New Organizational Structure Required for an Effective IT Governance Program With Strong Security
After agencies put an appropriate governance environment in place, they can implement a new and more secure approach to IT.
After agencies put an appropriate governance environment in place, they can implement a new and more secure approach to IT.
This consists of a definition of IT Governance communicated throughout the agency, and the establishment of a new organizational structure to ensure the IT Governance Program is effective and continuously improved. Continuing with the Veterans Affairs Department (VA) example discussed in the previous blog, below is the definition VA developed and a generic discussion of the organizational structure that VA adopted. The VA model provides an excellent example for agencies to consider as they implement IT governance. (Read my first blog on this topic.)
VA defined IT Governance as: “A structure of relationships and processes to direct and control the enterprise in order to achieve the enterprise’s goals by adding value while balancing risk versus return over IT and its processes.” This definition addresses the key issues of risks and value which are two major components of IT Governance – the other major components is resource optimization. And all of this is done to ensure stakeholder needs are being met, the most important of which to the VA is caring for the nation’s veterans, their widows and dependents, in an effective and secure manner. The definition was rolled out to all staff at VA to ensure that all had a common vision of IT Governance. Next VA developed the organizational structure (boards) necessary to ensure that the IT Governance program was effectively implemented within the department.
Below is a generic description of the IT Governance boards depicted above.
Executive Board
The Executive Board performs the following functions:
Strategic Management Council (SMC)
Chaired by the Deputy Secretary, the SMC serves as the senior board making decisions related to IT strategy and technology and assures the formulation of:
The SMC provides business recourse for issues unresolved by the ITLB. It meets at least quarterly and more frequently during the early stages of IT Governance implementation. The SMC is the strategic, priority setting, oversight and issue resolution board for IT matters within the department.
IT Leadership Board (ITLB)
The ITLB is chaired by the Deputy Secretary and includes the Chief Information Officer, deputy under secretaries along with other key staff as determined by each assistant secretary. The ITLB represents the IT services, strategies, principles, governance and resources that support business organizations across the department. Specifically, the ITLB performs the following functions:
Budgeting and Near Term Issues (BNTI) Board
The BNTI Board represents the business units and their needs/requirements for IT investments and monitors the fulfillment of those needs. Specifically, the BNTI Board performs the following functions:
Programming and Long Term Issues (PLTI) Board
The PLTI Board recommends the overall department-wide priorities for IT related business solutions and defines IT service offerings, infrastructure and technology architecture/standards; and is critical to assuring standardization, interoperability, security, privacy, reliability and flexibility of the IT infrastructure. Specifically, the PLTI Board performs the following functions:
Finally, the department established a continuous improvement process for evaluating the IT Governance transformation, not only to gauge prior progress toward a final department-wide vision, but to ensure that IT is being effectively deployed to support all those working or being served by the department in a secure manner This approach provides a model for agencies to adapt in their own journey for IT Governance maturity.