Communicate Management Aims and Direction

Communicate Management Aims and Direction

Management develops an enterprise IT control framework and defines and communicates policies. An ongoing communication program is implemented to articulate the mission, service objectives, policies and procedures, etc., approved and supported by management. The communication supports achievement of IT objectives and ensures awareness and understanding of business and IT risks, objectives and direction. The process ensures compliance with relevant laws and regulations.

IT Policy and Control Environment

IT Policy and Control Environment

Define the elements of a control environment for IT, aligned with the enterprise’s management philosophy and operating style. These elements should include expectations/requirements regarding delivery of value from IT investments, appetite for risk, integrity, ethical values, staff competence, accountability and responsibility. The control environment should be based on a culture that supports value delivery whilemanaging significant risks, encourages cross-divisional co-operation and teamwork, promotes compliance and continuous process improvement, and handles process deviations (including failure) well.

There are no PSGs published for this topic; however, the topic is under review for future PSGs.