企業面臨激烈的市場競爭,以及快速變化的商業環境,必須運用IT 支援企業營運與管理,以強化競爭優勢。企業對於IT的投資愈來愈大,其應用更加複雜,管理難度也相對提高,因此必須建構完善的IT治理機制。一個有效的IT治理機制,能夠幫助企業快速因應市場變化,提高管理效率,改進業務流程,強化客戶關係,以資訊科技提供企業發展的創新應用。IT能直接影響企業競爭力,以及企業經營績效,IT治理成為公司治理中一個非常重要的領域,完善的IT治理機制,可使企業有效運用IT資源,以得到最大效益。 本研究架構以COBIT四個IT流程為執行主軸,融合金控IT治理實務運作經驗,並將三十四項作業程序,彙總歸納為十七項關鍵程序,嘗試以這關鍵程序執行成效,能夠對應連結於IT治理五大構面,以期達成金控IT治理目標。 本研究以A金控個案研究,驗證此研究架構之可行性,以及對個案研究之建議。在IT對企業之價值及權責歸屬方面,應明訂IT治理組織的角色與責任,建立權責一致的決策機制,才能迅速有效做出正確決定。IT建置前需有詳細之效益評估,針對不同的投資目的,擬定投資策略,讓IT成效最大化。在系統上線營運之後,仍應建立追蹤機制,以衡量其效益與建置前評估之差異,作為改善之依據,並可成為未來IT發展之經驗學習。在IT 績效衡量方面,以卓越營運、企業貢獻、顧客導向,以及未來導向四個構面來衡量,將IT策略展現為可評價的目標和實際行動,增加IT價值呈現IT績效。在資訊安全方面可導入資安國際標準規範,建構適宜的資訊安全體系。制定IT架構標準,掌握核心技術能力,強化系統擴展能力。尤其在國際化的業務擴展策略,更須有一套標準,包含系統架構與管理程序,能夠整合資源,快速建置並能有效管理。積極培育IT人才,瞭解業務和客戶清楚企業策略,具備戰略思維運用IT驅動新的業務模式。
Nowadays, companies are facing a rather harsh competition and faster changing business environment. So company runners must find ways to better utilize their IT functions to support their business running and management, and hence strengthen their competition advantages. Companies are spending more and more on their IT investment, so their IT structures are getting more and more complicated, and it becomes harder and harder to manage them. And hence building a proper IT governance framework for a company becomes a must. An effective IT governance strategy could help a company to promptly respond to market changes, enhance management effectiveness, improve business processes, strengthen customer relationship, and provide IT innovation applications to business development. IT can directly affect business competency and revenue, so IT governance becomes an important topic when talking about running a successful business. A mature IT governance strategy can help a company to make use of its IT resources efficiently, and therefore gaining the greatest benefits from them. The structure of this paper is based on COBIT’s four main IT processes, combining IT operation practices from a financial holding company. It also merges 34 operation steps into 17 key procedures, and tries to achieve the goal of IT governance within a financial holding company by connecting these key procedures with 5 structural attributes in IT governance. This paper tries to demonstrate the feasibility of the said governance framework based on the case study of Financial Holding Company A. In the aspects of IT’s roles and responsibilities and its value related to an enterprise, it also suggests that in order for a company to respond fast and correctly, the roles and responsibilities within the IT governance structure plus an efficient decision making channel must first be defined and established. There should be a thoroughly cost-effective analysis before an IT system is built. This analysis shall draw up the investment plan based on the original investment purpose and hence making the IT resources most efficient. Besides, an examination mechanism should be put in place after the system is established to evaluate the difference between its expected and real value, hence becomes the foundation for improvement and IT development experience for future use. In the aspect of IT performance assessment, all four dimensions of excellence in operation, contribution to the company, customer orientation, and future perspective should be included. So the IT strategy can now be evaluated by quantifiable targets and actions. By using this method, it also increases the value and displays the performance of IT department. In the aspect of information security, there are some well recognized international information security standards which could be introduced to build up a suitable information security management system. Setting up the standard of IT structure, controlling the core skills, and increasing the system scalability. A standard, which includes system framework and management procedures, is especially critical when a company is expending its business internationally. This kind of standard can consolidate resources, quickly build up systems, and then manage them efficiently. Actively raising the skills of IT personnel; understanding your company's business, customers, and strategy; approaching issues with strategic thinking and driving new business models with IT resources.