1
Chapter 6 – IT Governance
Instructor Manual
An Introduction To IT Governance And Its Role In Strategic Management.
Decisions a company makes about the IT systems that it uses affect the efficiency
and effectiveness of the organization in achieving strategic goals. IT systems must
support management’s strategic goals and daily operational management. Strategic
management is the managerial process of determining the strategic vision for the
organization, developing long-term objectives, creating strategies to achieve the
An Overview Of The System Development Life Cycle (SDLC). The System
Development Life Cycle (SDLC) is a systematic process to manage the acquisition,
design, implementation and use of IT systems. The oversight and management of
the SDLC is normally the responsibility of the IT governance committee. There are
five phases to the SDLC: (1) systems planning, (2) systems analysis, (3) systems
Phases Of The SDLC. Following are the typical steps in the phases of the SDLC.
There may be some variation from company to company.
o Systems Planning. Systems planning is the evaluation of long-term, strategic
objectives and the prioritization of the IT systems that assist the organization in
achieving its objectives. Systems planning also involves the continuing oversight
of the design, implementation, and use of those IT systems. Through continual
monitoring of the IT system, the IT governance committee determines whether
2
The IT governance committee must follow procedures that will assist it in
prioritizing those parts of the IT system that need immediate modification or
upgrade. To prioritize these projects, the IT governance committee should
consider two broad aspects: (1) the assessment of IT systems and their match to
strategic organizational objectives, and (2) the feasibility of each of the requested
modifications or upgrades. This matching of IT systems to organizational
objectives also highlights the need for the IT governance committee to include
top management such as the CEO, CFO, CIO, and other top managers. These
which proposed IT changes should have the highest priority.
Technical feasibility. Does the technology exist to meet the identified need?
Operational feasibility. Will current employees and company be able to
operate the proposed system?
Economic feasibility. Will the benefits of the proposed system exceed its
costs?
Schedule feasibility. Can the proposed system be implemented in a
reasonable time?
o Systems Analysis. The systems analysis phase often includes a preliminary
investigation, a survey of the current system, a determination of user information
needs, analysis, and business process reengineering. At the end of this phase,
the project team will prepare and deliver a systems analysis report. The purpose
of the preliminary investigation is to determine whether the problem or deficiency
in the current system really exists. The project team may reexamine some of the
3
The analysis phase is the critical thinking stage of systems analysis. The
purpose is to question the current approaches used in the system and to
consider better ways to carry out the steps and processes in the system. The
project team studies the information collected in the system survey phase and
attempts to create improvements to the system. In many cases, the analysis
phase and the attempt to create improvements may lead to Business Process
Reengineering (BPR). The last step in the systems analysis phase is to prepare
a systems analysis report for delivery to the IT governance committee. This
report will inform the IT governance committee of the results of the systems
survey, user needs determination, and BPR, and will make recommendations to
the IT governance committee regarding the continuation of the project.
o Systems Design. The nature of the steps within the design phase of the SDLC
is different depending on whether the organization intends to purchase software,
or design the software in-house.
When software will be purchased, the project team is ready to solicit proposals
For in-house design, the next step would be to generate alternative conceptual
designs. The conceptual design phase involves identifying the alternative
conceptual design approaches to systems that will meet the needs identified in
the system analysis phase. This step could be viewed as a sort of
4
approach that best fits the organization’s needs. The evaluation process
includes a more detailed feasibility study to select the best alternative design.
Once the design has been selected, the details of that alternative must be
designed. The purpose of the detailed design phase is to create the entire set
of specifications necessary to build and implement the system. The various parts
of the system that must be designed are the outputs, inputs, processes, data
storage, and internal controls. When the project team has completed all of the
detailed designs, the implementation phase can begin.
o Systems Implementation. There are many different tasks within the
implementation and operation phase of the SDLC, and only a few of the most
critical steps are described here. Using the design specifications developed in
programming of the new system, the modules that make up the programs must
be tested. Software should never be implemented before it is tested. Since
inputs, outputs, and processes are very likely to change as systems are revised,
it is important to write the documentation that matches the new inputs, outputs,
and processes. There are many kinds of documentation necessary to operate
and maintain an accounting system, including flowcharts, data flow diagrams,
entity relationship diagrams, process maps, operator manuals, and data
o Operation And Maintenance. After implementation, the company will operate
and maintain the system. This part of the SDLC is the longest and costliest part
since it may last for several years. At some point, the company will find a need
to make major revisions or updates to the system. This would trigger the SDLC
to begin again to revise the system. During the ongoing operation of the IT
system, management should receive regular performance reports as necessary
5
The Critical Importance Of IT Governance In An Organization.
o SDLC As Part Of Strategic Management. An SDLC process, such as
described in this chapter, serves as the mechanism to continually assess the fit
of IT systems to long-term strategy and short-run goals of the organization.
Once the IT governance committee identifies which types of IT systems are
appropriate for the organization, the SDLC becomes the mechanism to properly
manage the development, acquisition, and implementation of IT systems
o SDLC As An Internal Control. The AICPA Trust Services Principles include
many details about an IT governance committee and the SDLC, as well as the
role of these two strategic management processes in the internal control
Ethical Considerations Related To IT Governance.
o Ethical Considerations For Management. The management of any
organization has an ethical obligation to maintain processes and procedures that
assure accurate and complete records and protection of assets. This
responsibility arises because management has a stewardship obligation to
those who provide funds or invest in the company, which requires that
management maintain systems allowing it to demonstrate the appropriate use of
o Ethical Considerations For Employees. As managers apply the processes
within the SDLC to revise IT systems, employees should not subvert the process.
If management has made an honest effort to include user feedback and
participation in the SDLC processes, employees should likewise make an honest
effort to participate, learn new system processes, and use new processes and
6
o Ethical Considerations for Consultants. When consultants are employed to
assist the organization with phases of the SDLC, there are at least four ethical