
The adoption of Information and Communication Technologies (ICTs) by small and medium-sized enterprises (SMEs) leads to cost reduction in processes and organizational effectiveness. The effective use of ICTs, however, greatly depends on their good governance, especially due to the impact generated by investments in information and communication technologies. In this scenario, we aimed at defining the state of art of IT governance in SMEs. A broad review of the literature on IT governance in SMEs was performed. The results indicated a field of research with little development, with 32 studies identified until the year 2018. Three research lines were observed. Initially, the researchers have discussed the barriers and characteristics of ITG in SMEs. In the next step, the studies were directed to the establishment of an ITG framework applicable to SMEs reality. The last line of research observed the IT capacities in relation to the environment in which the SME operates. The studies indicated a prevalence of qualitative approaches under the positivist paradigm.
With the standardization of Information Technology (IT) governance through ISO/IEC 38500 in the last decade, a good number of organizations have implemented IT governance (ITG) frameworks. Although it is not a fully extended practice. Given the fact that the use of balanced score cards (BSC) on ITG is not an unknown practice, the application of BSC in the implementation of ISO/IEC 38500 has been given less importance, since it normally appears as just examples of good practices. This work not only explains why the BSC's applicability to align IT with business in ISO/IEC 38500 implementations is not included in the standard, but also justifies the importance of BSC to report to the board or senior executive team in a clear way, without the details of the particular implementation framework of the standard. Thus, a framework that allows implementing IT BSCs within the context of IT governance is proposed, cascading objectives included in the strategic map through the tactical and operational level and backwards on the construction of the KPIs to better monitor IT.
Digitalisation in the public sector has attracted the attention of political and administrative leaders as well as researchers. Empirical studies suggest that most of the digitalisation efforts fail to achieve the intended efficiency, transparency, and responsiveness of the public sector. While digitalisation is a hot research agenda, only a few studies explored the issue in public organisations. This study, therefore, attempts to address the gap in the literature and identify the factors influencing digitalisation in the public sector. A case study is conducted at one of the largest state-owned enterprises in Liberia, the National Social Security and Welfare Corporation (NASSCORP). The data collected through interviews and examination of internal documents were analysed thematically. The study resulted in the identification of 13 factors influencing digitalisation in the public sector, which are related to technology, organisation as well as the environment. The contribution of the study to research and practice is presented along with the potential future research opportunities.
With the growing importance of IT as competitive advantage, companies aim to increase their digital transformation activities. Consequently, companies are also revisiting their existing IT sourcing arrangements. In the article at hand, the authors explore the concept of IT backsourcing by presenting the results from a quantitative online survey with global IT practitioners. The authors confirm that backsourcing is frequently applied in practice, with key reasons being dissatisfaction with service or relationship quality and higher than expected costs. Further, the authors identify IT services with an increased likelihood of being backsourced, e.g., application development or data center, and discuss the effect of a CIO change on the backsourcing decision. In addition, the authors show that there are differences in the perceptions on the antecedents and the results of backsourcing decisions between management and operational level. The authors conclude with practical implications for IT managers based on their findings.
The concept of information technology governance (ITG) was developed with foundations in organizational studies on corporate governance, but with a central element (information technology/information systems) in the field of information systems (IS). The ITG concept has become broad and ambiguous with inaccurate assessments leading researchers to adopt a nominal view of the theme. The ITG has a weak theoretical and ontological basis and its concept in the literature is not clear. Thus, the authors established as a research aim to analyze and discuss the composition of the ITG concept in an interdisciplinary perspective. The literature of governance, corporate governance, and IS were used as the basis for the analysis of the formation of the ITG concept. ITG studies were consulted and 79 textual corpora were analyzed in light of the techniques of content and lexical analysis. The analyses allowed rethinking the concept of ITG by considering that the theme must include both governance mechanisms and have a central element that represents the Information Technologies or Information Systems.
Although the concept of business-IT alignment was once considered one of the most important concerns of organizations, in terms of IT administration, the attention it has received has decreased significantly over the years. This article postulates that strategic alignment initiatives still have the same relevance—in particular for non-IT companies—which means that digital transformation strategies should consider the strategic alignment as a critical issue for their success. Therefore, the persistent relevance of this concept and the need to measure it with updated instruments capable of assessing the degree of maturity reached and feeding back the results to the organizations remains a key topic in IT administration. Based on an updated instrument, adequate for a digital framework, our study surveyed a sample of mostly large Chilean companies. The results obtained reveal the importance to count with an improved model that captures the changes this new digital scenario imposes.
IT governance research suggests the existence of a gap between theoretical frameworks and practice. Although current ITG research is largely focused on hard governance (structure, processes), soft governance (behavior, collaboration) is equally important and might be crucial to close the gap. The goal of this study is to determine what IT governance maturity models are available and if there remains a mismatch. The authors conducted a systematic literature review to create an overview of available IT governance maturity models. The study shows five new IT governance maturity models were introduced. Only one of the new IT governance maturity models covers hard and soft IT governance in detail. This model and corresponding instrument was used to illustrate its usability in practice. The authors demonstrate that combining the instrument with structured interviews results in a usable instrument to determine an organization's current maturity level of hard and soft IT governance.
The importance of data privacy, information availability and integrity are increasingly recognized. The new EU general data protection regulation 679/2016 obligates stringent legal requirements with high sanctions for noncompliance. Most organizations worldwide are affected directly or indirectly. It requires overall a risk and evidence-based data privacy management as part of corporate governance. More than 1.6 million organizations worldwide are implementing a standard-based management system, such as ISO 9001 or others. To implement the new data protection regulation in an effective, efficient and sustainable way, the author provides design-oriented guidelines on how to integrate the legal requirements into standard based management systems. The holistic data privacy governance model integrates different information security governance frameworks with standard based management systems in order to comply the regulation. In that way data privacy is part of all strategic, tactical and operational business processes, promotes corporate governance, legal compliance and living data protection.
The current operational environment for organizations is changing, which has effects on IT functions and IT activities. Various forms of networks, collaborations, and alliances are operational models, which organizations are using to an increasing extent. This reality has brought with it a need for improved IT governance (ITG). ITG research for inter-organizational arrangements will be needed. In the research, the target is to identify the current state of the inter-organizational ITG research among the information systems (IS) domain. The literature review covers academic articles and conference proceedings during this millennium. The findings of the current literature review reveal that interest towards ITG research is still quite limited. The future view of inter-organizational ITG research is quite clear: more research will be needed in the inter-organizational area, which is the current playground for several organizations today.
With the standardization of Information Technology (IT) governance through ISO/IEC 38500 in the last decade, a good number of organizations have implemented IT governance (ITG) frameworks. Although it is not a fully extended practice. Given the fact that the use of balanced score cards (BSC) on ITG is not an unknown practice, the application of BSC in the implementation of ISO/IEC 38500 has been given less importance, since it normally appears as just examples of good practices. This work not only explains why the BSC's applicability to align IT with business in ISO/IEC 38500 implementations is not included in the standard, but also justifies the importance of BSC to report to the board or senior executive team in a clear way, without the details of the particular implementation framework of the standard. Thus, a framework that allows implementing IT BSCs within the context of IT governance is proposed, cascading objectives included in the strategic map through the tactical and operational level and backwards on the construction of the KPIs to better monitor IT.
Research on Shadow IT is facing a conceptual dilemma in cases where previously “covert” systems developed by business entities are integrated in the organizational IT management. These systems become visible, are thus not “in the shadows” anymore, and subsequently do not fit to existing definitions of Shadow IT. Practice shows that some information systems share characteristics of Shadow IT but are created openly in alignment with the IT organization. This paper proposes the term “Business-managed IT” to describe “overt” information systems developed or managed by business entities and distinguishes it from Shadow IT by illustrating case vignettes. Accordingly, our contribution is to suggest a concept and its delineation against other concepts. In this way, IS researchers interested in IT originated from or maintained by business entities can construct theories with a wider scope of application that are at the same time more specific to practical problems. In addition, the terminology allows to value potentially innovative developments by business entities more adequately.
In this article, a theory-driven approach for managing the alignment process between business and IT by making high-quality IT investment decisions is developed. The aim is to increase the understanding of the dimensions of the alignment problem and to offer some support in solving it. The conceptualization of the alignment issue is searched from the structural alignment theory, arising from and applied in psychology. After the theoretical considerations, the article adopts a multidimensional and constructive approach to the alignment problem and looks for answers to the question: How should organizations align business and IT, or at least, how to support the business and IT alignment decisions? As a result, a theoretically sound framework originating from the alignment problem is proposed for the evaluation of IT investments, a methodology based on that framework, and a concrete investment support system to help decision makers. The applicability of the approach is evaluated in the context of an actual case in the finance sector.
In today's complex organizations, IT governance is an important managerial challenge. IT governance deals with decisions and responsibilities concerning IT. There are many factors influencing IT governance. One factor that has remained relatively unexplored by academic research is that of organizational culture. This research explores the influence of the organizational culture of collaborative networks on IT governance performance. A case study was conducted in a large complex company with several networks. The findings indicated that the networks fit better with different organizational culture types based on their priorities for IT governance outcomes to maximize performance. A clan organizational culture is desired when aiming for effective use of IT for asset utilization and cost-effective use of IT. An adhocracy culture fits better when prioritizing the effective use of IT for business growth. Finally, a combination of market and hierarchy organizational culture is desired and fits better when seeking effective use of IT for business flexibility and cost cutting.
Dynamic capabilities theory emerged as a leading framework in the process of value creation for firms. Its core notion complements the premise of the resource-based view of the firm and is considered an important theoretical and management framework in modern information systems research. However, despite DCTs significant contributions, its strength and core focus are essentially in its use for historical firm performance explanation. Furthermore, valuable contributions have been made by several researchers in order to extend the DCT to fit the constantly changing IT environments and other imperative drivers for competitive performance. However, no DCT extension has been developed which allows firms to integrally assess their current state of maturity in order to derive imperative steps for further performance enhancements. In light of empirical advancement, this paper aims to develop a strategic alignment model for IT flexibility and dynamic capabilities and empirically validates proposed hypotheses using correlation and regression analyses on a large data sample of 322 international firms. We conjecture that the combined synergetic effect of the underlying dimensions of a firms IT flexibility architecture and dynamic capabilities enables organizations to cope with changing environmental conditions and drive competitive firm performance. Findings of this study suggest that there is a significant positive relationship between the firms degree of strategic alignment defined as the degree of balance between all dimensions and competitive firm performance. Strategic alignment can, therefore, be seen as an important condition that significantly influences a firms competitive advantage in constantly changing environments. The proposed framework helps firms assess and improve their maturity and alignment of IT flexibility and dynamic capabilities.
This article examines the association between stakeholder functional role and the perceived level of IT governance and IT management implementation. Specifically, this article takes a COBIT 5 perspective, by first analyzing perception differences at the level of the implementation of the seven COBIT 5 enablers, followed by an analysis at the level of the COBIT 5 process domains. The results indicate that a shared understanding about the IT governance and IT management implementation level between different organizational stakeholders can be improved, especially between (1) IT and (2) audit, risk, and compliance (ARC) stakeholders. As IT governance is seen as a critical enabler for the achievement of IT business value, an appropriate level of shared understanding about its implementation level among important stakeholder groups should be achieved.
Despite the long list of cumulative research, business-IT alignment remains to be evasive for practitioners and researchers. As organizations continue to spend a significant amount of their resources on IT to improve the variety and quality of services, achieving and maintaining business-IT alignment is a timely issue. Studies indicate that organizational structure, among other factors, plays an important role on whether organizations succeed in achieving business-IT alignment. A systematic literature review is conducted to provide an overview of previous studies as well as point out possible future research directions. A total of 31 articles were identified and included in the review. The findings indicate that there are few studies poised to address the lack of knowledge on how the formal/informal organizational structure's influence on business-IT alignment. The study presents a summary of previous findings on organizational structure's influence on business-IT alignment and identifies potential future research directions.
Despite being one of the widely researched topics, information technology governance IT governance in the context of public organizations is less explored. A systematic literature review is conducted to provide an overview of the current status of the research area and propose future research directions. Databases indexing the reputable journals and top conference proceedings in the information systems area were searched to collect articles for analysis. A total of 109 relevant articles were identified and included in the analysis of the literature review. The findings of the literature are presented according to the research questions, and potential research directions are proposed.
A company has to operate with flexibility and cost-efficiency due to the continuously competitive business environment. Nowadays, cloud computing (CC) plays an essential part in flexibility and cost-efficiency of IT infrastructure. Companies using CC have to know how different types of contracts and their terms, modes of relationships, contract quality, and relationship management influence their CC activities. This article discusses how to build successful relationships in CC. The field of this study is CC from a service buyer perspective. The applied research strategy was survey research and the data was collected through interviews with IT managers in different medium-sized companies in Sweden. To identify and analyse the influencing factors of relationships in CC this research has used Transaction Cost Theory. The findings of this research are the identified influential factors to improve a cloud computing relationship like asset specificity, fee-for-service contracts, contract length, provider/buyer organisation sizes and the number of providers including guidelines for decision makers to strengthen this CC relationship.
ICT is significant for municipal' services. Yet, they are usually operated with limited resources, which motivates cooperation. We investigated, how ICT cooperation was governed in 20 Finnish regions. As the theoretical basis, we reviewed TCE, RBV, IT governance practice and Granovetter's social network theories. The theory basis was used to identify theory-proposed cooperation benefits and to link these benefits to IT governance practices. We then compared theory-proposed benefits and practices to those detected in the 20 regions. Our findings revealed differences in ICT cooperation, in the gaining of benefits, and in the use of IT governance practices. The lack of social ties helped to understand differences. Our findings indicate that the emperor will not enjoy new clothes – ICT cooperation benefits – unless ICT cooperation is systematically organized for governance. We contribute to research by augmenting the theory base of IT governance research, by extending IT governance research to inter-organizational contexts and by showing how this theory base can be used empirically.
We investigate the equilibria of CIO work. We apply the punctuated equilibrium paradigm based socio-technical model as our theoretical basis. We use this model to visually describe the impacts of business interruptions =punctuations on IT executives' perceived equilibria of work. We enhance the punctuated model with constructs taken from Granovetter's social network theory to better understand social mechanisms influencing IT executives' perceptions. We examined empirically perceptions about the equilibria of work and the role of IT in business in a media company during the years 2010-16. We collected data with the interview data collection method by conducting several interview rounds. Interview findings revealed that the equilibria of work were seen differently at three organizational levels. Also, the role of IT in business and the responsibilities of IT functions were seen in varied ways. The punctuated socio-technical equilibrium model together with the constructs of Granovetter's social network theory offered insightful theoretical explanations for our findings.