• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: IT Governance
      • Week 2: IT’s Role and the Control Environment
      • Week 3: IT Administrative Controls
      • Week 4: “Add your title”
      • Week 5: “Add your title”
      • Week 6: “Add your title”
      • Week 7: “Add your title”
    • Second Half of the Semester
      • Week 8: “Add your title”
      • Week 9: “Add your title”
      • Week 10: “Add your title”
      • Week 11: “Add your title”
      • Week 12: “Add your title”
      • Week 13: “Add your title”
  • Assignments
    • Project #1
    • Project #2
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5170-Topic: Information Security Regulations

MIS 5170 - Section 003

Fox School of Business

Week 1 Wrap-up: Defining IT Governance

January 15, 2016 by Richard Flanagan Leave a Comment

I think this case is wonderful as an opener for an IT Governance class.  Why?  Because there is no governance at STARS, at least nothing explicit.  If we use my “Right Things, Done Right” mantra, we can illustrate what I mean.  Khan is inheriting an IT organization that has no identifiable mission or charter.  Senior management doesn’t recognize the critical role that IT could play in its organization.  The implicit charter is probably something like, “Give the business what it needs to get the job done.”  That simply isn’t good enough leadership.  On the “Done Right” side, you all have pointed out the deficiencies of the effort (its not even a real organization). No organizational structure, runaway customers, out-of-control contractors, no technical standards, no project portfolio management etc.  The only good news for Khan is that the only way to go is up!

The key point for this class is to recognize that both things are necessary for true governance.  IT organizations, as a generalization, have tended to focus on the process of doing things extremely well and very efficiently.  This is important but it is only half of the game.  IT leadership and company leadership must work together to ensure that IT is doing the things that provide the most value to the company.  This is a political (small p) process and not one that is comfortable to most IT people.  Hence many CIO’s fail because, while they run good IT shops, they are not focused on, nor especially contributing to, the company’s goals.

Throughout this course and the program, keep the “Right Things, Done Right” model in mind.  Many CISA questions will give you three answers that urgently need doing and one that seems so obvious that it can be assumed and ask you which is MOST important.  Don’t fall for the trap, the one is usually about making sure that the organization is doing the right thing and must come first.

Filed Under: Week 01: IT Governance Tagged With:

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Week 01: IT Governance (3)
  • Week 02: IT's Role & the Control Environment (4)
  • Week 03: IT Administrative Controls (2)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in