|
|
Risk Management is at the core of the decision process. Risk Management answers the concern of the IT Manager who needs to establish a strategic plan based upon informed decisions, to document and to communicate the plan towards his hierarchy and within his department. These are the conditions that enable an organisation to leverage upon IT as a competitive advantage.
|
|
Risk Management highlights
|
| Operational Risk Management |
|
In recent years, information has become increasingly recognised as a strategic resource an organisation has to manage. Information Systems and Information Communication Technologies are the core competencies of any IT department. The role of the IT manager is and will be more and more recognised as key to the success of the business (even if organisation charts do not always cope with this (too) rapid evolution). What does this IT manager role consist into?
|
Over years, the IT manager main focus has moved from technology to organisation: the IT manager needs to make sure that the IT department is up to fulfil requirements formulated by the business and up to conduct business safely.
|
Paradigmo promotes Risk Management as a methodoly to assist the IT managers to fulfil their management responsibilities. Risk Management has different flavours, detailled in the table here below:
|
|
|
Purpose |
Stakeholders |
Deliverables |
Reference frameworks |
|
Information Security |
make sure the business can be conducted safely from a security perspective |
company managers, including IT |
security requirements as expressed by the company managers in terms of confidentiality, integrity, availability, analysis of the 'AS IS' and 'TO BE' gap analysis and project roadmap |
ISO 17799,CobiT |
|
Operational Risk Management |
make sure the business can be conducted safely from an operational perspective |
IT internal customers |
operational requirements as expressed by the internal IT customers in terms of confidentiality, integrity, availability, analysis of the 'AS IS' and 'TO BE'; gap analysis and project roadmap |
ITIL |
|
IT Governance |
make sure business and IT objectives are aligned |
company managers, including IT |
fonctional requirements as expressed by the company managers, analysis of the 'AS IS' and 'TO BE' gap analysis and project roadmap |
CobiT |
|
Identity Risk Management |
make sure that identities are dealt with in such a way that business can be conducted safely, complies to legal obligations and that management of identities is cost effective |
company managers, including IT |
fonctional and security requirements as expressed by the company managers, analysis of the 'AS IS' and 'TO BE' gap analysis and project roadmap |
CobiT |
A common benefit of all flavours of Risk Management is to provide to the IT manager a deliverable which is agreed upon by the decision makers of the organisation. The deliverable contains a roadmap the IT manager can refer to in order to draw his strategy for a 3-5 years period.
|
|
|
|