TOPIC: IT GOVERNANCE AND CHANGE MANAGEMENT PROPOSAL
Introduction
The threat to business information, asset-based information, intellectual property, and personal information is increasing day by day. Thereby it is important to control the threat while introducing a new framework that helps to ensure the fundamental needs of the organization. information security management is important as it tends to ensure imperative strategies and secure business threats. Cybercrime and data threat are the major threats of business thereby business spend a huge amount on controlling the threats. Improving quality assurance in the business and working towards COBIT 2019 framework will ensure change management model in the organization. To lift information and communication technologies and security performance, COBIT19 will increasingly ensure improved performance.
Background of the case and problem
There is an intense need to improve the performance of the IT sector while introducing COBIT19. The problems that have been addressed in the education sector is about the annual reports findings in terms of software application, security and protection of data. From the annual report findings, the problems that are illustrated are unsupported software, disaster recovery not tested, outdated technical documentation, weak passwords, agency passwords are longer still weak, complex passwords, inadequate policies, and controls over the passwords, do not address security risk, more support is needed to the staff, remote access systems are vulnerable, not understanding the active directory security risks, accounts are not managed, exposure of sensitive data, considerable time is spent on paperwork, security vulnerabilities and disaster recovery plans are not tested. These issues are increasing every year. From the findings of the annual report, these issues need to be resolved for effective information and communication technologies. It is thereby important to introduce COBIT19 framework to control these issues and work towards better information and communication programs in Western Australia.
COBIT19
COBIT2019 is the most accepted model that ensures the information system audit and control principles. It helps in governing the IT enterprise. The processes and principles that are used in the framework ensure governing IT departments and ensuring domains that are used in the management of the enterprise. It assumes to work for enterprise boards, management level, executives that embrace IT services and enable information as and when necessary. Governance and management are the two categories that are supported by this framework. COBIT framework ensured management objectives and governance principles to be primarily accepted in an educational sector. This is an educational resource that helps IT enterprises and tends to ensure security professionals and assurance. A successful outcome would be ensured while using COBIT 2019 which is the latest framework (ISACA 2019). It is the best framework that helps in understanding, implementing and controlling the enterprise governance of IT. The insights of the COBIT are used as the practices in the business. a broader area of information and technology governance and management framework is assumed in the COBIT 2019 framework. The I&T processing elements are considered to achieve the goal of the organization in terms of governance and management.
COBIT is a framework that ensured the management and governance of IT in the whole enterprise. The technology in the education sector is managed critically by the COBIT framework that will help to achieve organizational goals and solve the problems of the business. As discussed, several issues are released in the annual reports of Western Australian. These issues will be handled when COBIT 2019 will be implemented in the business. It will be a clear distinction of activities that will be performed in terms of management and governance of the enterprise. Government and management are the two principles that will encompass and solve the issues in an organization while performing different activities, organizational structure and work towards serving the best opportunity for the organization.
Governance: Governance principle ensures that the need for stakeholders, options, and conditions will be largely determined while balancing the enterprise objectives. At this time, the direction is well set and prioritization of activities must be the major action taken for the decision making process. With this principle, the performance and compliance activities will be well monitored and agreed upon with certain decisions and objectives. Governance is the responsibility of directors which need to be managed appropriately. Special organizational structures ensure governance responsibilities and work towards a larger emphasize in terms of complex enterprises.
Management: Management plan tends to ensure and builds alignment with the activities and directions. The activities are set by the governance body to fulfil organizational objectives. COBIT is responsible for defining the business components and sustain a governance system appropriately. Process, structures, and policies are ensured in the business while implementing COBIT 2019. Governance issues are solved by the COBIT framework to focus on management objectives and achieve the required capability levels.
Critical analysis of COBIT19
COBIT2019 at times do not satisfy the procedures of governance and management. Some misconceptions are produced by the COBIT framework. It is not an acceptable framework as it tends to ensure governance and management role only. Organizing the business process is not mentioned in the framework which is not the acceptable principle by some organizations. Any IT-related decisions are not considered by COBIT as it only determines the best IT strategy that needs to be used in the business (Grant & Marshak 2011). These are particular challenges of COBIT that need to be focused before implementing in the business.
Change management model
A change management model needs to be implemented in the case of Western Australia. As per the report, the change management project will be introduced that seek to strengthen the governance practice while using COBIT 2019 framework which involved management and governance. The It systems security, business continuity, and information security are the basics that will be used efficiently while planning a COBIT 2019 governance framework. The problems and the issues that are related to IT services tend to ensure that the flexible operations need to be provided in the business (ISACA 2019). From the real insights of the annual report, the information and communication technologies need a flexible system to deliver online learning for students. Thereby from the annual reports, it is largely assumed to use the COBIT19 framework and ensure that the typical shortfalls do not occur in the future. The execution of the pilot project in the education department is expected and designed by resolving issues of the education sector in terms of information and communication technologies. The emphasize is on audit and control of the education sector. Revitalizing ICT governance is necessary for the education department (Pieterse, Caniels & Homan 2012).
Various elements of COBIT 2019 will be adopted in the change management model which includes framework, process descriptions, control objectives, maturity models and management guidelines. Introducing to COBIT 2019 components, the framework ensures methodology to be introduced and the principles alongside with the overall framework and structure.
Source: (Andrade 2016)
Components of the governance system
The major components of governance system include the processes, organizational structures, principles, frameworks, information, culture, people, skills and infrastructure. These components help to satisfy the management objectives while ensuring enterprise rules and sustaining the governance system. Components are thereby the factors that ensure collective utilization of resources, contribute in good operations and work towards governance system in terms of auditing and controlling the activities (Andrade 2016). Components ensure that the results are in holistic governance system while identifying the major types of processes and activities. COBIT 2019 will help the business to align the activities in a single framework and ensure overall strategies to be included such as security compliance, information and communication technologies, risk management and information security. Organizational goals are fulfilled while designing the COBIT framework which emphasizes the need to audit and control the IT systems (Ford & Ford 2010).
To all processes and activities undertaken in an organization, the capability level is assigned that enables the process and capability level in an organization. When the process reaches a capability level, it achieves the business purpose and improves the overall performance of an organization for continuous improvement. COBIT Design Factors are considered for performance outcomes. Adopting COBIT 2019 in the education sector, strategic alignment, risk management, resource management, performance management and value delivery is expected (CIS 2016). It helps to support the organizational objectives while ensuring optimal investment levels. IT services are available and IT issues are resolved while implementing the change model in the business. Security vulnerabilities are minimal and IT service disruptions are controlled with security investment in the organization. Actual access violations are resolved, security incidents are reduced, obsolete accounts are not majorly observed, access rights are provided by the new COBIT 2019 framework.
Source: (ISACA 2019)
COBIT 2019 Framework includes introduction and methodology that helps to expand management services and governance with the updation of terminology and principles. ISACA added to several management objectives which let to managed programs, managed the system, managed programs, and managed assurance.
COBIT 2019 Framework includes Governance and management objectives. COBIT Core model ensures 40 objectives that are correlated with the metrics and related process in terms of enterprise goals.
COBIT 2019 Design Guide includes designing information and technology. This process helps to guide a particular system and apply the COBIT framework. The governance system can be tailored as per the organization’s need and the sourcing models (Ahmad 2013). There are threat landscapes that are predicted while designing information and technology.
COBIT 2019 implementation guide includes implementing information and technology solution for an organization. Necessary information is provided to ensure system adaptation and designing the guide. Some terms and concepts will be implemented in the new change management model of the company.
EDM processes for improving quality assurance
High-quality EDM enterprise document management ensures quality assurance in terms of ICT and information security. Change initiatives are made while addressing the reengineering process to achieve radical change in the business. Continuous improvement is addressed with the EDM processes. Four phases in the EDM process help to provide quality assurance and improvement in ICT services. Creation of EDM groups, identification of actors, EDM quality criteria and continuous improvement in EDM are the four phases (Sebaaoui 2019). Computerized document processing is used in the organization to achieve electronic EDM outcomes. The organizations use reengineering efforts to work towards continuous improvement plans. Systematic EDM process includes continuous improvement in information and technology. There are shared organizational guidelines that ensure IT capabilities which leads to ICT and information security. EDM components and processes ensure electronic document management system (Ahmad & Shamsudin 2013). Utilizing digital documents is increasing in the business as it ensures computerized systems with new skills and information technology systems. There are document management functions that embedded several activities instead of assigning work roles. There is a drastic shift from paperwork to enterprise document management system with the help of reengineering efforts. There is a need for continuous improvement that needs to be managed with continuous improvement in information and technology and ICT measures. Quality assurance is achieved with the EDM process improvement.
Conclusion
COBIT 2019 is the change management model that helps to achieve effective enterprise governance and management in an organization. The updated version ensures the quality of ICT with new processes and information. The two components of COBIT 2019 includes governance and management which are an important driver of information and technology. The business transformation is expected while working on COBIT 2019 which is the latest version that can be applied in the education department in Western Australia. The problem related to information and technology can be solved while taking advantage of the latest technology and framework. Thereby change management intervention is adopted in the form of COBIT 2019 that addresses the shortfalls of ICT systems in Western Australia. In the education department, the pilot project is implemented in brief.
References
Andrade, P., Albuquerque, A., Teofilo, W. & Silva, F., 2016, Change management: implementation and benefits of the change control in the information technology environment, International Journal of Advanced Information Technology (IJAIT) Vol. 6, No. 1, pp. 23-33.
Ahmad, N. & Shamsudin, Z.M., 2013, Systematic approach to successful implementation of ITIL, Procedia computer science, vol. 17, 237 – 244.
Ahmad, N. Amer, T., Qutaifan, F. & Alhilali, A., 2013, Technology adoption model and a road map to the successful implementation of ITIL, Journal of enterprise information management, vol. 26, no. 5, pp. 553-576.
CIS, 2016, Center for Internet Security, The CIS Critical Security Controls for Effective Cyber Defense, Version 6.1.
Ford, J.F. & Ford, L.W., 2010, Stop blaming resistance to change and start using it, Organizational Dynamics, vol. 39 no. 1, pp. 24-36.
Grant, D. & Marshak, R.J., 2011, Toward a discourse-centred understanding of organizational change, The Journal of Applied Behavioral Science, vol. 47, no. 2, pp. 204-35.
ISACA, 2019, COBIT 2019 Framework: Governance and Management Objectives, http://m.isaca.org/Knowledge-Center/Research/Documents/COBIT-2019-Framework-Governance-and-Management-Objectives_res_eng_1118.pdf
Pieterse, J., Daniels, M. & Homan, T., 2012, Professional discourses and resistance to change, Journal of Organizational Change Management, vol. 25, no. 6, pp. 798 – 818
Sebaceous, S., 2019, Design of an ITIL Implementation Model in a Company.” IOSR Journal of Computer Engineering (IOSR-JCE) vol. 21, no. 3, pp. 32-40.