IT Governance - The successful IT organization needs to ensure its strategies, policies and methods are aligned with the Corporate Strategies. IT governance is the organized system of responsibilities, polices and processes sets up to achieve the enterprise's goals by adding value while balancing risk versus return over IT and its processes.

The key components of IT Governance are Strategic Planning, Portfolio Management and Enterprise Architecture.
 
IT Governance dimension IT Governance tasks IT Governance processes
Strategy Define IT Vision Strategic Planning
Strategy Select, prioritize IT Investments / IT Projects IT Portfolio Management
Strategy Coordinate, control and review projects
Strategy Enterprise Asset Management
Enterprise Architecture:
Organize IT assets, strategies and standards into a multi-layered framework:
To facilitate day-to-day IT decision and action
To manage IT Assets
Conformance Internal controls / risk management and law compliance Part of enterprise governance compliance framework
 
IT Governance processes
 
Strategic Planning
The IT Organization needs to understand the Corporate Strategies, IT Technology and Trends to develop a plan, synchronized with themes and strategies and reflecting all the factors affecting these areas to be recognized, accepted and viable.
 
Enterprise Architecture
It represents a snapshot of where the organization is today, where it wants to go in the future and the roadmap to reach it. EA is a blueprint driven by the strategic goals of the enterprise to support the Business
 
IT Portfolio Management
IT portfolio is mapped to investment strategies and is a managed set of assets (hardware, software, human capital, processes and projects):
to select, prioritize and authorize IT Investments
and to manage and coordinate IT Projects.

The creation of programs and projects in support of the IT Strategic Plan must be evaluated, prioritized and monitored to provide consistent results and allow for adjustment as necessary.

 
Risk Management
Develop, implement and use a system of policies, method and tools to identify and manage IT-related risks (Basel II and SOX compliance)