IT governance and management

Technology governance and management

We work with your team to establish a strategic and operational framework for planning, implementing and overseeing IT practices. Through a structured approach, we make sure technology stays aligned with business objectives.

Typical duration
4 to 8 months
Reference frameworks
COBIT · ISO/IEC 38500 · ITIL
Deliverables
Governance model and indicators
Integrates with
ISO/IEC 20000-1 and 27001

Objective and scope

IT governance defines who decides, on what and with what information; IT management defines how it gets done. We work on both planes: decision structure, service and investment portfolio, technology risk management, indicators and accountability to the Board, drawing on practices from COBIT and ISO/IEC 38500 and scaled to the organisation as it actually is.


Project phases

Phase 1

Assessment of the current state

We review IT structure, processes, service portfolio, contracts and capabilities, and measure the gap against the chosen reference framework.

Phase 2

Governance model design

We define decision-making bodies, roles and responsibilities, investment prioritisation criteria and the technology planning cycle.

Phase 3

Management practices

We formalise change, capacity, service level, supplier, asset and technology risk management, supported by SORT Redmine.

Phase 4

Indicators and oversight

We set up the indicator dashboard and the reporting cycle to the Board so that governance holds up over time.


What the implementation includes

  • IT capability assessment
  • Structure and decision-making bodies
  • Roles and responsibilities (RACI)
  • IT service portfolio
  • Investment prioritisation criteria
  • Technology risk management
  • Supplier and contract management
  • Indicator dashboard for the Board

Frequently asked questions

Is it useful for a small organisation?

Yes, if it is scaled properly. In small organisations the goal is not to create committees but to make clear who decides on technology investments and risks, and with what information. The model is adjusted to the real scale.

Can it be combined with ISO/IEC 20000-1?

Yes, and that is the usual case. Governance sets the direction and the accountability; ISO/IEC 20000-1 formalises service management. We treat them as one programme when the objective includes certification.

your business partner

Protecting you today, innovating for tomorrow