Chapter 2 090716 PDF
Chapter 2 090716 PDF
IT Structure and
Governance
Disaster
Recovery
Planning
IT Outsourcing
IT Structure and
Governance
Disaster
Recovery
Planning
IT Outsourcing
• Key objectives:
1 Reduce risks
Reduces
risk
Involvement
of all
stakeholders Users Strategic
In needs ini=a=ves
complia
nce
with: Corp.
policies
SOX
Centralized data processing
Segregation of duties:
a. Systems development and Computer operations
b. Database administration and all other functions
c. Systems development and maintenance
• Inadequate documentation
• Program fraud
Distributed data processing
• Physical Location
• Construction
• Temperature
• Fire suppression
• Access
• Fault tolerance
Learning
Objectives
IT Structure and
Governance
Disaster
Recovery
Planning
IT Outsourcing
IT Structure and
Governance
Disaster
Recovery
Planning
IT Outsourcing
Outsource In-house
Theory Core competency Transaction cost economics
Pros • Improved core business • Greater control on every
performance aspect of IT function
• Improved IT performance • Tailor-fit to company
• Cost reductions needs
IT Structure and
Governance
Disaster
Recovery
Planning
IT Outsourcing
Procedures:
Test physical construction, fire detection/
suppression system, access controls, RAID, UPS,
insurance coverage
Audit: DRP