IT Management Processes

The Support Processes of IT Management

The fundamental processes, described above, are supported by a set of administrative and management activities, which contribute to the effectiveness and efficiency of such processes. These activities are organized in the so-called support processes, located in the lower part of the value chain of the IT management model (see figure 3).

Several of the support processes are specialized to provide better sustain for fundamental or support processes. Such is the case of the Configuration Management, Risk Management and IT Security Management processes. The latter, for example, specializes in management the security of the IT infrastructure, the Data, and the Computing Services.


Strategic Management

It is a management process for aligning the goals of the IT department to the strategic goals of the whole organization. The process consists of a set of activities that lead to maximize or at least to maintain at a high level, the degree of alignment between the implementation of the IT goals and the business goals.

To do that, the strategic management establishes the medium and long-term mission and vision, so it can establish the strategic goals of the business and the IT strategies that allow reaching them. It consists of a set of planning and strategic control activities. It also includes the management of IT policies that will be used to carry out the IT governance. This process is comprised of four sub-processes:

  • Strategic Direction. It consists on establishing the internal and external variables that influence both, positively and negatively, in the successful attainment of the goals of the IT Management. These variables assist to determine the main orientation that the organization must follow for defining IT strategic goals; which have to be consistent and cohesive with the strategic goals of the whole organization.

  • Establishment of IT Strategies. The process consists on the definition, analysis and selection of IT strategies that lead to implement the strategic goals of the IT Management. IT strategies must be in accord with business strategies. This process includes the processing and inclusion of strategies within the framework of the current and future EA. Among the main activities of this process are: strategic options and functional projects formulation, evaluation of these strategic options and functional projects, and definition of strategies for the IT management.

  • IT Policy Management. Policies are documented statements that establish the set of rules associated with the different aspects of the EA. Policy Management is a strategic process that requires the implementation of activities related to the definition and development of IT policies, implementation and maintenance of these policies, as well as the establishment of guidelines to eliminate these policies when they no longer support the business strategy.

  • Monitoring of IT Strategies. This process measures the degree of effectiveness of the implemented strategies in order to achieve IT goals and strategic projects. This process determines the technical and managerial mechanisms and instruments, considered necessary to measure efficiency and effectiveness of the implemented strategies and to establish mechanisms to improve these strategies, if required. In addition the process comprises the evaluation of the organizational and current EA performance searching to attain a better fit and support of strategic business goals.


Administrative Management

It is responsible for the planning, organization, direction, and control of human, financial, physical, and budgetary resources that are managed by the IT Department.

This process breaks down in the next set of processes:

  • Human Resources Management. It is in charge of matters pertaining to staff, the performance evaluation of the staff, and the staff training and development.

  • Management of Financial Resources. It is responsible for the management of all of the financial resources, including, among others, the management of contracts, purchases, and costs; as well as, the acquisition of goods, materials, and office supplies, the provision of services, and the processing costs and flow cash.

  • Management of Physical Resources. It consists of the control of goods and materials; as well as, the administration and control of documentation that handles the IT Department.

  • Budgetary Management. It is responsible for the formulation, monitoring, and control of the budget allocated to IT Management.


Portfolio, Programs and Projects Management

This process is related to the activities responsible for the management of the portfolio of programs and projects described in the EA plan (EAP). The EAP comprises the programs and projects that implement new architectures for information systems and IT. 

The standards of the Project Management Institute (PMI) describe how to manage portfolios, programs and projects. Our model uses these standards to describe three sub-processes called Portfolios, Program and Projects Management, respectively:

  • Portfolio Management. The portfolio is the collection of projects and/or programs defined within the EA that are fundamentals to achieve the strategic business goals. The portfolio reflects the investment undertaken or planned by the IT Management by identifying required priorities, resources and investment. This process includes the set of activities necessary to define and maintain the strategic alignment between an EA and the business, monitor, and control the behaviour of each of the EA components, review their performance, notify risks, and analyze and authorize changes.

  • Program Management. A program is a set of related projects that are managed in a coordinated manner to create benefits in pro of attaining the strategic business goals. Thus, the activities required for managing programs include the administration of the relationship between programs and the portfolio of projects, and the administration of risks between projects and programs governance. 

  • Project Management. An IT project includes the definition, implementation and control of the effort and the resources allocated to deliver a product or a service. Project management involves activities for planning, organizing, directing, and controlling the required and assigned resources of each IT project. It also implies the support activities for coordinate changes that may emerge during project execution. Project Management process is based on the standards, strategies and IT policies established within the organization.


Quality Management 

Is carried out through a Quality Management System, which must be designed, implemented, and properly managed to ensure, monitor, and improve the quality of the products, processes, and IT services.

The Quality Management System has as its main objective to contribute to the achievement of the strategic objectives of the EA plan. It is achieve through the implementation and execution of processes of assurance, control, measurement, and improvement of the quality of the products, processes, and IT services for the IT Department. Its main sub-processes are identified below:

  • Quality Assurance. It ensures that the IT management processes are running according to the rules, procedures, and standards established by the organization. In addition to fulfilling the obligations on the quality contracted with users or clients and referring both to the IT services and products.

  • Quality Control. It deals with the definition and implementation of measurement methods and standards of measurement and control of the quality of the processes, products, and IT services.

  • Continuous Improvement of Products, Processes, and Services. It refers to the continuous improvement of the quality of the processes to ensure compliance with the objectives and policies of quality set forth in the Quality Plan of the organization.

  • Quality Governance. It is responsible for planning and controlling the quality of the IT processes, products and services. Its main product is the Quality Plan.


IT Security Management

It groups a set of processes responsible for ensuring the security of the data and information which are handled by the information systems, the IT infrastructure, and the services of the IT Department. These processes are called, respectively, Management of the Data Security, Management of the IT Services Security, and Management of the Technological Infrastructure Security.

The IT Security Management must ensure compliance with three main objectives:

  • Confidentiality. It pursues to maintain the necessary protection against unauthorized access to the corporate data and information. It applies to all data (structured, unstructured, documents, and contents) during their storage, processing, and transit.

  • Integrity. It aims to ensure that the data is not altered, in an unauthorized manner, during storage, processing, and transit. This goal applies also to other resources or computing assets (applications, hardware, software, and networks), which should be protected from unauthorized modification, not anticipated or accidental.

  • Availability. The aim is to ensure, without limitations of time or place, authorized access to the computational resources and services of the organization, avoiding the denial of service to those who have the necessary authorization to access the information or to use the computing services. 


Configuration Management

It is responsible for the administration of the EA Repository, which stores all the models and documents related to the enterprise architecture. This process manages, in addition, any changes to these documents and models. It is, also, used to bring the control of changes in the products that are generated in the software development projects and the services provided by the IT Department.

This process takes an up-to-date register of all the elements that configure the EA. This register provides control over the changes and versions of those architectural elements that the organization wants to follow their evolution throughout their life cycle. 

To organize the activities of Configuration Management, our model is based on the IEEE standard 828-1998. The Configuration Management of the EA consists, therefore, of the following processes:

  • Configuration Management Planning. It is responsible for drawing up the plan of each configuration item, specifying its purpose, scope, organization, responsibilities of the actors, phases of the configurations based on their defined baselines, and the documentation of the plan.

  • Configuration Identification. It is about the identification of configuration items and the baseline configuration together with their associated databases, as well as documented deliveries or releases.

  • Configuration Control. It is responsible for the management of the requested changes to the configuration items. It is responsible for the authorization of these requested changes and the corresponding update of the plan after any change is made.

  • Configuration Status Accounting. It records and disseminates the latest state of the configuration items.

  • Configuration Auditing. It verifies and validates the EA configuration. This determines each configuration item of the baseline of the product, its version, and the revisions according to the baseline.

  • Release Management and Delivery. It controls the distribution or delivery of those products that are under configuration control.


Risk Management

This process supports the processes in the value chain (see figure 3) that require to control the risks that may affect the components of the information system and IT architectures. Risk management is applicable also to projects contained in the portfolio of the IT department.

The proposed model takes and adapts the general processes of Risk Management that recommends the PMI, specifically, in the body of knowledge PMBOK. The selected processes are the following:

  • Risk Management Planning. The main goal of this process is to plan the set of risk management activities to carry out. This process is necessary to ensure that the rest of risk management activities are performed effectively and efficiently. Among the activities included in this process are defining methods, tools, techniques and standards that will be used to manage risks of each EA component; developing the work breakdown structure necessary to manage risks within a risk timetable; estimating required resources to manage risks, and outlining the risk management plan.

  • Risk Identification. This process determines the risks that can affect different components of the EA and describes the characteristics of each identified risk. This process includes activities to develop checklists of risks, to analyse the characteristics of the EA components, to identify what risks apply to the different EA components, and to develop the risk log describing the identified risks.

  • Risk Analysis. Process that leads to establish the priorities of the already identified risks and to determine the probability of occurrence and the impact of each of them over the EA components. The activities of this process include selection of the techniques to prioritize the risks; estimation of the probability of occurrence for each risk; determination of the impact that the risk can have on the EA components; development of the probability and impact of risks matrix, and the updating of the risk register.

  • Response Planning. Planning actions that must be taken to prevent or mitigate the negative risks (threats) and encourage the occurrence of positive risks (opportunities).

  • Risk Monitoring and Control. Among the main activities that are performed in this process are implementations of plans in response to risks, monitoring identified risks, identification of new risks, updating risks register and risk management plan.

With this last process description, we conclude the general explanation of each one of processes included in the IT department chain of value. We consider that these processes are essential to perform an appropriate IT management within a medium or large size organization either it belongs to the public or private sector.

Callback before_footer in local_aigrade component should be migrated to new hook callback for core\hook\output\before_footer_html_generation
  • line 7225 of /lib/moodlelib.php: call to debugging()
  • line 7292 of /lib/moodlelib.php: call to {closure}()
  • line 71 of /lib/classes/hook/output/before_footer_html_generation.php: call to get_plugins_with_function()
  • line 987 of /lib/classes/output/core_renderer.php: call to core\hook\output\before_footer_html_generation->process_legacy_callbacks()
  • line 97 of /mod/book/tool/print/index.php: call to core\output\core_renderer->footer()