IT Governance: Notes from the Field

A critical factor in achieving speed of execution is being clear about who gets to make which decisions. Governance is about establishing a framework to ensure that all decisions are made by the right person or persons, according to the importance of the decision and the expertise and organizational responsibilities of the parties to the …

Additional Thoughts on Criteria for Your Business Case Development

In a previous post, I talked about developing a criteria triangle, with the bottom being the systems/data layer, the middle the objectives/tactics layer, and the peak the strategic results layer. The objective is to make sure the criteria that you select hit in the middle and upper layers of the triangle, where folks work in the realm of …

You Need IT-Business Integration, Not Alignment

There are many times when I’m on consulting engagements when I ask CIOs, “How much of an understanding do you and your management have about how your company makes money, thereby having a staff that knows where the money comes from and where it goes?” One of the scariest responses that I have had to that …

Cloud and Virtualization Security: An After Thought

The October conference schedule is now complete and it was a tough one but very rewarding. The events that happened in October were numerous and overlapping in some cases. Travel was one week here and the next week there, yet we managed to get through it. Of the mass of conferences, I attended two, IPexpo as a guest and The ExecEvent and Hacker Halted as a speaker. I discovered something very strange, virtualization and cloud security are merely after thoughts. I felt this should have changed by now, but alas this is not the case. Is it that our scope is incorrect, or is it that there is no Return on Investment on security tools, procedures, etc?