18.01.2013 Views

Enabling Processes

Enabling Processes

Enabling Processes

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Align, Plan and Organise<br />

APO07 RACI Chart<br />

Key Management PracticeBoard APO07.01<br />

Maintain adequate and<br />

appropriate staffing.<br />

APO07.02<br />

Identify key IT personnel.<br />

APO07.03<br />

Maintain the skills and<br />

competencies of personnel.<br />

APO07.04<br />

�������� �������� ���<br />

performance.<br />

APO07.05<br />

Plan and track the usage of IT<br />

and business human resources.<br />

APO07.06<br />

Manage contract staff.<br />

84<br />

: ENABLING PROCESSES<br />

Chief Executive Officer<br />

Chief Financial Officer<br />

Chief Operating Officer<br />

Business Executives<br />

APO07 Process Practices, Inputs/Outputs and Activities<br />

Business Process Owners<br />

Strategy Executive Committee<br />

�������� ��������������������� ���������<br />

������� ���������� ������<br />

����� ���������� ������<br />

Chief Risk Officer<br />

Chief Information Security Officer<br />

Architecture Board<br />

Enterprise Risk Committee<br />

Head Human Resources<br />

Compliance<br />

Audit<br />

Chief Information Officer<br />

R I R A R R R R R R R<br />

R R A R R R R R R R<br />

R R A R R R R R R R<br />

R R A R R R R R R R<br />

R C A R R I R R R R R R R R<br />

R R A R R R R R R R<br />

Management Practice Inputs Outputs<br />

APO07.01 Maintain adequate and<br />

appropriate staffing.<br />

Evaluate staffing requirements on a regular basis or<br />

���� ����� ������� �� ��� ���������� �� �����������<br />

or IT environments to ensure that the enterprise has<br />

sufficient human resources to support enterprise goals<br />

��� ����������� �������� �������� ���� �������� ���<br />

external resources.<br />

From Description Description To<br />

EDM04.01 � �������� ��������� ����<br />

� ������� ���������� ���<br />

allocation of resources<br />

and capabilities<br />

EDM04.03 Remedial actions to<br />

address resource<br />

management deviations<br />

Head Architect<br />

Head Development<br />

Staffing requirement<br />

evaluations<br />

Head IT Operations<br />

Competency and career<br />

development plans<br />

APO01.02 Definition of supervisory<br />

practices<br />

Personnel sourcing plans Internal<br />

APO06.03 � ������ ��������������<br />

� �� ������ ��� ����<br />

Outside COBIT � ���������� ����� ���<br />

����������<br />

� ���������� �� ��������<br />

and procedures<br />

Activities<br />

�� �������� �������� ������������ �� � ������� ����� �� ���� ����� ������� �� ������ ���� ����<br />

� �� �������� ��� ���������� ��������� �� ���������� ��� ������������� ������� ���������� ����� ��� ����������<br />

� ���������� ��� ���������� ��������� �� ���������� ��� ������������� ������� �������� ��������� ��� �������� ��� ���������� �����������<br />

�� �������� �������� ��� �� ��������� ����������� ��� ��������� ��������� �� ���� ���� ��� ������� ������������ ��������� �������� ��� �����������<br />

3. Include background checks in the IT recruitment process for employees, contractors and vendors. The extent and frequency of these checks should<br />

������ �� ��� ����������� ������ ����������� �� ��� ���������<br />

4. Establish flexible resource arrangements to support changing business needs, such as the use of transfers, external contractors and third-party<br />

service arrangements.<br />

5. Ensure that cross-training takes place and there is backup to key staff to reduce single-person dependency.<br />

Personal Copy of: Mr. Dong Hong Wang<br />

Head IT Administration<br />

Service Manager<br />

Information Security Manager<br />

Internal<br />

Internal<br />

Business Continuity Manager<br />

Privacy Officer

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!