D2IT Governance

IT Governance: Glossary

Balanced Scorecard (BSC)
A strategic management framework that measures organizational performance across four perspectives: financial, customer, internal business processes, and learning and growth.
Business Case
A documented justification for a proposed IT investment that includes expected benefits, costs, risks, and alignment with business strategy.
Business Impact Analysis (BIA)
A process that identifies critical business functions and quantifies the impact of a disruption, including financial loss and recovery priorities.
CMMI (Capability Maturity Model Integration)
A process improvement framework that defines five maturity levels: initial, managed, defined, quantitatively managed, and optimizing.
COBIT (Control Objectives for Information and Related Technologies)
A governance and management framework for enterprise IT published by ISACA. It provides a comprehensive set of controls and best practices for IT governance.
Enterprise Architecture (EA)
A framework that defines the structure and operation of an organization, including business processes, information systems, and technology infrastructure.
Enterprise Risk Management (ERM)
A structured approach to managing all risks across an organization. It aligns risk management with business strategy and objectives.
Gap Analysis
A comparison of actual performance or state against desired or expected performance, identifying differences that need to be addressed.
IT Governance
The system by which the current and future use of IT is directed and controlled. It ensures IT investments support business objectives and manage risks appropriately.
IT Steering Committee
A cross-functional group of senior executives responsible for prioritizing IT investments, monitoring project progress, and aligning IT strategy with business goals.
IT Strategy
A comprehensive plan that defines how technology should be utilized to meet business goals. It must be aligned with the overall organizational strategy.
ITIL (Information Technology Infrastructure Library)
A set of best practices for IT service management (ITSM) that focuses on aligning IT services with business needs across the service lifecycle.
Key Goal Indicator (KGI)
A metric that measures whether an IT process has achieved its objectives. KGIs are outcome-focused and typically measured after the fact.
Key Performance Indicator (KPI)
A measurable value that demonstrates how effectively an organization is achieving key business objectives. KPIs are lead indicators of performance.
Key Risk Indicator (KRI)
A metric used to provide an early warning signal of increasing risk exposure in various areas of the enterprise.
Outsourcing
The practice of contracting IT functions or services to a third-party provider. The organization retains accountability for governance and oversight of outsourced services.
Policy
A high-level document that communicates management intent and direction. Policies are mandatory and set the framework for standards, procedures, and guidelines.
RACI Chart
A matrix that defines roles and responsibilities for tasks or deliverables. RACI stands for Responsible, Accountable, Consulted, and Informed.
Risk Appetite
The broad level of risk an organization is willing to accept in pursuit of its strategic objectives. It is set by the board and senior management.
Risk Assessment
A systematic process of identifying, analyzing, and evaluating risks to organizational assets, operations, and objectives.
Risk Tolerance
The acceptable level of variation in performance relative to the achievement of objectives. It is more specific than risk appetite and applies to individual risks.
Segregation of Duties (SoD)
A control principle that divides critical functions among different individuals to prevent fraud and errors. No single person should control all phases of a transaction.
Service Level Agreement (SLA)
A formal agreement between a service provider and a customer that defines the expected level of service, including availability, performance, and responsibilities.
SMART Objectives
Goals that are Specific, Measurable, Achievable, Relevant, and Time-bound. Used in IT governance to set clear and trackable objectives.
Standard
A mandatory requirement that supports a policy. Standards define specific rules or specifications that must be followed to comply with organizational policies.
Total Cost of Ownership (TCO)
A financial estimate that includes all direct and indirect costs associated with acquiring, deploying, operating, and retiring an IT asset over its full lifecycle.