Friday, October 19, 2012

Manage and Improve Your Business Relationships


Manage and Improve your Business Relationships

By John Kyriazoglou*

Managing your professional and business relationships is a very important and critical issue in dealing with your people (staff, partners, customers, authorities, colleagues, etc.) in any business environment. It takes a significant amount of time to build and can be broken in just an instant.

Is it possible to manage, improve and sustain your business relationships?
The answer is YES! But you have to ACT immediately.
Don’t let one or more mistakes in judgment turn into a failure of your character.


I would suggest that you take the actions and that you use the behavioral dimensions noted next:


1. Sensitivity. Show sensitivity by avoiding personal comments and do not criticize, condemn or complain to anyone.

2. Collaboration. Make your goal the habit to work together harmoniously, show patience and maintain good relationships with everyone (colleagues, supervisors, senior management, customers, authorities, etc.).

3. Honesty. Be interested in others (colleagues, supervisors, senior management, customers, etc.) with sincerity, always showing friendship, goodness and love to all.

4. Respect. Remember that it is the sweetest sound in any language when you address the other person with friendship and love.

5. Politeness. Address the other person always in plural terms, unless the other person allows you to speak in the singular.

6. Silence. Use silence appropriately. Be careful how long you talk so that you do not become wordy and boring.

7. Importance. Make the other person feel important to you, and you do that with sincerity.

8. Opinion. Show respect for the opinion of others and do not to tell them that they are wrong.

9. Errors. When you are in error, accept it quickly and emphatically and apologize with honesty.

10. Conversation. Start a conversation in a friendly and pleasant manner.

11. Sympathy. Express your sympathy to the other person.

12. Humor. Keep your humor within acceptable social boundaries while rejecting slander and vulgarities.
13. Appreciation. Relate to the other person by using praise, appreciation and honesty.

14. Time Management. Examine your activities in accordance with the values ​​of love and friendship, and your obligations. Spend 60% of your time in critical non-emergency activities, 30% of your time in critical and emergency activities, and the remaining 10% of your time in uninteresting activities.

15. Rejection. Learn to say a friendly "no" when others attempt to load you with activities that are not aligned with your needs, your vision, your mission and your values​​.

16. Positive Thinking. Use positive and friendly thinking to manage all the events, issues, problems and facts related to your business life and take preventive action when it is required on your part.

17. Priority. Perform your activities based on the priorities set by you and the time requirements of your life, but also reinforcing the values ​​of justice, goodness, fairness, love and friendship.

18. Participation. Participate in social groups, professional societies and corporate volunteering (unpaid) activities on the basis of love and friendship.

19. Ethics. Understand and know your personal limits and the limits of your business organization.

20. Quality. Do not take on more responsibility and tasks that you can do with absolute quality and execute your tasks and deliver your work, studies, services, etc., within well-accepted time and cost limits and best quality, technical and scientific standards.

 
Will these improve your relationships? Yes, if you act with honesty, love, friendship and self-control.

 

*John Kyriazoglou (jkyriazoglou@hotmail.com)

John Kyriazoglou, CICA, B.A (Hon-University of Toronto),

International IT and Management Consultant (with over 35 years of experience),

Editor-in-Chief for the Internal Controls Magazine, www.theiic.org

Author of several books:

(1) ‘IT Strategic and Operational Controls’, Publisher: www.itgovernance.co.uk


(2) ‘Addendum to IT Strategic & Operational Controls’

This book contains over 60 of IT audit programs and checklists in all IT audit areas.

Direct Link: www.itgovernance.co.uk/products/3143

(3) ‘Corporate Strategic and Operational Controls’, Publisher: www.theiic.org

with Dr. F. Nasuti and Dr. C. Kyriazoglou.


(4) ‘Implementing Management Controls for Small and Medium-Size Companies   

AMAZON Kindle Books:www.amazon.com


(5) ‘Business Management Controls: A Guide’, Publisher: www.itgovernance.co.uk

Expected to be published within 2012

(6) ‘Pearls of Wisdom of the 7 Sages of Ancient Greece

AMAZON Kindle Books:www.amazon.com




SSRN Free Publications: http://ssrn.com/author=1315434

Wednesday, October 3, 2012

Business Management Free Material


Business Management Free Materials

 

Please check out my blog and the SSRN site (noted next) for my free posts and articles on business management.


SSRN Free Publications: http://ssrn.com/author=1315434


Regards,

John Kyriazoglou, CICA, B.A (Hon-University of Toronto),

Business Thinker, Consultant and Author

Editor-in-Chief for the Internal Controls Magazine (U.S.A.),

Member of the Board of Directors of Voices of Hellenism Literary Society (U.S.A.)




Monday, October 1, 2012

Human Factors in EA Implementation


Human Factors in EA Implementation


 

By John Kyriazoglou

 

Enterprise Architecture (EA) is used to align IT systems with your business strategy and objectives (for more details see my book: E-Book: ‘How to Align IT with your Business’, Direct Link: http://www.amazon.com/dp/B009E6U8Z8). It has proven a very difficult and cumbersome process.

 

My experience has taught me that when implementing enterprise architecture for your own company and business environment the most important issue for success is to manage the human aspects (so called ‘soft controls’) permeating any such difficult and cumbersome effort.

 

All of these soft controls relate to tone at the top, understanding of the organization by the board, culture, structure of reporting relationships, morale, integrity and ethical values, operational philosophy, trust, ethical climate, empowerment, etc., and are directly linked to the emotional contracting issue, also referred to as 'the psychological contract'. This is the crucial and powerful link between the organizational performance intent (board and management planning to implement enterprise architecture), and the motivations, values and aspirations of the people (EA coordinator, enterprise architect, IT staff, etc.) instructed to carry out all implementation tasks.

This emotional contracting element is sometimes overlooked by organizations, board members and managers, and that is the reason that may explain why the people have failed to do what the organization expected and asked them to do.

Soft internal controls (trust, integrity, values and beliefs, etc.) should be part of the organizational process of strategy setting and ethical environment establishment. Corporate policies and procedures, vision and mission statements, strategic planning, ethics codes, job descriptions, training and coaching of staff, compliance programs, etc., are the tools and the hard controls that help define whether an organization consistently will do (supposedly ) the right thing.

An organization (private or public) might have written codes of conduct and other value defining type documents (vision, mission, values, social responsibility, etc.) but that does not guarantee whether they are actually followed consistently. Most of the real understanding will not be expressly written in any document but better evidenced in the day-to-day discharge of everyday duties and interactions. For example, the ethical culture can only rise as high as the tone set by the board and the senior executive management. If management distributes the message about ethics poorly or worst yet, delegates the message to subordinate levels, then the effectiveness of the ethical culture is greatly diminished.

The best way to reinforce soft controls and therefore ensure better EA implementation for your business is to (probably) formalize them. I recommend this to be the task of a senior board member of your company. This can be accomplished by Soft Controls Management Action Plan, as described next.

Action 1. Establish and monitor the implementation of an ethics code and a fraud policy and associated procedures.

Action 2. Ensure that your EA process is well communicated to all parties within your company.

Action 3. Interview key organization personnel and select the best for the EA implementation project.

Action 4. Implement training, coaching and mentoring programs for all critical staff involved in your EA implementation.

Action 5. Certify critical personnel (finance, IT, audit, purchasing, etc.) to ensure success of your EA process.

Action 6. Certify, if needed, all your critical functions (finance, IT, audit, purchasing, quality, customer service, etc.) related to EA.

Action 7. Review and improve all soft controls and particularly pay attention to how these are related to your EA project and to the linking of your IT strategy to your business objectives.

 

It is your duty, as a board member or senior executive, to handle all these successfully and therefore avoid any potential failures.

 

 

 

Friday, September 21, 2012

IT-Business Alignment Book


BOOK: ‘How to Align IT with your Business’

 

Publication date: 21 Sept. 2012

Author: John Kyriazoglou


Summary description of the Book

 

This book deals with the issues of linking and aligning your IT application systems and services with your business goals to achieve your business objectives in a more effective and efficient way by the use of the Enterprise Architecture (EA) approach. Its contents describe four processes, several controls, activities, documents, checklists and procedures necessary for an effective EA implementation. Also seven recommendations are offered to streamline your EA efforts.

 

Detail Contents of the Book

 

The contents of this book are:

 

Chapter 1: Current Business Operating Environment

Description of the economic, social and technological factors and conditions (e.g., failure of corporate IT systems to be aligned and linked to the business objectives of the company.) affecting 21st century business organizations. Outline of the need for better business controls in all areas: governance, risk, strategy, IT, production, enterprise architecture (EA), etc.

 

Chapter 2: Business Controls and Enterprise Architecture

Description of the role of business controls making up a Business Control Framework to improve strategy and operations. Outline of the way enterprise architecture fits into this to satisfy your business needs and expectations in terms of IT systems and services.  

 

Chapter 3: Why is Enterprise Architecture (EA) important?

Description of the importance of EA (e.g., failure of strategic plans for various reasons, IT systems not linked to business strategy, etc.). How the EA approach resolves the ‘flexibility’ issue in business planning. Outline of the terms ‘enterprise’ and ‘architecture’.

 

 

Chapter 4: Definition and Processes of the EA Approach

Description of the role and purposes of the EA approach. Formal definitions of ‘Enterprise Architecture’.  Description of the main types of EA Processes (EA Management Plan, EA Resources, EA Components and EA Improvement) making up the EA approach.

 

Chapter 5: Process 1 - EA Management Plan

Description of the 12 steps (needs analysis, employing resources, selecting an EA framework, etc.), controls and end results (products created) in creating and executing the EA management plan (EA Process 1) for achieving EA and its benefits for your business. Listing out the products of this process: ‘EA Feasibility Study’, ‘EA policy’, ‘EA Communication Plan’, ‘EA Requirements Study’, ‘Business Model Changes’, ‘Enterprise Architecture Repository’, ‘EA Implementation Plan’, etc.

 

Chapter 6: Process 2 - EA Resources

Description of the role and responsibilities of the required corporate human resources (board, management, EA technical, IT, etc.) and the application of segregation of duties (EA Process 2) to implement EA for your company.

 

Chapter 7: Process 3 - EA Components

Description of the technical and procedural components (EA Process 3) which required for the effective establishment, implementation and administration of your EA: EA framework, business model, goals, EA repository, installation procedure, security procedure, etc. Also outline of various examples related to these components: Business process narrative, business strategic plan, strategy, goals and objectives, etc.

 

Chapter 8: Process 4 - EA Improvement

Description of an EA Improvement Plan and examples of performance measures, compliance indicators and EA checklists (Business Processes, Overall Corporate Business Data Management, Overall Corporate Business Strategy, etc.) which may be used to review and improve your EA processes, controls and components (EA Process 4).

 

Chapter 9: Benefits of Enterprise Architecture

Description of the benefits of the EA approach to your business organization, in terms of: Better alignment of your business strategy and business processes with your IT systems, better control of business data and faster and more seamless flow of information, more efficient control of your IT operation (systems, projects, data, etc.) fully supporting your business, etc.

 

Chapter 10: Concluding Remarks

Description of the latest data on how the enterprise architecture approach changes and improves the management and operation of IT systems to serve your business better. Also presentation of seven recommendations related to planning and implementing EA for your business in a more efficient and effective way.

 

Appendix 1: EA Case Study

Description of how enterprise architecture has been implemented to solve real-life business problems related to corporate operational and performance information issues and demands in IT-enabled company operations.

 

Appendix 2: EA Frameworks

Short description of the main standard-industry EA frameworks.

 

Further Resources

Listing of various books related to EA for anyone wanting to delve more into this subject.

Monday, September 10, 2012

Business Data Security Checklist


Business Data Security Checklist

 

John Kyriazoglou*

 

A business data security policy and related procedures should include protection controls and measures that cover the following issues:

1. Comprehensive due diligence of all critical staff, including external parties (outsourcing, external suppliers, sub-contractors, etc.). 

2. Authentication of all customers.

3. Non repudiation and accountability for all on-line transactions.

4. Segregation of duties.

5. Authorization controls.

6. Business data, transactions, records and information integrity.

7. Transactions audit trails.

8. Information confidentiality.

9. Appropriate disclosures for organizational services.

10. Data privacy.

11. Business continuity and contingency planning.

12. Security and other crises incident response planning.

13. Access controls: encryption, passwords, password control devices, tokens, user authentication devices, anti-hacking tools/techniques, digital signals origin identification, anti-tapping tools/techniques.

14. Data confidentiality.                             

15. Data integrity.

16. Anti-virus and e-crime detection software.

17. Time stamping.

18. Biometrics.

19. Digital signatures.

20. Smart cards.                            

 

 

John Kyriazoglou (jkyriazoglou@hotmail.com)

John Kyriazoglou, CICA, B.A (Hon-University of Toronto)

International IT and Management Consultant, author of several books



SSRN Free Publications: http://ssrn.com/author=1315434

 

 

Sunday, August 5, 2012

Audit Committee Practices


AUDIT COMMITTEE PRACTICES

By John Kyriazoglou


There are several discussions in various professional forums about ‘good’, ‘bad’ or ‘ugly’ practices related to audit committee activities. These terms are not defined at all, so far.

 I think the terms ‘Good’, ‘Bad’, and ‘Ugly’ practices need to be defined and/or specified explicitly, in terms of effectiveness (results-oriented), efficiency (resource-oriented) and morality (according to corporate ethics code, compliance regulations and societal benefits).

 Also these practices should be established in accordance to the pre-defined audit committee’s vision and strategy, which should be aligned and linked to the corporate vision, mission, values, and performance targets.

 And this to avoid a ‘vacuum’ or ‘looking glass’ situation whereby the audit committee is quite off the corporate agenda. 

 Furthermore these practices should relate to the audit committee acting in an oversight and guidance role in respect to various standard-practice ‘red flag’ issues, in order to avoid or protect the company better against fraud and mismanagement.

These ‘red flag’ issues are based on my auditing and consulting experience and on discussions and communications with other consultants, auditors, fraud examiners, accountants, and other professionals.



Issue 1. Policies and Procedures: Inadequate design, development, implementation, annual review and improvement of corporate policies and procedures.  

Issue 2. Board and Management Roles: Ineffective oversight exercised by the board and insufficient discharge of duties and responsibilities by all senior levels of management.

Issue 3. Auditing: Audit (internal and external) findings not acted upon within the time-frame agreed or forgotten all together.

Issue 4. Fines and Legal Breaches: Fines imposed by regulators and government authorities on compliance, tax, customs, accounting, performance results, data privacy, environmental, worker safety and health issues, etc., as well as penal and civic code litigations, breaches, etc.

Issue 5. Training of Staff: Inadequate or ineffective supervision of staff activities by management, including guiding, coaching and training, discussing issues and problems, etc.

Issue 6. Personnel Supervision: Inadequate or ineffective execution of personnel administration controls, including segregation of duties, authorizations and approvals, rotation of duties, hiring and dismissal of personnel, due diligence of all staff, vacation taking, etc.

Issue 7. Personnel Adequacy: Inadequate skills, dexterities, knowledge and experience including professional certifications, for all board members, managers, and critical staff (accountants, auditors, IT resources, etc.).

Issue 8. Corporate Performance: Very high or very low achievement of strategic and operational objectives as evidenced by financial and non-financial performance reports and results.

Issue 9. Morale: Very high or very low morale of board, management and employees.

Issue 10. Turn-over: Very high or very low turn-over of board, management and employees.

Issue 11. Accuracy of Data: Inaccurate data, unsupported or unauthorized transactions, discrepancies and large number of errors in business records, including accounting records, purchase orders, transactions, balances, files, bank accounts, etc.

Issue 12. Conflicts of Interest: Too close relationship with customers, vendors, competitors, regulators and other parties involved in the activities of the organization.



Is this list relevant to you? It is hard to say on an absolute basis. You have to consider these in relation to your operating environment and how you want to implement business management controls to manage these ‘red flag’ issues before disaster strikes you.



Your ‘Good’ practices that are required to get the job of the audit committee done better, and the ‘Bad’ or ‘Ugly’ practices to be avoided need rethinking.



The whole picture would rather be better when you specify your practices, in terms of a purpose-driven approach that incorporates effectiveness (results-oriented), efficiency (resource-oriented) and morality (according to corporate ethics code, compliance regulations and societal benefits).


Thursday, July 12, 2012

ENTERPRISE ARCHITECTURE FRAMEWORKS


ENTERPRISE ARCHITECTURE FRAMEWORKS



John Kyriazoglou*



The most common industry-standard EA Frameworks briefly presented next are: The Zachman Framework, The Open Group Architecture Framework (TOGAF), Enterprise Architecture Body of Knowledge (EABOK), Generalized Enterprise Reference Architecture and Methodology (GERAM), Reference Model of Open Distributed Processing (RM-ODP), The CIMOSA Framework, The Federal Enterprise Architecture (FEA) Framework, Other Government Enterprise Architecture Frameworks, ITIL Enterprise Architecture Framework and Microsoft Enterprise Architecture Framework.



The Zachman Framework

This framework provides a formal and well-structured way of viewing and defining an enterprise on the basis of a two dimensional classification matrix. Each row represents a type of stakeholder, these being: contextual, conceptual, logical, physical, and detailed. Each column denotes the aspects of the architecture, such as: ‘Why’ (represents the motivation), ‘How’ (denotes the functional description), ‘What’ (represents the data description), ‘Who’ (represents the people), ‘Where’ (denotes the network), and ‘When’ (defines the time).

The resulting matrix is a template that must be filled in by the goals, rules, processes, material, roles, locations and events specifically required by the organization.

The Open Group Architecture Framework (TOGAF)

This framework provides a comprehensive approach to the design, implementation, and governance of an enterprise information architecture at four levels or domains: Business Domain (business strategy, governance, organization,, and key business processes), Applications Domain (blueprints for the individual application systems to be deployed and their interactions), Data Domain (logical and physical data assets), and Technology Domain (hardware, software, and network facilities required to support the deployment of core and mission-critical applications).

Enterprise Architecture Body of Knowledge (EABOK)

This is a guide to enterprise architecture produced by MIT. It treats enterprise architecture as not including merely diagrams and technical descriptions, but gives a holistic view that includes U.S. legislative requirements and guidance, as well as giving technologists a better understanding of business needs on the basis of the value chain concept of Professor Porter.

Generalized Enterprise Reference Architecture and Methodology (GERAM)

This is a generalized enterprise architecture framework for enterprise integration and business process engineering. It defines the enterprise related generic concepts recommended for use in enterprise integration projects. These concepts include: a life cycle approach in identifying the life-cycle phases for any enterprise (from entity conception to its final end), enterprise entity types and enterprise modelling with business process modelling, integrated model representation in different model views, and modelling languages for different users, such as business users, system designers, IT modelling specialists, etc. 

Reference Model of Open Distributed Processing (RM-ODP)

This framework supports distribution, inter-working, platform and technology independence, and portability, together with an enterprise architecture framework for the specification of open distributed processing systems. It provides five generic and complementary viewpoints on the system and its environment: enterprise viewpoint, information viewpoint, engineering viewpoint, computational viewpoint, and technology viewpoint.

The CIMOSA Framework

CIMOSA is a well known framework which supports all phases of the CIM (Computer Integrated Manufacturing) system life-cycle from requirements definition, through design specification, implementation description and execution of the daily enterprise operation.

CIMOSA incorporates an event-driven, process-based modelling approach with the goal to cover essential enterprise aspects in one integrated model. The main aspects are the functional, behavioural, resource, information and organizational aspect.

Federal Enterprise Architecture (FEA) Framework



The FEA framework is a U.S. Government standard which is used to facilitate shared development of common processes and information among U.S. Federal agencies and other government agencies. On the basis of this framework, a given architecture can be partitioned into four layers, as depicted next.



Layer 1: Business Architecture. Represents the business functions of the organization and the information it uses.

Layer 2: Data Architecture. Defines how data are stored, managed and used in a system.

Layer 3: Application Architecture. Consists of the logical systems that manage the data in the data architecture and support the business architecture.

Layer 4: Technology Architecture. Describes current and future infrastructure (hardware and software) that support the application systems in the application architecture.



Other Government Enterprise Architecture Frameworks

There is a set of various other government sponsored enterprise architecture frameworks, such as the ones listed below, which are beyond the scope of this paper. These are: (a) Department of Defense (U.S.) Architecture, (b) NIST (U.S.) Enterprise Architecture Model, (c) British Ministry of Defense Architectural Framework (d) The NATO Architecture Framework and (e) Government Enterprise (Australia, Queensland) Architecture.



ITIL Enterprise Architecture Framework

This framework is based on the Information Technology Infrastructure Library (ITIL) which contains a set of concepts and policies for managing Information Technology (IT) infrastructure, development and operations. ITIL includes five core components: Service Strategy, Service Design, Service Transition, Service Operation, and Continual Service Improvement.

Service Strategy: Service strategy encompasses a framework to build best practice in developing a long term service strategy. It covers many topics including: general strategy, competition and market space, service provider types, service management as a strategic asset, organization design and development, etc.

Service Design: The design of IT services includes design of architecture, processes, policies, documentation, capacity management, IT service continuity, Information Security, supplier management, key roles and responsibilities of staff and future business requirements, etc.

Service Transition: Service transition covers topics such as: Service Asset and Configuration Management, Transition Planning and Support, Release and deployment management, Change Management, etc.

Service Operation: Service Operations include monitoring of problems and balance between service reliability and cost, balancing conflicting goals, Event management, incident management, problem management, etc.

Continual Service Improvement (CSI): The goal of Continual Service Improvement is to align and realign IT Services to changing business needs by identifying and implementing improvements to the IT services that support the Business Processes.

Microsoft Enterprise Architecture Framework



This EA framework

is based on the IT Service Lifecycle approach of 4 phases:




(1) The Plan Phase. The activities of this phase ensure that your IT services are planned effectively so that they are implemented successfully.

(2) The Deliver Phase. The activities of this phase ensure that your IT services are developed effectively, are deployed successfully, and are ready for Operations.

(3) The Operate Phase. The activities of this phase ensure that your IT services are operated, maintained, and supported in a way that meets your business needs and expectations.

(4) The Manage Layer. The activities (IT governance, risk, compliance, roles and responsibilities, change management, configuration, etc.) of this phase provide operating principles and best practices to ensure that your IT investments deliver expected business value at an acceptable level of risk.





*Author’s Credentials

John Kyriazoglou, CICA, B.A(Hon-University of Tororonto), is an International IT and Management Consultant, author of the book ‘IT STRATEGIC & OPERATIONAL CONTROLS’ (published in 2010 by www.itgovernance.co.uk), and co-author of the book CORPORATE CONTROLS’, (published in 2012 by www.theiic.org), with Dr. F. Nasuti and Dr. C. Kyriazoglou).