Communication plays a very important role in the success or failure of modern-day enterprises.Employees constantly exchange information as part of organizational planning, developing, control, reporting, etc. Communication is as important in the process of business-IT alignment.If the efficiency of communication between the business and IT sections is bad, the business-IT alignment will surely suffer.For this reason an enterprise should attempt at all times to optimise communication between the business and IT sectors.What is important though is to determine the suite of possible factors that might influence such business-IT alignment and to use these factors in attempts to improve the efficiency of such communication.The objective of this paper is to determine such a suite of factors influencing business-IT alignment.
Communication is a crucial part and, often, a thorny problem of organizational life. In the modern-day organization, individuals must exchange information continuously and rapidly throughout the chain of command, whether to offer evaluation, direction or control. No more is this true, then for the rapidly growing and evolving domain of IT governance. Unfortunately, communication failures between business and IT management continue to be an all too familiar sight. Whilst knowledge of this communication challenge has emerged, less attention has been devoted to identifying and understanding the underlining barriers, possible problems and causes of business/IT communication failure. This paper contributes to the above-mentioned concern by arguing that the domain of cybernetics may hold promise for understanding the underlining problems of the challenge. In particular, the concepts of transduction and pacing, could offer practical insight towards the creation of strategies or approaches for its resolution.
As the dependence on information and its supporting IT infrastructure has grown in the modern-day organisation, so too has the need materialised for closer business and IT alignment. Hence, this remains one of the primary aims and challenges of IT governance. Unfortunately, although such alignment may be seemingly trivial, it has remained a troublesome prospect for organisations worldwide throughout the last decade. Whilst knowledge of this alignment challenge has emerged, less attention has been devoted to understanding the collective role of the board and the chief information officer (CIO). Furthermore, the nature of the interplay between these roles within an organisation in successfully contributing to the resolution of this alignment issue remains unclear. This paper contributes to the above-mentioned concern by arguing towards a conceptual IT alignment continuum that elucidates the role of the board and the CIO and their interplay in relation to the IT alignment challenge, as they represent the core of IT and the business.
This paper conceptually explores the existing IT governance literature and reveals that the concept remains an evolving and `murky' phenomenon. Specifically, it highlights that as IT governance continues to evolve, it emerges in ever-new forms with increasing complexity and confusion. This is especially true, when studying the various differing definitions and terms applied within current literature and the nature and breadth of discussion. Even more so, when taking into account the whirlpool of standards and best practices currently operating within this domain. All of this leads to a lack of clarity, having the potential to confuse and possibly impede useful development and research in the field. Using content analysis, argumentation and modelling, this paper sets out to review and model a possible reform to the IT governance landscape. Hereby, it aims to offer much-needed clarity, provide a frame of reference and guide future research in the field.
It has been found that many small, medium and micro enterprises (SMMEs) do not comply with sound information security governance principles, specifically those principles involved in drafting information security policies and monitoring compliance, mainly as a result of restricted resources and expertise. Research suggests that this problem occurs worldwide and that the impact it has on SMMEs is great. In previous research an information security governance model was established to assist SMMEs in addressing information security governance issues and concerns. In order to provide SMMEs with a practical approach for applying this model, further research was conducted to establish a software program that demonstrates the model's practical feasibility. The aim of this paper is to introduce this software program, called The Information Security Governance Toolbox (ISGT), by means of its various components, workings and benefits. Furthermore, a focus-group study's evaluation results are offered that suggest that the program is useful to SMMEs in addressing their information security governance implementation challenges and offer value for industry.
The challenge of the corporate environment has been and remains one of competitive advantage. To address this challenge information technology (IT) is playing an ever-increasing role. Nowadays it is not uncommon to find IT entrenched in all business processes in the corporate environment, as it has become pervasive in nature. With this high dependence on IT, literature is paying a renewed attention to those responsible for the well-being of the organisation, namely the board, and its role in providing proper governance over IT. Earlier research indicated that complete control over IT was lacking since there was a general shortcoming of IT expertise or ability at board-level within the corporate environment. The question then that can rightfully be asked is whether any progress has taken place over the past few years in this regard. Hence, do boards today still lack IT expertise or ability in addressing their IT governance obligations in the corporate environment. Accordingly, this paper reports on a replicative study conducted in this area to answer this question. The results of this study suggest that certain progress has been witnessed, indicating that some improvement has taken place; nevertheless, much work still remains to be done in this area. Key words: board of directors, board-level IT ability, board-level IT involvement, chief information officers, IT governance, IT oversight committees.
The proliferation of e-business, e-services and e-governance in developing countries has resulted in businesses and governments becoming highly dependent on business information and related information technologies. Such information is, however, constantly exposed to real threats that could result in security breaches. If these are realised, the prevailing economic structure of a developing country, which is often frail and dependent on the success of its businesses, may be significantly affected as a result of monetary losses. It is thus vital for businesses in these countries to implement, manage and govern information security adequately so as to ensure that valuable information resources are effectively protected. Regrettably, many businesses in developing countries lack the expertise to perform these activities owing to a lack of resources or expertise. Accordingly, the aim of this paper is to establish a model for information security governance that can be implemented with little expertise, as well as minimal effort and capital outlay.
Many small-to-medium sized enterprises are finding it extremely difficult to implement proper information security governance due to cost implications. Due to this lack of resources, small enterprises are experiencing challenges in drafting information security policies as well as monitoring their implementation and compliance levels. This problem can be alleviated by means of a cost effective ”dashboard system” and automated policy generation tool. This paper will critically evaluate an existing policy generation tool, known as the Information Security Management Toolbox, and will propose improvements to this existing system based on changes in both information security standards and business needs, since the development of the original system.