<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itskeptic.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The IT Skeptic - Comments for &quot;The third castor: IT Assurance&quot;</title>
 <link>http://www.itskeptic.org/third-castor-it-assurance</link>
 <description>Comments for &quot;The third castor: IT Assurance&quot;</description>
 <language>en</language>
<item>
 <title>IT is losing Change</title>
 <link>http://www.itskeptic.org/third-castor-it-assurance#comment-8295</link>
 <description>&lt;p&gt;We in IT Management, from the CIO down, are losing control of the centre, of Production (will be a blog post on this if I ever get it finished, and I&#039;ve spoken of it at conferences).  In particular we are losing control of Change.  To Agile developers in the business; to business units signing up for SaaS and Cloud; to end users who will run whatever platform they bloody well like and buy a new one when they like, and customize it constantly with apps downloaded from outside.  This is the future.  IT Change is controlled by the business and the users.  We can only defend and attempt to influence.&lt;/p&gt;
&lt;p&gt;As for the IT Assurance function, they aren&#039;t auditors (though one of their instruments is audit).  They try to prevent a situation arising that would get an auditor&#039;s attention after the fact.  It is a formalisation of what all those areas I listed already do: think quality control, architecture enforcement, safety education...  It is a delegation of the CIO&#039;s responsibility to look out for the safety of the organisation.  As such it sits under the CIO and reports directly.&lt;/p&gt;
</description>
 <pubDate>Wed, 06 Jul 2011 18:44:54 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 8295 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Who pays for the auditors?</title>
 <link>http://www.itskeptic.org/third-castor-it-assurance#comment-8294</link>
 <description>&lt;blockquote&gt;&lt;p&gt;I believe there needs to be an active IT Assurance function. One CEO said to me &quot;we have auditors for that&quot;. I replied that IT Assurance exists to ensure that there is nothing for the external auditors to find. (Actually I think it is worth leaving something for auditors to criticise, to make them happy).&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;I agree with you if and only if the auditors are reporting externally, to customers, to governing bodies or in some cases to the owning organization.&lt;/p&gt;
&lt;p&gt;If you call in and pay the auditors yourself - they are your Assurance function. So you can use the auditors as that.&lt;/p&gt;
&lt;p&gt;But I must challenge the Swami - I miss the 4th leg called change. &lt;/p&gt;
&lt;p&gt;Service -&amp;gt; Will make sure I know what I need to provide to my customers/business side or whatever I strive to support. Demands change, so this results in new requirements.&lt;br /&gt;
Governance -&amp;gt; Takes in requirements from outside as well as own management to define what we want to do. Rules, regulations and strategy change, so again this results in new requirements.&lt;br /&gt;
Assurance -&amp;gt; Makes sure (I guess thats where the name comes from) that rules, regulations and strategy is met. It will audit (that is where your CEO was right) and produce findings. Findings require implementation of changes -&amp;gt; again new requirements.&lt;/p&gt;
&lt;p&gt;So the basic production unit of future IT mangement is not Service, not Governance nor Assurance. It is Flexability allowing Change to happen as all these 3 result in change.&lt;/p&gt;
&lt;p&gt;There is no better place to be to find inspiration for new blog posts than your blog Rob. Thanks for that! It gets me thinking.&lt;/p&gt;
</description>
 <pubDate>Wed, 06 Jul 2011 17:45:41 +0000</pubDate>
 <dc:creator>mbuzina</dc:creator>
 <guid isPermaLink="false">comment 8294 at http://www.itskeptic.org</guid>
</item>
</channel>
</rss>
