2012-06-27

Writing IT strategy - From business priorities to the planning of IT actions

This post is the continuation of the post "Writing IT strategy" -  http://improving-bpm-systems.blogspot.com/2011/09/writing-it-strategy.html

The explicit dependencies between business-specific initiatives, business-generic needs (or business capabilities), IT-generic capabilities and programs demonstrated in figure below allow to explicitly linking the business priorities with the planning of IT actions. The logic of linking is the following:
  1. each business-specific initiative has its own corporate priority;
  2. each business-specific initiative requires a particular level of maturity of some existing business-generic needs;
  3. each business-generic need has its own current level of maturity (can be determined by experts) and the requested level of maturity (so a gap can be identified);
  4. particular level of maturity for each business-generic need depends on a particular level of maturity of some existing IT capabilities;
  5. each IT capability has its own current level of maturity (can be determined by experts) and requested level of maturity (so a gap can be identified);
  6. programmes to close gaps are proposed, and
  7. priorities of programmes are defined by the contribution into business priorities.

Thanks,
AS

2012-04-09

Architecting modern information systems

My course "Architecting modern information systems" (please, see its structure below) is available at slideshare.net.

The class in Tunisia:


 Module 1: Enterprise architecture (EA) http://www.slideshare.net/samarin/architecting-of-modern-information-systems-m1
  •  Architecture within an enterprise 

 Module 2: Business architecture http://www.slideshare.net/samarin/architecting-modern-informaiton-systems-m2a and http://www.slideshare.net/samarin/architecting-modern-informaiton-systems-m2a-business-architecture
  •  Management by processes 

 Module 3: Application architecture http://www.slideshare.net/samarin/architecting-modern-informaiton-systems-m2b-application-architecture
  • Link applications to the business 
  • Technologies: BPM, BRM, BEM, BAM 
  • SOA, Integration (ESB), Application systems (suites) 

 Module 4: Information architecture http://www.slideshare.net/samarin/architecting-modern-informaiton-systems-m4-information-architecture
  • Knowledge management 
  • Technologies: ECM, MDM, BI, risk management 

Module 5: Technology architecture
  • Flexibility systems 
  • Security considerations 
  • Virtualisation 

 Module 6: Modern disruptive technologies http://www.slideshare.net/samarin/architecting-modern-informaiton-systems-m6-modern-disruptive-technologies
  • Cloud computing 
  • Social computing 
  • Free and Open Source Software; Open standards 

 Module 7: Essential techniques http://www.slideshare.net/samarin/architecting-modern-informaiton-systems-m7-essential-techniques
  • Project management (PMBOK, HERMES)  
  • Governance (COBIT)
  • Writing the IT strategy
Thanks,
AS

Lettre de remerciement



2012-01-14

Enterprise pattern: SITO, extended

Comments to SITO enterprise pattern (see the updated version of it at http://improving-bpm-systems.blogspot.com/2011/10/enterprise-pattern-structuring-it.html ) were that it is too classic. Sure, structuring is the first step to establish the balance between functions and projects.

Next step is how to preserve, enrich and re-use the technical/business knowledge and experience gained in each project. A possible way is to create competence forums which are oriented to deliver business-generic services (or "needs" as they mentioned in http://improving-bpm-systems.blogspot.com/2011/09/writing-it-strategy.html ). Usually, such services are based on several IT-generic services which are mastered in different IT functions.




How those competence forums to be managed to avoid over complication and conflicts of responsibilities? Competence forum is led by the CIO with the help from an informal leader from the participants. For example, the CIO chaired a few initial meetings and then delegates the routine work to the informal leader.

Next step, the IT governance, was already covered in http://improving-bpm-systems.blogspot.com/2011/01/relationships-between-ea-and-pmo.html . Just a small addition to that post:
  • EA (or EITA) defines/monitors WHAT should be done (technical coordination of the enterprise IT environment).
  • PMO defines/monitors HOW it should be done (administrative coordination of changes in the enterprise IT environment).
Both EA and PMO are top-down and they are supported by bottom-up ITIL (http://improving-bpm-systems.blogspot.com/2011/01/relationship-between-ea-pmo-sdlc.html ). 

Thanks,
AS

2012-01-06

Enterprise anti-pattern: Silo-Oriented Virtualisation Anarchy (SOVA)

That was found in the same organisation....

Normally, an organisation of this size should not used more than 2 virtualisation products.

Thanks,
AS

2011-12-18

Enterprise pattern: #Cloud-Ready Estimation and Evaluation Procedure (CREEP)

The aim of this post is to consider a systematic procedure for estimation and evaluation of cloudability of an IT service – what type of cloud (GOLD, YELLOW, GREEN, BLUE, VIOLET) is acceptable for a particular IT service and for what cost. Quick reminder re the zone types (from http://improving-bpm-systems.blogspot.com/2011/07/1-relationships-between-enterprise.html ):
  • classic within enterprise computing centre – zone type GOLD; 
  • within enterprise private cloud – zone type ORANGE; 
  • outside enterprise and enterprise-managed private cloud – zone type GREEN; 
  • outside enterprise and service-provider-managed private cloud – zone type BLUE; 
  • public cloud (outside enterprise and service-provider-managed by definition) – zone type VIOLET. 
The evaluation consists of two parts:
1. ranking of an IT service by several characteristics,



2. decision table for acceptability of cloud solution (actually, what ZONEs are acceptable for this IT service). 
Note: “maybe” means that further investigation is necessary;
Note: more than one column for GREEN, BLUE, and VIOLET can be possible if you work with several providers

Example: SharePoint Extranet


Ranking applied


Decision table applied



Rules for the recommendation :
  1. If at least one “NO” then “NO”
  2. If no “OK” and some “maybe” and “IaaS/PaaS/SaaS” then “maybe” + “IaaS/PaaS/SaaS”
  3. If some “OK” and some “maybe” and “IaaS/PaaS/SaaS” then “OK” + “IaaS/PaaS/SaaS”

Note: CAPEX and OPEX are functions of a service and a zone type.

Resume: 3 zones are not recommended, 2 accepted as SaaS:
1st preference SaaS in BLUE zone; CAPEX = ...  OPEX =... Lead time=....
2nd preference SaaS in GREEN zone; CAPEX =.. OPEX =... Lead time=...

Thanks,
AS

2011-10-15

Enterprise pattern: Structuring IT Organisation (SITO)

How to decompose an IT organisation into smaller units?

Approach

  1. Collect major IT-related functions (approx. 30-50) to be carried out at an IT organisation; potential sources COBIT, ITIL, PMBOK, PRINCE2, HERMES, etc. 
  2. Draw a matrix of mutual relationships between those functions or group of functions (about 10) 
  3. The relationships may be like “synergy” (functions to be carried-out rather together) 
  4. The relationship may be like “prohibition” (functions to be carried-out by different units because of SoD principle, good practices, etc.) 
  5. Each particular relationship has to be justified 
  6. Find clusters in that matrix 

Example of  the relationship matrix:

Potential functional groups

  • GOVERN – administrative coordination as the whole -- set and maintain internal policies, controls and processes
  • ARCHitect – technical coordination – define structural changes (of core capabilities and services) in response to business and technologies changes
  •  Make SAFE (added to be conceptually complete) – define policies concerning the confidentiality, integrity and availability of information services 
  • Supervise building of core services and capabilities – project management (PM) Supervise operating of core services and capabilities – operations monitoring (OM
  • BUILD core capabilities and services: application services, information services and infrastructure services 
  • OPERate core capabilities and services – integration, pilotage and service desk
  • EVALuate (as an independent control) capabilities 
  • INTERNal support capabilities 

Define YOUR rules for decomposition

Depending on your current needs and concerns, define two group of rules.

Prohibition rules:
  • P1 Separate doing and supervising/controlling – SoD 
  • P2 Separate architecture/design and implementation – SoD, specialisation and quality at entry 
  • P3 Separate implementation and operation – SoD, specialisation and quality at entry 
  • P4 Policy vs applying it – legislation vs executive separation 
  • P5 Specialisation

Synergy rules:
  • S1 Close work (e.g. there is a primary / single client for services of that function) 
  • S2 Architecture role to guide (an architect is a person who translates a customer’s requirements into a viable plan and guides others in its execution) 
  • S3 Synergy between technical and administrative activities (how you do something may be more important what you do)

Example of relationship matrix

 

Arrangement of functions into smaller units (divisions)

BUILD-related functions are decomposed into three (process-centric, knowledge and infrastructure) due to specialisation.


So, the structure should be as shown below.


Thanks,
AS

2011-10-09

EA view on Enterprise Risk Management (ERM) platform

In many cases, it is impossible to find a single ERM product which spans all business areas to be covers by ERM. So, it requires building an internal ERM platform on top of which different ERM-related applications will be built (following the PEAS enterprise pattern – see http://improving-bpm-systems.blogspot.com/2011/04/enterprise-patterns-peas.html ).

Business architecture view

Risk must be carefully monitored (through data collection), evaluated and acted upon. This means (see also the illustration below):
  1. Enterprise business functions should be enriched to generate the risk-related data.
  2. Those risk-related data need to be collected at the enterprise data warehouse together with other business data.
  3. Some business processes need to be updated to embed risk-related activities.
  4. A set of risk-related rules, logic and risk-related knowledge should be able to use the risk-related and other business data to detect acceptable limits of risk as well as interdependencies and correlations between different risks.
  5. Some business processes for risk mitigation maybe automatically activated.
  6. A lot of risk-related indicators, alerts should be available in the form of dashboards and reports available for different staff members.
  7. Staff members should be able to initiate business processes based on the observed risk-related information.



Business-generic capabilities involved

The following business-generic capabilities are involved in the ERM platform:
  • Management by processes
  • Efficient data gathering channels
  • Single version of truth for data
  • Ingesting (into the data warehouse) of external information
  • Efficient dissemination channels
  • Effortless collaboration within groups / communities of practices
  • Formalized business logic

Supremacy of management by processes

Managing any work by processes is the key business capability with allows to address the risk-related issues in a proactive manner. The risk is strongly related to how the business processes are carried out. By understanding a process (i.e. through being able to simulate it) the business may predict how the risk is changing during the execution of that process. The explicit description of processes permits to add a few “check-points” within any process to examine its risk-related “health”.

Business processes act as a skeleton to which the enterprise adds risk management (as shown on the picture below) – each usual activity is enriched by risk-related monitoring and evaluation.

The risk evaluation may initiate some risk mitigation processes. The risk evaluation may be as complex as necessary, and it may include simulations (e.g. value at risk and stress testing), and the conduct of statistical and scenario analysis.

IT-generic capabilities involved

The following IT-generic capabilities are involved into the ERM platform:
  • Enterprise resource planning platform
  • Data analytic
  • Business process management platform
  • Business intelligence platform
  • Business rules management platform
  • Document management platform
  • Corporate portal

Thanks,
AS