PO06: Communicate Management Aims & Directions

Description Controls KGI KPI CSF Maturity Levels

1. Description

Policies and standards (to translate the strategic options into practical and usable user rules) established and communicated to the Client organizations.

[To top of Page]

2. Control Objectives



[To top of Page]

3. Key Goal Indicators



[To top of Page]

4. Key Performance Indicators



[To top of Page]

5. Critical Success Factors



6. Service Maturity Variations

0 Non-existentManagement has not established a positive information control environment. There is no recognition of the need to establish a set of policies, procedures, standards, and compliance processes.
1 (Initial/Ad Hoc)Management is reactive in addressing the requirements of the information control environment. Policies, procedures and standards are developed and communicated on an ad-hoc, as needed basis, driven primarily by issues. The development, communication and compliance processes are informal and inconsistent.
2 (Repeatable but Intuitive)Management has an implicit understanding of the needs and requirements of an effective information control environment. However, practices are informal and not consistently documented. Management has communicated the need for control policies, procedures and standards, but development is left to the discretion of individual managers and business areas. Policies and other supporting documents are developed based on individual needs and there is no overall development framework. Quality is recognized as a desirable philosophy to be followed, but practices are left to the discretion of individual managers. Training is carried out on an individual, as required basis.
3 (Defined Process)Management has developed, documented and communicated a complete information control and quality management environment that includes a framework for policies, procedures and standards. The policy development process is structured, maintained and known to staff, and the existing policies, procedures and standards are reasonably sound and cover key issues. Management has addressed the importance of IT security awareness and has initiated awareness programmes. Formal training is available to support the information control environment but is not rigorously applied. There is inconsistent monitoring of compliance with the control policies and standards.
4 (Managed and Measurable)Management accepts responsibility for communicating internal control policies and has delegated responsibility and allocated sufficient resources to maintain the environment in line with significant changes. A positive, proactive information control environment, including a commitment to quality and IT security awareness, has been established. A complete set of policies, procedures and standards has been developed, maintained and communicated and is a composite of internal best practices. A framework for roll out and subsequent compliance checks has been established.
5 OptimizedThe information control environment is aligned with the strategic management framework and vision and is frequently reviewed, updated and continuously improved. Internal and external experts are assigned to ensure that industry best practices are being adopted with respect to control guidance and communication techniques. Monitoring, self-assessment and communication processes are pervasive within the organization. Technology is used to maintain policy and awareness knowledge bases and to optimize communication, using office automation and computer based training tools.

[To top of Page]


Visit my web site