You are not authorized to post comments.

Interview: IT Controls Benchmark Survey Results - Gene Kim, IT Process Institute

By David Geer, ITworld.com |  Business Add a new comment

David Geer recently spoke with Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute, an independent research organization that exists to support the membership of IT audit, security, and operations professionals. Following is an edited transcript of that conversation. You may also listen to the original interview here, or visit our Podcast Center for more audio interviews.



Digg!




Hello, I'm David Geer, and we're talking with Gene Kim about the IT Controls Benchmark survey conducted by Kim and researchers from Carnegie Mellon, Florida State, and the University of Oregon, and published by the Institute. For this survey, 98 respondents from a wide range of company sizes and industries were queried with 97 questions related to IT controls. Forty-three percent of respondents were directors, vice presidents, or C-level managers. The purpose of the survey was to demonstrate how IT organizations can begin to move from good to great in handling IT control issues.



David Geer: In general, why is this survey important?



Gene Kim: This survey is important because I think we're starting to test the medication that we're doling out. In the manufacturing world, there was a big breakthrough in the decision sciences around automotive manufacturing when the lean manufacturing researchers out of MIT basically benchmarked every major automotive manufacturing plant in the world and they found out, wow, high performance exists. They have one-half the floor space, one-half the defects, one-half the inventory, one-half the cycle time, and they've called these the high performers. And they went out and captured and codified what they did. And so what the IT Controls Performance Study is all about is really trying to replicate that same methodology and figure out what is it exactly that the high-performing IT organizations are doing, and figure out more specifically what is it that the medium and low performers aren't doing that's keeping them from being high performers.



Geer: The two top controls in this survey that were most universally present in the high performers and yet virtually absent in everyone else, including 87% of the rest of the respondents, were monitoring systems for unauthorized changes and having defined consequences for intentional unauthorized changes. What surprised you about these results, Gene?



Kim: You just really put your finger on one of the two big surprises that came out of the study, which was that of the 63 controls and the six ITIL processes that we tested, what we were looking for was, is there a smoking gun that says there are a handful of things that management is focusing on in the high performers that none of the medium and low performers are. In other words, is there a small set of things that might be keeping the low and medium performers from becoming high performers?



High performers are doing two things that medium and low performers aren't, which is do you monitor a system for unauthorized change? And the second one is, do you have defined consequences for intentional unauthorized change? So the reason we think this is important is that when you take a look at ITIL process frameworks or COBIT control frameworks, they're full of many good ideas, but you can't do all of them. So if you can't do all of them, where do you start? Where do you have the highest rate of return? Where do you get the biggest bang for the buck? And these are things that these descriptive frameworks don't really give us a lot of guidance to management on.



So what we did in this survey was really tried to create the tool so that management can focus on what is most important -- which controls and behavior and processes really lead to the most improvements in IT effectiveness and IT efficiency.

ITworld LIVE

BusinessWhite Papers & Webcasts

Webcast On Demand

Delivery Management -- Extending Lifecycle Management

Date: Wednesday, June 20, 2012, 1:00 PM EDT Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs, project delays, lower quality, and time-to-market delays. Providing a collaborative platform where the whole organization can prioritize, share and manage deliveries with more transparency can help the organizations make more informed decisions at all levels, and greatly improve communications and traceability between teams. Hear from application lifecycle management experts how to increase delivery efficiency and effectiveness with a new approach to Delivery Management.

Sponsor: IBM

White Paper

Gartner: Magic Quadrant for Midrange and High-End Modular Disk Arrays

This Magic Quadrant represents vendors that sell into the end-user market with branded midrange and high-end modular disk array storage systems that support block-access protocols. Despite rather gloomy macroeconomic conditions worldwide and ongoing geopolitical unrest in the Middle East, the midrange and high-end modular disk array storage market grew 8.2% from 3Q10 through 2Q11, compared with the same period the year before. Propelled by technological innovation and enhanced scalability, this continued growth in vendor revenue supports the observation that IT executives are willing to invest in modern midrange and high-end modular disk storage systems to improve operational efficiency, to support deployments of virtualized IT infrastructures, and to address the impact of unabated terabyte growth.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

White Paper

Seven Priorities for Integrated Network Management - How HP Intelligent Management Center Delivers an Enterprise-class Solution

This white paper describes the major requirements for network management solutions to help the organizations become more profitable, efficient and reliable.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Webcast On Demand

Operational Analytics - Changing the Competitive Dynamics of the Business

Date/Time: June 5, 2012, 11:00 a.m., EDT, 4:00 p.m. BST / 3:00 p.m. UTC Please join us for this webcast, as Dr. Barry Devlin, Founder and Principal, 9sight Consulting, describes what operational analytics can do for your business and reviews an architectural approach that will enable you to make it a reality.

Sponsor: IBM

White Paper

The Total Economic Impact of the HP 3PAR Storage

Forrester Research provides an analysis of four HP 3PAR storage customer implementations to quantify the efficiency and cost savings achieved over legacy storage platforms. On average, HP 3PAR storage customers achieved a 10.4 month payback period with a 55 % ROI over a 3-year evaluation period and a significant reduction in CapEx and OpEx over that same period as a result of thin provisioning, maintenance costs avoided and labor productivity gains.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

See more White Papers | Webcasts

Ask a question

Ask a Question