It Governance

Solution Search:
The Case for IT Governance in a Lotus Notes Environment by TeamStudio
this proliferation is dangerous.

IT Governance specifies decision making authority and accountability to encourage desirable behaviors in the use of IT. I know that...
The Road to IT Governance Excellence by SERENA Software, Inc.
they established an award-winning IT Governance structure as a foundation for improving the business value of their office of Information Technology. CIOs today...
Data Governance Strategies: Helping Your Organization Comply, Transform, and Integrate by Informatica
is best coordinated with IT governance and corporate governance.

This report from TDWI Research clears the confusion by drilling into the business...
Ten Components of Effective ERP Governance by Epicor Software Corporation
the need for enterprise level governance until post-implementation issues have highlighted the gap between IT oriented governance and the governance needed...
Securing the Common Point of Failure in IT Risk Controls by Cyber-Ark Software
a cornerstone of best practice in IT governance, risk and compliance control-except the privileged user for shared administrative accounts, and the embedded...
Sharepoint E-zine Vol.4: Balancing SharePoint Governance by SearchWinIT
place service models and rules for IT governance. That should go a long way toward getting control back in your hands. Want to give up a little bit of control to lighten your...
Information Governance for Microsoft Office SharePoint Services by CA
that provides Information Governance that is efficient, proactive and cost-effective. With new technology advancements, your organization can greatly...
Strategies for Implementing Green IT Management by CA
within six key Enterprise IT Management (EITM) focus segments for green IT initiatives CA provides integrated solutions within six key Enterprise...
IT Agility: Balancing Performance, Security and Cost in a Tight Economy by CA
44; network performance, IT governance, application support and regulatory compliance.

This session will focus on some of the "Big Questions" in IT and...
Doing More With Less: The Art of Data Center Automation by CA
Simplification and standardization of infrastructures will be the dominant themes of the next five years. In this...
Formalizing Operational Governance: Ensuring the Well-managed Enterprise by Vitria Technology, Inc.
Operational Governance poses a significant challenge for businesses today, one that has considerable direct and indirect costs. With the...
SOA Governance: Framework and Best Practices by Oracle Corporation
a framework and best practices for governance as it specifically relates to Service Orientated Architecture (SOA). It also introduces a Six Steps to Successful SOA...
SOA Governance: Necessary Protection for a Strategic Business Investment by IBM
present a business guide for SOA governance based on the most recent user enterprise research and analysis from Saugatuck Technology. This research paper will...
Information Governance: CA/Microsoft Solutions for Compliance, Legal and Governance Responsibilities by CA
comprehensive Information Governance that is efficient, proactive and cost-effective. Today, organizations face enormous challenges regarding the...
Implement and Enforce Security Policies and Report on Your Compliance Efforts by Logicalis
of the data while continuing to make it highly available for the trusted users, applications and services that require it. Leading companies realize that...
How PPM Solutions Are Delivering Value to Organizations by CA
a PPM solution to help optimize IT resources and to better plan business strategies. Gauging resources against tasks and developing manageable...
IT Briefing: Information Governance for Microsoft Office SharePoint Services by CA
Manager manages records in place. It does not move content unless the user explicitly moves it. Enterprises can define and centrally manage all of the...
Information Governance: How Can I Take Control of My Information to Reduce My Enterprise Risk Exposure and Increase Productivity? by CA
CA Information Governance helps you solve an array of challenges with unique solution offerings that include federated records management,...
How Varonis Helps in Sharepoint by Varonis
DatAdvantage software for data governance and Microsoft's SharePoint content management solution. The purpose of this document is to explain the...
Small and Mid-sized Companies in a Slowing Global Economy Gartner On-Demand Webcast by SAP America Inc
gaining more value out of IT assets already in place should be an important focus for small and mid-sized.. In today's market, companies need to make...
SOA Governance Technical Approaches and Requirments by Hewlett-Packard Company
more than just services -- it's about the various artifacts and assets that relate to and affect a service or set of services. Service-oriented...
eBook: Understanding GRC(Governance, Risk Management, and Compliance): Frameworks, Tools and Strategies by SearchSecurity.com
mired in the complexity of governance, risk, and compliance (GRC) requirements and implementing the right policies and technologies is critical for...
The Critical Role of Data Leak Prevention in Governance, Risk and Compliance by Mimecast
become a critical business tool, but it is also the easiest way for information to escape from the confines of a business. Learn why email Data Leak Prevention...
eDiscovery in Data Governance by CDW Corporation
Reich delves into just what a Data Governance plan entails and how the Federal Rules of Civil Procedure's latest eDiscovery amendment impacts this strategy. Data is...
Related Interviews
By Linda Tucci, Senior News Writer
Was there debate within PeopleSoft that it might be a bit shortsighted not to give steady-as-you-go maintenance?

Other than from me? You had development lining up on the side of, 'Absolutely hold to these support polices.' The consulting group wants to sell upgrade services. The development organization only wants to support a limited number of product lines, and there are practical reasons for that. They can't technically support 10 lines forever. In general, they were just incensed it accreted life to releases that they wanted to see retired.
Isn't this a problem for all software?

Everyone has to carry forward their baggage, and a backwards compatibility. Very rarely do you come out with a brand new release that has no connection, in technology, to what you had before, because then you open up the whole competitive realm. 'Well, hell, if your new product isn't really an upgrade, it's a migration, then I might as well look at everybody's else's if I am going to move to a migration.'
How have companies managed this problem before your software maintenance businesses existed?

They thought they could basically use the stick to beat customers forward by threatening them. You've seen that with Oracle. Siebel is the same way -- basically, if you don't upgrade, we're going to pull your support, you'll rue the day, you'll get nothing from us, and we'll still charge you the full amount.
What are the reasons your customers opt for third-party software maintenance?

They do it for different reasons. The small customers were making the move, because it was right after the dot-com meltdown. Prior to that, people were very optimistic, thinking they would be growing 10 times their size. They went in and bought PeopleSoft; it was the Rolls-Royce of HR systems and finance. So now they're stuck with the Rolls-Royce. They love it; they don't want to get rid of it. But they can't afford to keep it. So, a lot of those people, by switching to third-party maintenance, actually were able to keep the software they loved at price points they could afford.
Why did you leave TomorrowNow after the acquisition by SAP?

I left three months after the SAP acquisition; as an entrepreneur I needed to be on to my next thing. I actually was going to go build a software company, but after looking at it, I couldn't stay away from the maintenance stream. When you've got a 90% profit margin, it's just too hard to resist. And TomorrowNow didn't even take 1% of the market. As soon as Oracle announced its acquisition of Siebel, I decided to launch Rimini Street and offer the first third-party alternative into Siebel space.
Oracle must love you, especially given its suit against SAP -- targeted at TomorrowNow.

Oh yeah. I announced Rimini Street at OracleWorld 2005 and I think the words were, 'He's back.' As soon as my noncompetes expired with PeopleSoft and J.D. Edwards products, we introduced those at Rimini Street, too. So now you have two companies -- the captured, SAP-TomorrowNow and our independent Rimini Street -- and we are the only two really credible companies in the industry.
The Oracle lawsuit against TomorrowNow is notable for its strong language -- "corporate theft on a grand scale." Some analysts said that one of the aims of the lawsuit was to scare companies off using third-party maintenance.

Just to give you that color from the lawsuit -- it hasn't deterred the business. The lawsuit actually opened up business -- because some people didn't even know there was a choice. A lot of people read the lawsuit and said, 'My God, Merck and Honeywell, and all these large companies using third-party support.' And instead of saying, 'Wow, look what happened here!' The issue really is, 'Holy gee, am I the only guy paying full price?'
What about maintenance of SAP software at Rimini?

I have a noncompete that expires in January. Let's just say, we're looking with interest at the SAP market. With 30,000 customers, who wouldn't be? They recognize what is good for the goose is good for the gander. You can't complain and say you want Oracle to open up and allow third parties more access and think that is not going to boomerang back on you. They know this is about open access.
AMR analyst Jim Shepherd makes the argument that because everything is changing -- the software platform, the underlying components, your company's business -- that the software needs to be continuously updated.

That's not what we're hearing from clients. They have incredibly stable platforms that they feel like they can run their business on for 10 years. And, in fact, if you look at the recent enhancements from the PeopleSoft product line, it is akin to heated and cooling cup holders -- they're really cool, but it doesn't help me pay my employee any faster.
Who do you go to when you make your pitch? The CEO, the CIO -- who is most receptive to your message?

It's gotta be the CIO and the CFO. The reason is, this is a lot like outsourcing. You're not going to go pitch the IT team how great it is to send your jobs to Infosys. When we come in, how much excitement is there to tell a team, 'Hey, we've got some great news for you -- you guys are going to drive the same car for the next five to seven years instead of that new one you were hoping to play with.' A lot of IT folks do want the excitement of getting new tools and new technology to play with -- and that is part of the fun of it.

Our decision is very much a cost-driven decision, so it is very often the CFO or the CIO who says, 'I'm the guy who has to go before the board and justify we need to spend $2 million on an upgrade when we did it just three years ago, and I can't put down on paper how that money is going to be returned to us in benefits.'


What about people who have just upgraded to the newest version of software -- are they off-limits?

We used to work primarily with more retired or retiring-level versions of the software. Today, 30% to 40% of our business is on the latest versions of the software, so it is people who literally go and do the next upgrade and say, 'You know what, we are done for the next decade. And all that money we bank over the next decade? We will then do a capital expense because a whole new version of software is coming.' In 2015, '17, as late as 2018, you'll see a mature Fusion product against a mature NetWeaver product from SAP, hell Microsoft will probably be offering a full enterprise-level product at the rate they are investing. Rather than play the upgrade game every two or three years that doesn't necessarily yield results but ties up the entire IT team, costs a fortune, instead we're going to make a generational change.
How long should a company hold on to a software product?

We have more customers than ever looking for five- and 10-year guarantees for support. No one makes this change for a six-month change; it is not worth it.

Let us know what you think about the story; email: Linda Tucci, Senior News Writer


It doesn't take much to get Seth Ravin badmouthing big software companies. Ravin co-founded TomorrowNow, which he sold to SAP, and eventually went on to found Rimini Street Inc., an independent provider of enterprise software support services for Siebel Systems Inc., PeopleSoft Inc. and J.D. Edwards & Co. licensees. The companies share the same aim: make software last longer. Ravin's idea of software maintenance evolved from his work at PeopleSoft in the late 1990s. He was in charge of getting 4,000-plus customers through Y2K. The board authorized Ravin to quietly sell customers a Y2K package of support -- on top of their regular maintenance support -- so they could stay on their older releases.

Indeed, as word of the special program spread, enthusiasm reached fever pitch. By 1999, Ravin had customers left and right willing to pay him more than regular maintenance fees, so they wouldn't have to upgrade. Not long after, he left PeopleSoft to join former colleague Andrew Nelson, who had a little consulting business, TomorrowNow.

By Mark Fontecchio, News Writer
How did you get interested in mainframes at such a young age?

I always tell people that it's not my fault. Both my parents were mainframe software developers. It's sort of in my blood. My senior year in high school, I took an independent study course from my dad to learn all the basics. Each summer during college, after graduating from high school, I had an internship with NESI. That's where I learned the majority of what I know now.
Why aren't you administering Linux and Windows boxes like most people of your generation?

When you see the power of how the mainframe can have so much control over things, you get over a little Java program that you can use to run a game or something. I felt like this was more challenging, and I could go further with this type of job. With the mainframe there's so much to learn. There are so many things going on. It's like you can play this game forever and never reach the highest level. That aspect of a mainframe career got to me, and I never looked back.
What does IBM have to do to get young people interested in mainframes?

That's definitely the question of the year. IBM has already been working to address this problem through the Academic Initiative program. We have to get past the stigma that the mainframe seems to have with the younger generation. Most people don't know the mainframe very well. My peers told me I was crazy for going into this career. IBM is trying to get schools to teach this curriculum. It is a problem being worked on, but it's one of those that can't be solved in a week or a day or a year.
How did you get involved in zNextGen?

It sort of began at Share in Boston, which was in August of 2005. They held a little get-together for younger people at a tavern, and that went so much better than people expected it to go. I got involved in it by participating in that. The next thing I knew they decided to make zNextGen a full-fledged project this year. They designated me as project manager, and I was happy to take on the job.
Tell my why zNextGen is such a good thing.

As I'm sure you're aware, there's not exactly a flood of new mainframers coming into the business. The goal isn't to get people interested in mainframes necessarily, but for those getting into the mainframe, there wasn't a community for them to speak and reach out to. We're sort of there to encourage people to come to Share, to branch out in the mainframe community, use your resources out there, build a network of friends and mentors. We sort of have this goal to be the gateway for newcomers to the mainframe.
What are some new, upcoming plans for the group?

We have plans to really work with projects to make sessions more beneficial to members. We also do have some things hopefully planned outside of the Share conference. I was just up in Poughkeepsie, [New York], for an IBM course, and we had a dinner event up there. Hopefully we'll do more of those.

Let us know what you think about the story; e-mail: Mark Fontecchio, News Writer. This article originally appeared on SearchDataCenter.com.
Kristine Harper is not your normal mainframe developer. First, she's a woman. Second, she's 23. So how did she get interested in the mainframe?

By Linda Tucci, Senior News Writer
What is the biggest challenge in getting a job as a first-time CIO? Is it out-competing others who look similar on paper?

I think there is a tremendous amount of competition. Most of the CIO positions out there are usually going through some type of an executive recruiting network. The recruiters I talked to don't usually pull up a set of criteria in a database online. One recruiter I talked to doesn't even recommend candidates putting information into an executive recruiting online database, because most executive recruiters aren't going to use it. They're going to look to the contacts and network of sitting CIOs or deputy CIOs to ask if there is someone on their staff or someone they know.
You became CIO of the World Wildlife Fund at age 37. What helped you most to get that job?

I was recruited for it. I did not approach an executive recruiter for that position; they approached me, at the recommendation of another sitting CIO. I had established my credentials in the private and for-profit sector. I had gotten experience with a variety of technologies at some pretty tier-one organizations: it was Sallie Mae on the financial services side, and PricewaterhouseCoopers on the consulting side. I had gotten all my tickets punched. I got my technical MBA at Johns Hopkins University. I actually took it a step farther. A year after I obtained by graduate degree I started teaching as an adjunct faculty at Johns Hopkins -- intentionally.
As a way to increase your network?

Increase my network, increase my exposure. As an adjunct faculty I was giving back to the IT community and the educational community, but at the same time I was greasing the skids for easier access to publications. When someone was looking at my bio and saw I was a director of this, a tech MBA and teach at a graduate level, when I submitted articles I believe they had a little more merit behind them.
What's the biggest mistake you made in plotting your career?

I'm not sure that I made any.
None?

I really don't think that I have. I've gotten consulting experience, I've gotten for-profit experience, I've gotten Big Five experience, I got my tech MBA, I've got publishing experience, I've got my graduate adjunct faculty. The only thing that I would -- I don't know if this is really a mistake. I was about to say, started my graduate work earlier. But Hopkins wouldn't really let me enroll in the program until I had a specific number of years of business experience.
Fifty percent of your experience is in consulting, and you strongly recommend that aspiring CIOs work as consultants. Why?

You've got to get both sides of the fence if you want to be a viable CIO. You have to understand the consulting proposition. You have to know also how to manage consultants and vendors.

Being a consultant makes you a little bit humble. There are many instances where you have to sidestep and put the brakes on what you may know technically or business wise. You may have to deal with a client or a customer that is not that smart or that doesn't know as much as you do, and you've got to figure out creative and diplomatic ways to get that customer on board or eliminate any roadblocks that the customer may be putting up. In the organizations that use consultants regularly, some of the internal employees are a little bit jaded. They're thinking, 'Why did we have to go to the outside, when we could have probably done this on the inside.' Serving in a consulting role gives you far more experience than flat-out IT experience.
Define for us what you call in your book "the IT glasshouse."

I define the glasshouse as the central IT management infrastructure of the past where all decisions, all the systems and all the policies were pretty much made within the IT shop. If you had to classify it as a government, it would be an IT monarchy. Today, I don't believe that works. I am not a fan of 100% decentralized IT, where managers and staff are completely decentralized and put into business units. I am not saying do a 180-degree from the old model. But I do think that today's CIOs need to work more with the business units and customers of their organizations and form better relations to share the risks, responsibilities and project sponsorship, as opposed to assuming the responsibility in IT or forcing a system on a business unit.
There is a lot of talk about letting your business units take responsibility for the technology they use. But how do you do that? Do you get it in writing?

I do. But I don't let them take responsibility for the technology. I let them take responsibility for the business process that drives the solution. So when we are looking at doing a requirement analysis for trying to solve some problem or drive some goal, whether it is increasing revenue or something else, when we put budgeted dollars toward the project, we use an organizational structure that integrates with the project manager in the business unit itself. I bolt on an IT lead and have at least one business VP take accountability as co-executive sponsors. At the end of the day if I don't get signature from a business unit sponsor for a business unit application, I will not press forward. I make the calls for infrastructure, for security, all those good things. That is my job. But if we are looking for a CRM system, for example, to help drive donor management, the CIO should not own that system. IT should be owned by the business unit that is responsible for the revenue.

I have a simple phrase: IT drives technology decisions. The business units drive application business technology.
I thought it was refreshing to read in your book that a CIO should have a solid grounding in technology, because so much of what you hear now is that this position is being taken over by businesspeople.

I just met one the other day. A new CIO from the business unit, and I think he's scared. Think about it. I take the inverse view that businesspeople can do the job. I think it is way off, and I am not shy in stating that. Look, this is a profession that in my case includes 20 years of work experience at some of the best companies in America. I have gotten a top-tier education. If you combine all that together, I am somewhere in the 28-year range of progressive IT skills and experience, managing technology and applying it to business. Now, would you hire someone who came up that track, who had all that experience in IT, to head up your financial organization? I wouldn't.
The flip side is why is it hard for technical people to speak in business terms?

Given the amount of time they work on the technology side versus the amount of time they spend in the business unit side, it is so easy to lapse back into all of the different acronyms and the lingo the technology people use. I'll be honest. I have to force myself to be conscious of the fact that when I am speaking to a nontechnical audience to not be too technical. I have to force myself, today, and I am a sitting CIO with a new book out giving guidance to others on how to follow in my footsteps. It's hard.
Does it have anything to do with the notion that the kind of people attracted to technology are very concrete in their thinking; they simply think in a different way from businesspeople?

Working in the technology area takes an analytical, top-down, logical, process-oriented person. That said, I think at some point in their career they have to force themselves to branch off and submerse themselves in an environment, like an MBA, which makes them recognize the other side of the fence and to think like a business person. The technology field attracts far more the introvert than the extrovert. I probably started out as a pretty strong-typed introvert and became a forced extrovert as a result of going up the ladder.
When did you turn outward?

When I realized that it was absolutely one of the most important skills needed for an IT executive to have excellent communication skills.
How long did it take you to hone your presentation skills?

Oh gosh. I'll give you the answer in the form of advice given to me from one of my mentors. I asked how long it would be before I was completely comfortable giving presentations to an audience I had never met before. The answer was, once you've done your first 100 or so, you'll get the hang of it.
Your book's title is Straight to the Top, and top for you is CIO. Do you ever think there is somewhere else to go once you're a CIO?

Absolutely. I think it is the next-generation track to chief operating officer, and potentially a CEO of a technology company. I can tell that my career aspirations include one or two of these tracks.
You devoted an entire chapter to golf. I found that a bit shocking.

It wasn't the whole chapter. Half of it was about the vendor management function. I talk about the importance of relying on vendors, having a vendor management strategy, in my case reducing the overall number of vendors, and distinguishing between commodity-based vendors and strategic vendors. I consider Dell a commodity-based vendor. I buy stuff from them and put it in. A strategic vendor will actually help me go from Point A to Point B. It might be a CRM vendor. It might be a consulting vendor. And I talk about that whole process of how do you manage and scorecard your vendor and different approaches for doing that. And I ask other CIOs how they do it. So you'll see stuff about outsourcing.

Then, halfway through Chapter 8 is when I start talking about integrating sports to build your relationships and to grow your network and build stronger relationships with your vendors.
But why go out with them at all, especially given the sensitivity about conflict of interest these days?

Well, let me ask you, define conflict of interest.
There are some companies that say don't even go out for a cup of coffee with your vendors, because you don't need to be friends with them or beholden.

That would be the federal government. And you know what? I understand why they do it. But I don't think that a cup of coffee is going to materially make a difference in the decision to purchase goods or services. I think the federal government has just decided to take that track. But I take the issue beyond the level of the CIO. How many CEOs do you know who go out and have dinner with some of their partners and vendors and colleagues? And how many CEOs and presidents do you see on the golf course? I can tell you I played golf in a tournament and John Thompson was there. He is not a CIO. He is the CEO for Symantec.

It doesn't have to be about who pays for what, as I clarified in my book. My guidance to people is, check what your policies are. If there is a no-pay policy, fine, pay for yourself. There are some clear benefits of getting out of the office and spending some time with people, getting to know them. And at the end of the day, because I have a better relationship both professionally and through sports, I have several vendors who I can pick up the phone and say, 'Listen Tom, I need this done, you need to help me out with this.' Now granted, they should be able to do that regardless, as a vendor. But it doesn't work that way. And if you look at the quotes from the vendors in the book, people tend to reciprocate, form partnerships and get more stuff done, cut through the [bull], when they have a better relationship. And I have found that a 30-minute meeting in my office doesn't get me a better relationship with a strategic vendor.
Another piece of advice you give is that a CIO has to think like a chief financial officer. Why?

If you don't start thinking like a CFO, you're going to be reporting to one.
What is so bad about reporting to the CFO?

Because historically, CIOs who report to CFOs are doing so because the CFO is not comfortable with their financial management skills, or the CIOs need to be reined in on their cost controls. The other research that I found is that CIOs who reported in to the CFO spent overall less percent of the company's revenue than those that didn't. A CFO's job is internal controls, audit, cost containment, financial management and reporting. I don't think that is the best creative place to put a potential innovator and catalyst, such as the CIO, who interfaces with just about everybody. There is no other executive that touches every other point of the organization.

Let us know what you think about the story; email: Linda Tucci, Senior News Writer


Gregory Smith, author of "Straight to the Top: Becoming a World-Class CIO" and CIO of the World Wildlife Fund, talks about his carefully plotted route to the executive ranks and offers some tips for aspiring CIOs.
RELATED TIPS
is becoming obsolete quickly, but it is becoming obsolete [due to the complexity issue]," said Mike Summers, managing director for the disaster recovery...
proposing a twist on the SaaS model it believes corporate customers will find more palatable.

The Cambridge, Mass.-based provider is launching a BPM Platform...