First and foremost, it is essential to analyze the risks and how they are managed. How robust is the organization's IT RISK MANAGEMENT? Does management have a risk evaluationmodel in place? Are risks periodically assessed, and how swiftly can security threats be addressed and acted upon?
Additionally, we assess the overall management of the IT architecture to determine how IT GOVERNANCE is structured. What does the management control model look like, and what approach is taken to asset management? Besides standard legislation, are there specific compliance issues to consider, and is there sufficient awareness within the organization? Are the risks and responsibilities with third parties transparent? What agreements have been made with providers (SLAs)? How does the organization test and audit the IT architecture, and how frequently?
An important part of the assessment revolves around how the existing IT solutions contribute to the organizational strategy. In the BUSINESS LEADERSHIP section, we assess the relevance of IT for current and future objectives, and how budgets can be optimally allocated towards IT maturity and IT, cloud, and network security. This includes identifying the essential KPIs for performance monitoring.