COM7007: IS Governance Report on Islamic Development Bank

Verified

Added on  2022/09/11

|18
|4322
|21
Report
AI Summary
This report critically assesses the role of Information System (IS) Governance within the Islamic Development Bank (IDB), emphasizing its importance in managing sensitive financial and customer data. It explores the alignment of IS governance with organizational factors, specifically highlighting the use of COBIT 5 and its impact on stakeholder needs, goal setting, and risk optimization. The report evaluates the effectiveness of existing IS governance policies, plans, projects, and priorities, suggesting improvements such as organization-wide integration, a risk-based approach, and clear investment goals. Furthermore, it analyzes the crucial link between IS governance and business strategy, emphasizing the alignment of IT strategies with business objectives to ensure effective investment and business success. The report also discusses potential discrepancies and provides recommendations to address them, ultimately focusing on enhancing confidentiality, integrity, and availability of information, and fostering a robust system environment for stakeholders, concluding with the benefits of IS governance for the organization, including strategic alignment, risk management, value delivery, and resource management.
Document Page
Running head: IS Governance
Information System Governance
Name of Student
Name of the University
Author notes
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
1IS GOVERNANCE
Table of Contents
Introduction................................................................................................................................3
Organizational overview............................................................................................................3
Question 1:.................................................................................................................................4
Need of information system governance................................................................................5
Organizational factors aligned with IS governance...............................................................6
Question 2:.................................................................................................................................7
Confidentiality........................................................................................................................7
Integrity..................................................................................................................................7
Availability.............................................................................................................................8
Necessary suggestions for improvement of the IS governance policy..................................8
Establishing information system organization wide..........................................................8
Adopting risk based approach............................................................................................8
Setting clear goal of the investment decision.....................................................................9
Conformance with the external and internal requirements................................................9
Fostering system environment for the stakeholders...........................................................9
Question 3:.................................................................................................................................9
Question 4:...............................................................................................................................11
Challenges and solution.......................................................................................................12
Information management.................................................................................................12
Regulatory compliance.....................................................................................................12
Storage management........................................................................................................13
Document Page
2IS GOVERNANCE
E-Discovery......................................................................................................................13
Benefits of IS governance for the organization....................................................................14
Strategic alignment...........................................................................................................14
Risk management.............................................................................................................14
Value delivery..................................................................................................................14
Resource management.....................................................................................................14
Conclusion................................................................................................................................14
Reference..................................................................................................................................16
Document Page
3IS GOVERNANCE
Introduction
The objective of the report is to discuss the role of information system governance.
Discussing the role of information system governance from an organizational perspective, it
can be analysed that, this particular approach is increasingly essential yet critical process that
depends on the nature of the information. The policy is important for avoiding the unethical
access to the information and reducing any kind of uncertainty over the information by
providing higher system to it (Flores, Antonsen and Ekstedt 2014). On a broader aspect the
concept of information governance can be explained by the system using which an
organization can control as well as direct the process and policies related to the IT system.
This report is going to discuss about the Information system governance policies,
elements of the Saudi Arabia based Islamic Development Bank. In addition, the interrelation
between the business strategies of the organization and the IS governance along with the risks
and opportunities related to this process are going to be discussed in this report. Moreover,
the Information system governance also specifies the organization’s accountability
framework as well as provides an oversight for ensuring that all the risks are mitigated
adequately (Whitman and Mattord 2014).
Organizational overview
Founded in the year 1973, the Islamic Development Bank is one multilateral financial
developmental institution that emphasizes on enhancing the Islamic finance present in the
Saudi Arabia. Currently, the organization has approximately 57 number of memberships in
different states and identified as the single largest stakeholder of the Saudi Arabia. With the
motto of “together we build a better future”, the organization is now serving the country
people successfully. A total of 932 individuals are currently being employed inside the
organization (Isdb.org. 2019). The major activities of this organization includes SME
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
4IS GOVERNANCE
financing, Emergency relief, resource mobilization, trade financing, reinsurance and
insurance coverage for the investment as well as export credit, financing the projects of
private and public sectors, providing technical assistance for building higher capability and
many others. Holding thousands of crucial and sensitive financial and other customer related
information, it has become necessary for the organization to maintain higher system of those
information and protecting those from unethical accesses.
Question 1:
Critically assess the extent to which IS Governance is aligned, inclusive, educated,
engaged, connected and informed in relation to the existing system in your organisation.
Organizational factors aligned with IS governance
Usage of COBIT 5 is made by Islamic Development Bank. COBIT 5 finds its usage in
the operational section of the bank. With the help of this governance tool, management
support have been getting benefitted to the highest extent. The organizational factors that act
crucial for the bank includes the likes of developing proper understanding regarding
stakeholder needs. Developing both short term as well as long term goals also act important.
Cascading of goals also act important in the operational process. It have been seen that
COBIT 5 framework infrastructure is integrated in such a manner that it fulfils the above
stated requirements. This framework also helps in performing benefit realisation,
optimisation of resources as well as risk optimization. These are the aspects that benefits
fulfilling the stakeholder demands. Setting of enterprise goals have been another task that is
performed by COBIT 5. Thus it can be stated that alignment of the COBIT 5 framework is
high with the requirement of the bank.
In order to gather efficient result from the IS governance practice, it is mandatory for the
business to have supporting elements such as infrastructure, organizational network and many
Document Page
5IS GOVERNANCE
others. However, the necessary factors that are aligned with the information governance
policies and practices of the discussed organization are as follows;
Organizational structure
Strategic planning
Establishment of role and responsibility
Integration with enterprise architecture
Documenting the objectives of the system in guidelines and policies.
The strategic planning of the discussed organization is widely explained by the
enterprise strategic planning, IT strategic planning, IS or cyber system strategic planning.
The first factor that is the enterprise strategic planning includes strategies for defining long
term goals of the organization and the ways of achieving it (Bobbert and Mulder 2015).
Meanwhile, the IT strategic planning of this organization usually aligned with the IT
management, operations and the enterprise planning for managing the technical aspects of the
organization. The purpose of the information system governance of the selected organization
is to pervasive using and understanding the value of the information and ensuring its system.
COBIT 5 is an educated system as data analysis is made and hence wise system
generated decision making is also made. Data is gathered in daily basis. These data are stored
in the system (Huygh et al 2018). This stored data set ensures that information that is
gathered and used in the process will be having a better management of the data and hence
wise better data analysis can be performed. The data that are stored in the system are updated
in a frequent manner. This section ensures that the Information System governance tool stays
well informed.
COBIT 5 is engaged in a differential manner. The methodology that is performed
includes proper mapping of the current IT process. Setting of Goals and framework risks that
Document Page
6IS GOVERNANCE
might be present in the operational process is performed in a proper manner. Stakeholder
engagement is yet another section that is affected in a positive manner.
Question 2:
Evaluate the effectiveness of the existing IS Governance policies, plans, projects and
priorities and identify any areas of improvement.
The IS Governance policies can be differentiated in between IT Policies and Policies
as Enablers. Being in a Banking domain the main aspect that will be considered is that there
will be several IT operations. It have been seen that IT policies are not only related to the IT
principles but also end to end business processes have been considered. Performing proper
cooperation across the bank have been one of the major aspect that is performed with the help
of the COBIT 5. With the help of proper COBIT 5 proper communication of policies can be
made. Policies as Enablers deals with different stakeholder dimension, goal dimension, Life
Cycle Dimension as well as Good Practices Dimension (Pereira, Ferreira and Amaral 2017).
Strategic Planning can be made with the help of COBIT 5. There are certain data sets
that are required for performing strategic planning. The section includes the likes of
collecting data regarding generic enterprise goals, goals are the cascaded with all levels.
Developing IT generic goals are also performed in this section. Proper mapping in between
IT strategic goals as well as enterprise strategic planning can be made. Data regarding
enabler’s goal are also collected. Enabling process of governance and management have been
included in the process as well. Analysing stakeholder needs have been another domain that
is considered in the process. Details regarding life cycle phases also acts important in the
planning process of COBIT 5 (Pane et al 2018).
COBIT 5 have been benefitting the prioritization process. There are few sections that
are considered while performing the prioritization process. The processes are namely
ensuring governance framework setting and maintenance. After this process, analysing the
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
7IS GOVERNANCE
benefit delivery is also considered. After this benefit delivery process, risk optimization is
also performed. Risk optimization plays as an important factor that will ensure proper
understanding of the prioritization. Resource optimization have also been another aspect that
is to be considered. After gathering data of such process, the entire prioritization process
begins (De Haes et al 2016).
The above discussed policies related to the IS governance in context of the selected
organization are definitely efficient for maintaining the confidentiality and system of the
information. Yet, there are some principles or practices need to be carried out by the
organization for enhancing the above discussed IS governance policies.
Necessary suggestions for improvement of the IS governance policy
Establishing information system organization wide
Information system or mainly known as the cyber system shows higher concerns to
the existing structure and function of the organization. Therefore, the management of all
levels need to ensure that the information system of the organization should integrated with
the IT and other necessary activities. It is necessary for the top level management of the
discussed organization to ensure the selected areas of the information system practice and
principle to serves the overall business objectives by establishing higher responsibility as well
as accountability throughout the business (Kim and Ahn 2013).
Adopting risk based approach
System governance, which mainly involves the allocation of resources as well as
budgets, need to emphasize on the risk appetite of the organization. In addition, it also focus
on minimizing the competition, compliance along with all the liability risks, reputational
harm, financial loss and operational disruptions (Flores, Antonsen and Ekstedt 2014).
Document Page
8IS GOVERNANCE
Setting clear goal of the investment decision
The investments related to the process of Information system need to support all the
organizational objectives. Additionally, the process will also ensure that the IS governance
policy to be integrated with the existing processes of the organization so that the capital as
well as operational expenditure, can be efficiently addressed and the risks associated with the
organization can also be avoided.
Conformance with the external and internal requirements
The external requirements usually involves the mandatory legislation as well as the
set of regulations and standards that lead to the contractual requirements and certification. On
the other hand the internal requirements encompasses the organizational objectives and goals
on a broader aspect (Tsiakis, Kargidis and Chatzipoulidis 2013). Ensuring both the
requirements effectively, the discussed organization can ensure efficient accessibility to the
information.
Fostering system environment for the stakeholders
The information system policies undertaken by the organization need to be discussed
with the stakeholders and it should responsive to the expectation of the stakeholders’.
Promotion of the IS cultures and providing necessary training to the employees regarding
maintenance of the system is also essential for addressing all the facilities provided by the
discussed technological solution.
Question 3:
Analyse the link between IS Governance and the business strategy. Are there any
discrepancies? How would you address them?
The main goal of involving the IS governance into the organizational workplace is to
gather a set of tools, methodologies as well as processes for maintaining the system of the
Document Page
9IS GOVERNANCE
organizational information. Identification of the relationship between the business strategies
and the IS governance, the fact that comes into consideration is that, aligning the business
strategies with the selected technological solution can be beneficial for the organization in
addressing its goal and objectives (AlHogail and Mirza 2014). The IS governance is nothing
but a formal framework that helps the organization in aligning the IT strategies with the
business strategies, thus ensuring effective investment and success of the business.
(Figure 1: Relationship between the information system governance with business strategy)
(Source: Kim and Ahn 2013)
The main role of including IS governance into the business environment of the
discussed Saudi Arabian bank can be analysed in terms of building successful strategic plans
(Whitman and Mattord 2014). Strategic plans are nothing but the documentation of the
business objectives and goals and the actions required for achieving the goals. The
management actions or activities involved in the process of strategic planning of the
organization can be explained by the set of practices, priorities, focus, energy as well as
resource need to strengthen the operational functionality of the organization so that the
organizational objectives can be achieved. In addition, the process of IS Governance also
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
10IS GOVERNANCE
known as one potential solution for resolving the business challenges and dilemmas (Rebollo
et al. 2015). It also ensure that the organizational investment on the IT environment and its
associated components will generate higher value and migrate all the risks associated with the
IT environment of the business by avoiding chances of failure (Gashgari, Walters and Wills
2017). An efficient IS Governance strategically aligns the business so that it can support any
technical evolution. Moreover, it prioritise that the enterprise architecture will delivers
consistent as well as scalable business values despite of going through current technical
evolution. Emphasizing on the risk management and overall performance of the organization
for addressing the metrics definition, undertaking rigorous process, making costs efficient
business and controlling the objectives of the organization also comes under the area of an
successful IS governance (Ula and Fuadi 2017). The chosen organization can also measure
effectiveness of the technological revolutions, business goals and analysing the financial
condition of it by aligning the IS governance policies with the business strategies.
Question 4:
Identify the values, risks and opportunities to your organisations IS strategy derived
from the modifications and revisions proposed to IS Governance in your audit.
As the business objectives of the Islamic Development Bank is to provide financing
and technical solution to the country people. Despite of having several facilities of
implementing the IS governance practices and policies; yet there exist certain challenges that
might hinder the functionality of the particular process.
Challenges and solution
Information management
Information management inside the organization needs the retrieval, system,
acquisition, as well as maintenance of all the information of the organization in an efficient
Document Page
11IS GOVERNANCE
manner. However, in case of organizations like Islamic Development Bank, it is essential for
the organization to deal with a vast amount of information, therefore, managing such amount
of information sometime create several complicacy for the organization.
Solution: In order to achieve successful results from the information governance process, the
selected Saudi Arabian organization need to implement an efficient information management
automation model (Silic and Back 2014). This suggested solution can discard several
essential responsibilities such as, data storage, maintenance and even the need of backup and
it will also ensure that the particular organization will have higher system over its information
and data.
Regulatory compliance
Regardless of the country, there exist some regulatory requirement on having records,
which explains the type of information need to be storage and also decides its storage period.
Therefore, information related to this type of retention requirements need be stored, managed
and accessed with special care. If any case any violation to the compliance requirements
found, it can gather several expensive legal proceedings as well as fine for the organization,
which ultimately will harm the reputation of the organization (Debreceny 2013). Hence, it
definitely create a challenging situation for the IS governance practice.
Solution: In this case, implement one information governance software in the organization
automatically store the electronic records automatically by analysing the industry regulations
is vital. In addition, a proper archiving system can also be considered as another solution,
which will ensure that the data is automatically stored without having any end user
management.
chevron_up_icon
1 out of 18
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]