Page 99 - CITP Review
P. 99
Benefits of effective IT governance
Two of the main purposes of IT governance are to effectively manage the IT function — plan, organize,
and control IT activities — and effectively mitigate IT risks. These purposes provide assurance about the
quality of IT overall, and specifically to provide assurance over aspects such as change management.
When an entity has mature IT governance, there will be signs to indicate it. In mature IT governance, IT
priorities are driven by the business strategies; in basic IT governance, IT priorities are driven by the IT
community or IT department. This continuum from basic to mature IT governance exists on a number of
factors such as how IT adds value, BoD involvement, and portfolio management.
IT governance is important to reducing IT risks because it has impact and scope across the entity. To
illustrate, project management can be seen as a subset of IT governance, and project management
principles are critical success factors in major IT projects, that is, change management. But IT
governance considers the enterprise and the entire IT portfolio in its processes, structure, and
monitoring.
© 2019 Association of International Certified Professional Accountants. All rights reserved. 3-15