit
What is CobitWhat is Cobit
What is Cobit
 
4 mock exam tips 2
4 mock exam tips 24 mock exam tips 2
4 mock exam tips 2
 
Modeling Enterprise Risk Management and Security with the ArchiMate Language
Modeling Enterprise Risk Management and Security with the ArchiMate LanguageModeling Enterprise Risk Management and Security with the ArchiMate Language
Modeling Enterprise Risk Management and Security with the ArchiMate Language
 
COBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From ManagementCOBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From Management
 
RBI Gopalakrishna Committee Report on IT
RBI Gopalakrishna Committee Report on ITRBI Gopalakrishna Committee Report on IT
RBI Gopalakrishna Committee Report on IT
 
Cobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder NeedsCobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder Needs
 
COBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated FrameworkCOBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated Framework
 
iDialoghi - ICT Security Consulting
iDialoghi - ICT Security ConsultingiDialoghi - ICT Security Consulting
iDialoghi - ICT Security Consulting
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic Approach
 
COBIT5 Implementation Guidance
COBIT5 Implementation GuidanceCOBIT5 Implementation Guidance
COBIT5 Implementation Guidance
 
COBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-EndCOBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-End
 
RBI Cyber Security Guidelines- FixNix GRC
RBI Cyber Security Guidelines- FixNix GRCRBI Cyber Security Guidelines- FixNix GRC
RBI Cyber Security Guidelines- FixNix GRC
 
IT4IT - itSMFUK v4 (3)
IT4IT - itSMFUK v4 (3)IT4IT - itSMFUK v4 (3)
IT4IT - itSMFUK v4 (3)
 
COBIT®5 - Implementation
COBIT®5 - ImplementationCOBIT®5 - Implementation
COBIT®5 - Implementation
 
Cobit 5 Business Framework -Governance and Management of Enterprise IT
Cobit 5  Business Framework -Governance and Management of Enterprise ITCobit 5  Business Framework -Governance and Management of Enterprise IT
Cobit 5 Business Framework -Governance and Management of Enterprise IT
 
COBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an IntroductionCOBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an Introduction
 

Semelhante a Implement cobit in your organization

Prosci Change Maturity Community of Practice webinar
Prosci Change Maturity Community of Practice webinar Prosci Change Maturity Community of Practice webinar
Prosci Change Maturity Community of Practice webinar Catherine Smithson
 
Leading Cultural Change
Leading Cultural ChangeLeading Cultural Change
Leading Cultural ChangeMary Fisher
 
Proactive Governance & Adoption in Microsoft 365
Proactive Governance & Adoption in Microsoft 365Proactive Governance & Adoption in Microsoft 365
Proactive Governance & Adoption in Microsoft 365Richard Harbridge
 
An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?
An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?
An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?Cprime
 
Evaluate the Effectiveness of Your Online Learning & Training Programs
Evaluate the Effectiveness of Your Online Learning & Training ProgramsEvaluate the Effectiveness of Your Online Learning & Training Programs
Evaluate the Effectiveness of Your Online Learning & Training ProgramsNimritta Parmar
 
PM-Champion-PPT-11-10-2020.pdf
PM-Champion-PPT-11-10-2020.pdfPM-Champion-PPT-11-10-2020.pdf
PM-Champion-PPT-11-10-2020.pdfErmiyas Tariku
 
10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...
10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...
10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...YeurDreamin'
 
Tackling Adoption Like A Service With Office 365 - Microsoft Ignite
Tackling Adoption Like A Service With Office 365 - Microsoft IgniteTackling Adoption Like A Service With Office 365 - Microsoft Ignite
Tackling Adoption Like A Service With Office 365 - Microsoft IgniteRichard Harbridge
 
FCB Partners Course Preview: Process Owners in Action
FCB Partners Course Preview:  Process Owners in ActionFCB Partners Course Preview:  Process Owners in Action
FCB Partners Course Preview: Process Owners in ActionFCBPartners
 
IT satisfaction.pdf
IT satisfaction.pdfIT satisfaction.pdf
IT satisfaction.pdfJohnDough52
 
Operating Model & Organization Design Toolkit and Playbook
Operating Model & Organization Design Toolkit and PlaybookOperating Model & Organization Design Toolkit and Playbook
Operating Model & Organization Design Toolkit and PlaybookAurelien Domont, MBA
 
QI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptx
QI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptxQI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptx
QI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptxsovvie
 
Construction Futures Wales - Leadership & Management Taster Session
Construction Futures Wales - Leadership & Management Taster SessionConstruction Futures Wales - Leadership & Management Taster Session
Construction Futures Wales - Leadership & Management Taster SessionRae Davies
 
Cross functional team leadership workshop prospectus v2
Cross functional team leadership workshop prospectus v2Cross functional team leadership workshop prospectus v2
Cross functional team leadership workshop prospectus v2Martin Stein
 
Having a PMO with agile flavor
Having a PMO with agile flavorHaving a PMO with agile flavor
Having a PMO with agile flavorImad Alsadeq
 

Semelhante a Implement cobit in your organization (20)

Prosci Change Maturity Community of Practice webinar
Prosci Change Maturity Community of Practice webinar Prosci Change Maturity Community of Practice webinar
Prosci Change Maturity Community of Practice webinar
 
Leading Cultural Change
Leading Cultural ChangeLeading Cultural Change
Leading Cultural Change
 
Proactive Governance & Adoption in Microsoft 365
Proactive Governance & Adoption in Microsoft 365Proactive Governance & Adoption in Microsoft 365
Proactive Governance & Adoption in Microsoft 365
 
Synergis60: 6 Critical Steps to Implementing Data Managment
Synergis60: 6 Critical Steps to Implementing Data ManagmentSynergis60: 6 Critical Steps to Implementing Data Managment
Synergis60: 6 Critical Steps to Implementing Data Managment
 
An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?
An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?
An Outcome Measurement Model: Is your Agile Adoption Moving the Needle?
 
Evaluate the Effectiveness of Your Online Learning & Training Programs
Evaluate the Effectiveness of Your Online Learning & Training ProgramsEvaluate the Effectiveness of Your Online Learning & Training Programs
Evaluate the Effectiveness of Your Online Learning & Training Programs
 
PM-Champion-PPT-11-10-2020.pdf
PM-Champion-PPT-11-10-2020.pdfPM-Champion-PPT-11-10-2020.pdf
PM-Champion-PPT-11-10-2020.pdf
 
6 Sigma - Chapter7
6 Sigma - Chapter76 Sigma - Chapter7
6 Sigma - Chapter7
 
Workshop - Innovation Readiness
Workshop - Innovation ReadinessWorkshop - Innovation Readiness
Workshop - Innovation Readiness
 
10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...
10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...
10 Lessons of Salesforce Nonprofit implementations from a Customer and Integr...
 
Tackling Adoption Like A Service With Office 365 - Microsoft Ignite
Tackling Adoption Like A Service With Office 365 - Microsoft IgniteTackling Adoption Like A Service With Office 365 - Microsoft Ignite
Tackling Adoption Like A Service With Office 365 - Microsoft Ignite
 
FCB Partners Course Preview: Process Owners in Action
FCB Partners Course Preview:  Process Owners in ActionFCB Partners Course Preview:  Process Owners in Action
FCB Partners Course Preview: Process Owners in Action
 
IT satisfaction.pdf
IT satisfaction.pdfIT satisfaction.pdf
IT satisfaction.pdf
 
Operating Model & Organization Design Toolkit and Playbook
Operating Model & Organization Design Toolkit and PlaybookOperating Model & Organization Design Toolkit and Playbook
Operating Model & Organization Design Toolkit and Playbook
 
Tm book
Tm bookTm book
Tm book
 
QI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptx
QI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptxQI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptx
QI-Leadership-Assessment_Group-Scoring-Slides algemeen.pptx
 
Construction Futures Wales - Leadership & Management Taster Session
Construction Futures Wales - Leadership & Management Taster SessionConstruction Futures Wales - Leadership & Management Taster Session
Construction Futures Wales - Leadership & Management Taster Session
 
Lean Transformation
Lean TransformationLean Transformation
Lean Transformation
 
Cross functional team leadership workshop prospectus v2
Cross functional team leadership workshop prospectus v2Cross functional team leadership workshop prospectus v2
Cross functional team leadership workshop prospectus v2
 
Having a PMO with agile flavor
Having a PMO with agile flavorHaving a PMO with agile flavor
Having a PMO with agile flavor
 

Implement cobit in your organization

  • 1. Session S12 Implementing COBIT® in your OrganizationOrganization by Debra Mallette, CISA, CGEIT, CSSBB
  • 2. Implementing COBIT® in your organization • Implementing COBIT Program: – Organizational Change – IT Governance Program – Iterative approach to implementation • Learning Objectives: – definitions and context – basic process – lessons learned– lessons learned – success factors – risk mitigation – how to adapt these for your organization. • Pre-requisites: – "COBIT Foundation Certificate" – familiarity with ValIT and RiskIT 2
  • 3. Why are you here (in this session)? • Assignment? • Champion? • Career Advancement? • Curiosity?• Curiosity? • All of the above? • Other? 3
  • 7. How to implement COBIT – Basic Process 7
  • 8. 1. What are the Drivers? • Pain Points + Trigger Events -> Need for Governance! 2. Where are we now? • Define the Problems and Opportunities • Form Powerful Guiding Team • Assess the Current State 6. Did we get there? • Realize the benefits • Embed new approaches • Operate and Measure 7. How do we keep momentum going? • Review the Programme effectiveness • Sustain • Monitor and Evaluate 8 4. What needs to be done? • Develop Programme Plan • Empower Role Players and Identify Quick Wins • Design and Build Improvements 5. How do we get there? • Execute the Plan • Enable Operation and Use • Implement Improvements 3. Where do we want to be? • Define the Roadmap • Communicate (communicate, ….) • Define Target State and Perform Gap Analysis
  • 9. 1. What are the Drivers? • Pain Points + Trigger Events -> Need for Governance! 2. Where are we now? • Define the Problems and Opportunities • Form Powerful Guiding Team • Assess the Current State 6. Did we get there? • Realize the benefits • Embed new approaches • Operate and Measure 7. How do we keep momentum going? • Review the Programme effectiveness • Sustain • Monitor and Evaluate 9 3. Where do we want to be? • Define the Roadmap • Communicate (communicate, ….) • Define Target State and Perform Gap Analysis 4. What needs to be done? • Develop Programme Plan • Empower Role Players and Identify Quick Wins • Design and Build Improvements 5. How do we get there? • Execute the Plan • Enable Operation and Use • Implement Improvements
  • 11. • Senior Management not bought in • Lack of Enterprise policy and direction • Cost of Improvements outweigh perceived benefits • Lack of trust and good relations between business and IT • Resistance to Change • Lack of Understanding of IT Governance 1111 • Trying to do too much at once • IT in fire-fighting mode, not able to prioritize tasks • Lack of appropriate IT skills in place • Improvements not adopted or applied • Benefits difficult to show or prove
  • 12. Lessons Learned: Deal with the People • Must assure that people in the organization adopt, use and sustain the practices • People, employing the practices, generate the benefits to the organization • Must understand, communicate, influence• Must understand, communicate, influence and persuade people with the case for change • Failure to establish a measurable target 12
  • 13. Lesson Learned: Failure is Likely The Diffusion of Innovations Model Laggards Late Majority Early Success %ofPopulationUsingTechnology 50% 80% 13 Ref: Diffusion of Innovations, 3rd Ed. by Everett Rogers; Simon & Schuster, 1995 Early Majority Innovator Early Adopter/ %ofPopulationUsingTechnology Time 20% Failure Ref: Diffusion of Innovations, 3rd Ed. by Everett Rogers; Simon & Schuster, 1995
  • 14. Lesson Learned: People employing practices generate benefits to organization Highest ROI= Effectiveness & Cycle Time to Use Return = f (Use (Population,Effectiveness),Synergy(1/Time)) Investment = g (Infrastructure,Culture,Transition Process) Return on Investment = (f - g ) / g ReturnonInvestment + 14 ReturnonInvestment Time + - O Failed Transitions lose money
  • 15. Lesson Learned: Improvements not sustained SMART Implementation Goal: • At least 80% of the target users in the organization effectively & efficiently use the improvement. • There is evidence of sustained use and• There is evidence of sustained use and improving effectiveness and efficiency. • The organization has measurable results. • People new to the organization, are told what to do and learn how to do it. 15
  • 16. Lesson Learned: Improvements not applied Attributes of Effective Use 3 4 5 LevelofEffectiveUse Formalized Prevention Focus Org-wide Standard Looked for on Major projects Req’d on all major projects Valued in organization Par with Industry Prevention & Optimization Some More Formalized Recognized as value-added Metrics drive Improvements 16 Ref: “Key Lessons in Achieving Widespread Inspections Use” by Grady & Van Slack, IEEE Software July 1994 Objectives ComplianceProcess Infrastructure 1 2 3 LevelofEffectiveUse None Formalized “Guideline” Major projects Avoided with Pride Favorably Noticed None Defined Industry None Training for Practitioners Some Documented
  • 17. Lesson Learned: Benefits difficult to measure Use => Benefits! Question: • Who is using it? • How often? • For what? • Where in org? Metric Source l User id’s l Hit rate l Hit paths & operations l Tie to org chart 17 • Where in org? • How widespread? • Users satisfied? • Is the use making an impact on the business? l Tie to org chart l Diffusion Curve l User responses l Correlation to business information
  • 18. Lesson Learned: Making the case is important Process Paradox Salience Investment Mandated Background Priority Identity The case made for this change assures mind share & resources when prioritized with everything else This is the case made for most capability improvements. Lack of buy-in or support is guaranteed. 18 Return Investment Mandated Income Generated Income Lost Fixed Costs Reduced Variable Costs Reduced Insurance Small Medium Large
  • 19. Lesson Learned: Resistance to Change Middle Management Black Hole 19
  • 20. Implementation follow-through in organization: Development->Test->Production (Service Delivery) • Each must be resourced and managed. • Who has what accountability and responsibility for sustaining or service delivery activities in the COBIT implementation? • How do you assure the implementation is sustained• How do you assure the implementation is sustained through re-orgs? • What is the SLA/OLA’s for delivering the IT Governance service? • How are sustaining / service delivery functions resourced or financed? 20
  • 21. Risk Mitigation – List, prioritize, plan Risks/challenges Challenge for you? Plan to address? • Senior Management not bought in • Lack of Enterprise policy and direction • Resistance to Change • Lack of Understanding of IT Governance • Trying to do too much at once • IT in fire-fighting mode, not able to prioritize• IT in fire-fighting mode, not able to prioritize • Lack of appropriate IT skills in place • Improvements not adopted or applied • Benefits difficult to show or prove • Cost of Improvements outweigh perceived benefits 21
  • 22. Change Enablement: Based on Cotter Model Establish a sense of urgency Form a powerful guiding coalition Create and communicate a clear vision, expressed simply Empower others to act on the vision, identifying and implementing quick-wins Program Management: 1. Initiate program 2. Define problems and opportunities 3. Define roadmap 4. Develop program plan 5. Execute plan 6. Realize benefits Empower others to act on the vision, identifying and implementing quick-wins Enable use and implement improvements/produce more change Institutionalize new approaches Sustain 6. Realize benefits 7. Review program effectiveness
  • 23. Adapting these to your organization Please take 10 minutes to discuss amongst yourselves: • Your role? • What implementation phase to start at? • What’s your target (big Why)? • What risks need to be managed? • What methods to use? • What resourcing approach? 23
  • 25. Wrap-up: Implementing COBIT® in your organization 25 Smarts and action are on the same side of the equation where the sum is success. ~Garrett Hazel
  • 26. Speaker Contact Information Debra Mallette, CGEIT, CISA, CSSBB 4460 Hacienda Dr, Building F -1039 Pleasanton, CA 94588-2761 Office Phone: 925 924 5123 26 Office Phone: 925 924 5123 Cell: 510-295-3217 debra.mallette@kp.org