IT Governance Fit & Function
CIOREVIEW >> IT Service Management >> NEWS

Churchill Downs Incorporated [NASDAQ: CHDN]

Daniel Poff, Senior Director IT Governance

IT Governance Fit & Function

Daniel Poff, Senior Director IT Governance
Daniel Poff, Senior Director IT Governance, Churchill Downs Incorporated [NASDAQ: CHDN]

IT Governance is broad, reaching across all IT functions. The image below depicts the five domains of the IT Governance Framework that primarily come from COBIT (Control Objectives from Information and Related Technologies), which is a framework developed by ISACA (Information Systems Audit and Control Association).

COBIT has evolved through several versions since its initial release in 1996, with the framework being refined and updated to reflect changing business and technological needs. The current five domains in COBIT 2019 are:

1. Evaluate, Direct and Monitor (EDM) – Governance processes.

2. Align, Plan and Organize (APO) – Strategic alignment and planning.

3. Build, Acquire and Implement (BAI) – Solution development and implementation.

4. Deliver, Service and Support (DSS) – Service delivery and support.

5. Monitor, Evaluate and Assess (MEA) – Performance monitoring and compliance

These domains represent a logical grouping of governance and management processes that companies need to effectively govern and manage their information and technology investments. Now there are different IT governance frameworks that may present slightly different domain structures e.g., ITIL (Information Technology Infrastructure Library), or ISO/IEC 38500 (the international standard for IT governance). However, COBIT’s five-domain structure is the most widely adopted model for comprehensive IT governance.

  IT governance is not a onetime project but a continuous journey to strengthen and mature every aspect of technology  

There are approximately fifty core IT processes that span across functional areas such as Governance Risk & Compliance, Strategy & Innovation, Project & Portfolio Management, Enterprise Architecture, IT Financial & Vendor Management, and Infrastructure & Operations, just to name a few. Let us take Infrastructure & Operations, we can break it down to processes like Asset & Configuration Management, Change & Release Management, Availability & Capacity Management, and Incident & Problem Management.

So where does one start? Have you heard the adage, “How do you swallow and elephant, one bite at a time,” well that pretty much relates to IT Governance. For many companies that are just starting on this journey I would advise picking some block and tackle processes e.g., Asset & Configuration Management. Perform an audit of the process and determine its maturity level, identify gaps and shortcomings, and implement corrective actions that will mature the process, then move on to another one, and then another one. Also, this is cyclic, like painting a large ship, by the time you think you are done its time to start over again. Depending on resources it could take years to address all the processes in the framework.

Another area that IT Governance continuously addresses is who owns what and who has the authority to make decisions. One of the first surveys I did when I started at my current company, specifically directed at IT management, I only asked a couple questions related to all the processes in the framework. The first one was, “how mature do you feel this process is currently,” and the second one, “who is accountable for the process.” The results spoke for themselves, it was easy to identify processes that were much less mature than others, e.g., IT Strategy versus Incident management. More importantly ownership of a process was all over the board, many thought they owned it when they really did not, or that someone else owned it and that was not the case either.

Early on I was asked to help write an IT policy, being new to the company I asked where I could find the approved policy template and what the process was for reviewing, approving, and publishing the policy. I received the deer in the headlights look and my red flag went up; there was not a defined approved template or process. So, my team created the IT Policy Framework specific to our IT organization. We defined not only the policy template but also a template for documenting Standard Operating Procedures, How-To, and Guideline documents. We used Microsoft SharePoint as our document repository where the templates would be located, and SharePoint managed version control. We laid out the process to get a policy reviewed and approved, once a draft is ready it is sent to corporate legal for review, and if HR needs to be involved legal will bring them in. Once its reviewed and approved by legal/HR, it is put on the IT Steering Committee agenda for approval. There were no IT committees when I started, so we created the IT Steering committee as the first one with our CTO as chair and his direct reports, internal audit, and finance represented. This provided transparency and improved communication from top down.

In the formal sense of IT Governance representatives from the business such as the CFO, COO, and business unit leadership would be included in the IT Steering Committee to make sure that IT and the business are in strategic alignment. Depending on the maturity level of your company this may or may not be the case.

Another committee that we started was the IT Software Selection committee. The reason was simple, to get some form of control over software purchases. With many independent businesses geographically dispersed, but a centralized IT shared services support model, it was important to make sure the software was a fit, that there was not something we owned that could already be used, that it was an architectural fit, and that Cybersecurity was front and center.

So, as you can see IT Governance is truly a broad far-reaching discipline, and at the heart of it is the continuous effort to mature every aspect of Information Technology. Most companies do this organically over time, that they have not specifically identified IT Governance as a role or department and staffed it as such. Governance can also bring a negative connotation, many relate it to more bureaucracy, when really, and it is just the opposite by streamlining processes or decision making. Most importantly it needs top leadership support because it will be exceedingly difficult to implement far reaching organizational change management without it.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.