IT °Å¹ö³Í½º, ÅëÁ¦, º¸¾È ±×¸®°í º¸Áõ ¾÷°èÀÇ ±Û·Î¹ú ¸®´õ
 
 
HOME > Ä¿¹Â´ÏƼ > ¼­Æò & ¹ø¿ª¹°
  IT °Å¹ö³Í½º¿¡¼­ Àü»ç IT °Å¹ö³Í½º·Î À̵¿ By Steven De Haes, Ph.D. and Wim Van Grembergen, Ph.D.
  ±Û¾´ÀÌ : ½ÅÀÎö     ³¯Â¥ : 09-06-03 11:55     Á¶È¸ : 3058     Ãßõ : 18     Æ®·¢¹é ÁÖ¼Ò

IT °Å¹ö³Í½º¿¡¼­ Àü»ç IT °Å¹ö³Í½º·Î À̵¿

 

Moving From IT Governance to Enterprise Governance of IT

 

By Steven De Haes, Ph.D. and Wim Van Grembergen, Ph.D.
ISACA Journal Volume 3, 2009

 

IT °Å¹ö³Í½º´Â °©ÀÛ½º·´°Ô ³ªÅ¸³ª Á¤º¸±â¼úÀÇ Áß¿äÇÑ À̽´°¡ µÈ °³³äÀÌ´Ù. ±× °³³äÀÌ Åº»ýÇÑ ½Ã±â´Â ºÐ¸íÇÏÁö ¾Ê´Ù. ¡°IT °Å¹ö³Í½º °³¼±Çϱ⡱´Â 2003³â¿¡ óÀ½À¸·Î °¡Æ®³ÊÀÇ »óÀ§ 10°³ CIO °ü¸® ¿ì¼±¼øÀ§¿¡ Æ÷ÇԵǾúÀ¸¸ç, 3À§¸¦ Â÷ÁöÇÏ¿´´Ù. 1998³â¿¡´Â IT °Å¹ö³Í½º °³³äÀ» ³Î¸® º¸±ÞÇϱâ À§ÇÏ¿© IT °Å¹ö³Í½º Çùȸ(ITGI)°¡ ¼³¸³µÇ¾ú´Ù. ÇÐ°è ¹× Àü¹® ¹®Çå¿¡ À־´Â Á¦¸ñ ¼Ó¿¡ IT °Å¹ö³Í½º¸¦ ¾ð±ÞÇÑ ³í¹®µéÀÌ 1990³â´ë ÈĹݺÎÅÍ ³ªÅ¸³ª±â ½ÃÀÛÇß´Ù. °¡Æ®³Ê¿¡¼­´Â 2003³â 3À§¿¡ ·©Å©µÈ »óÀ§ 10°³ CIO °ü¸® ¿ì¼±¼øÀ§¿¡¼­ óÀ½À¸·Î IT °Å¹ö³Í½º¸¦ °³¼±Çϱâ À§ÇÑ ¾ÆÀ̵ð¾î¸¦ ¼Ò°³ÇÏ¿´´Ù.

 

IT °Å¹ö³Í½º °³³äÀÇ ÃâÇö ÀÌÈÄ¿¡, ÀÌ °³³äÀº ¸¹Àº ÁÖ¸ñÀ» ¹Þ¾Ò´Ù. ±×·¯³ª, À̸§¿¡ µé¾îÀÖ´Â ¡°IT¡±¿¡ °üÇÑ ÁýÁßÀûÀÎ °ü½É ´öºÐ¿¡, IT °Å¹ö³Í½º Åä·ÐÀÌ ÁÖ·Î IT ³»¿¡¼­¸¸ ¸Ó¹°·¯ ÀÖ¾ú´Ù. IT ºÐ¾ß¿¡¼­, ¸¹Àº IT °Å¹ö³Í½º ±¸ÇöÀÌ IT Á¶Á÷¿¡ ÀÇÇØ ÃßÁøµÇ¾úÀ¸³ª, »ç¶÷µéÀº ºñÁî´Ï½º Á¶Á÷¿¡¼­ ÁÖµµÀû ¿ªÇÒÀ» ÇØÁֱ⸦ ±â´ëÇÏ¿´´Ù. IT ÅõÀڷκÎÅÍÀÇ ºñÁî´Ï½º °¡Ä¡´Â IT¿¡ ÀÇÇؼ­´Â ½ÇÇöµÇ¾îÁú ¼ö ¾ø°í, ±×°ÍÀº ¾ðÁ¦³ª ºñÁî´Ï½º Ãø¸é¿¡¼­ âÃâµÈ´Ù´Â Á¡Àº ºÐ¸íÇÑ »ç½ÇÀÌ´Ù. ¿¹¸¦ µé¾î, IT°¡ »õ·Î¿î °í°´°ü°è°ü¸®(CRM) ¾ÖÇø®ÄÉÀ̼ÇÀ» Àû±â¿¡, ¿¹»ê ¹üÀ§ ³»¿¡¼­ ±×¸®°í ±â´É¼ºÀ» °®Ãç Àü´ÞÇÏ´õ¶óµµ, ±× ÀÌÈÄ¿¡ ºñÁî´Ï½º°¡ »õ·Î¿î IT ½Ã½ºÅÛÀ» ºñÁî´Ï½º ¿î¿µ¿¡ ÅëÇÕ½ÃÅ°Áö ¾Ê´Â´Ù¸é ºñÁî´Ï½º °¡Ä¡´Â ÀüÇô âÃâµÇÁö ¾ÊÀ» °ÍÀÌ´Ù. ȸ»çÀÇ ¿µ¾÷ ºÎ¼­°¡ ¸ÅÃâ°ú ÀÌÀÍÀ» Áõ´ëÇÒ ¼ö ÀÖµµ·Ï »õ·Ó°í ÀûÇÕÇÑ ºñÁî´Ï½º ÇÁ·Î¼¼½ºµéÀ» ¼³°èÇÏ¿© ½ÇÇàÇÒ ¶§¿¡ ºñÁî´Ï½º °¡Ä¡´Â âÃâµÉ °ÍÀÌ´Ù.

 

ºñÁî´Ï½ºÀÇ Âü¿©°¡ ÇÊ¿¬ÀûÀÏ ¼ö¹Û¿¡ ¾ø´Â °¡Ä¡ ½ÇÇöÀº ±×°ÍÀ» Á¤ÀÇÇϴµ¥ À־ Àü»çÀû IT °Å¹ö³Í½º(enterprise governance of IT)·ÎÀÇ À̵¿À» Ã˹߽ÃÄ×´Ù. Àü»çÀû IT °Å¹ö³Í½º´Â ±â¾÷ °Å¹ö³Í½º(corporate governance)ÀÇ ÇʼöÀûÀÎ ±¸¼º¿ä¼ÒÀ̸ç, ¶ÇÇÑ ±×°ÍÀº ºñÁî´Ï½º/IT ¿¬°è¿Í IT-È°¼º ÅõÀڷκÎÅÍ ºñÁî´Ï½º °¡Ä¡ âÃâ¿¡ µ¿Á¶ÇÏ¿© ºñÁî´Ï½º ¹× IT Àη ¸ðµÎ ÀڽŵéÀÇ Ã¥ÀÓÀ» ÀÌÇàÇÒ ¼ö ÀÖ°Ô ÇÏ´Â Á¶Á÷ÀÇ ÇÁ·Î¼¼½º, ±¸Á¶ ±×¸®°í °ü·Ã ¸ÞÄ¿´ÏÁòµéÀÇ Á¤ÀÇ¿Í ±¸Çö¿¡ ÃÊÁ¡À» ¸ÂÃá´Ù.©ö Àü»çÀû IT °Å¹ö³Í½º´Â ºÐ¸í IT-°ü·Ã Ã¥ÀÓÀ» ³Ñ¾î¼­ ºñÁî´Ï½º °¡Ä¡ âÃâÀ» À§ÇØ ÇÊ¿äÇÑ IT-°ü·Ã ºñÁî´Ï½º ÇÁ·Î¼¼½ºµé·Î È®´ëµÈ´Ù. ´õ±¸³ª, ±¹Á¦Ç¥Áرⱸ(ISO)µµ ±â¾÷ IT °Å¹ö³Í½º(¡°Corporate Governance of IT¡±)·Î Á¤ÀÇÇÑ ±¹Á¦ Ç¥ÁØÀÇ 2008³â ¹ßÇ๰(ISO/IEC 38500:2008)¿¡¼­ ±×¿Í °°Àº ¹æÇâ¿¡¼­ Á¢±ÙÇÏ¿´´Ù. ±× Ç¥ÁØ¿¡¼­, ISO´Â ºñÁî´Ï½º¿Í ITÀÇ ¿ªÇÒ ¹× Ã¥ÀÓÀ» ¾ð±ÞÇϸ鼭 IT-°ü·Ã ÀÇ»ç°áÁ¤¿¡ ´ëÇÑ °¡À̵带 À§ÇÑ ¿ì¼±Àû ÇൿÀ» Ç¥ÇöÇÑ IT °Å¹ö³Í½º¸¦ À§ÇÑ 6°¡Áö ¿øÄ¢À» Á¦½ÃÇÏ°í ÀÖ´Ù.

 

¸íĪ°ú ÃÊÁ¡¿¡ À־ÀÇ ÀÌ·¯ÇÑ º¯È­´Â ¹Ì¹ÌÇÏ¸ç ±×¸®°í ȹ±âÀûÀÌÁö ¾ÊÀº °ÍÀ¸·Î º¸ÀÏ ¼ö ÀÖÁö¸¸, Çö¾÷ »ç¶÷µéÀÇ ¸¶À½ ¼Ó¿¡´Â Áß´ëÇÑ º¯È­¸¦ °¡Á® ¿Ô´Ù. IT °Å¹ö³Í½º¿¡ À־ ITÀÇ ÁÖµµÀû ¿ªÇÒÀº Ç×»ó ¸ð¼øµÈ´Ù. ºñÁî´Ï½º ÇÁ·Î¼¼½ºµé°ú ºñÁî´Ï½º °¡Ä¡ âÃâÀº ºÐ¸í ºñÁî´Ï½º »ç¶÷µéÀÇ ¼öÁß¿¡ ÀÖÀ¸¸ç ¶ÇÇÑ ÀÖ¾î¾ß¸¸ ÇÏ´Â °ÍÀÌ´Ù. ÇÑÆí, »ç¶÷µéÀº ±×·¯ÇÑ ¸¶À½ÀÇ º¯È­°¡ ÀúÀý·Î ȤÀº ±× °³³ä¿¡ ´ëÇÑ ¸íĪ¸¸À» ¹Ù²Û´Ù°í ÀϾÁö ¾ÊÀ¸¸®¶ó´Â °ÍÀ» ½ÇÁúÀûÀ¸·Î ±ú´Þ¾Æ¾ß¸¸ ÇÑ´Ù. IT °æ¿µÀڴ ȸ»ç¿¡¼­ º¯È­ÀÇ Áß°³ÀÎÀ¸·Î È°µ¿ÇÏ°í ½Ã°£ÀÌ Áö³²¿¡ µû¶ó¼­ ¿µ¾÷ ¸ÅÃâ(business buy-in)À» Çâ»ó½ÃÅ°´Â À¯ÀÏÇÑ À§Ä¡¿¡ ÀÖ´Ù. ±×·± Á¡À» ±ú´Ý°Ô Çϱâ À§Çؼ­, ITGIÀÇ ÁÖ¿ä ÇÁ·¹ÀÓ¿öÅ©µéÀº, CobiT ¹× Val IT, °­·ÂÇÑ Ã˸ÅÁ¦·Î ÀÛ¿ëÇÒ ¼ö ÀÖ´Ù. CobiTÀº IT °ü·Ã ¼öÇàÃ¥ÀÓ¿¡ ÃÊÁ¡ÀÌ ¸ÂÃçÁ® ÀÖÀ¸¸ç Val IT´Â ºñÁî´Ï½º °ü·Ã Ã¥ÀÓ¿¡ ÃÊÁ¡ÀÌ ¸ÂÃçÁ® ÀÖ´Ù. Çö¾÷ »ç¶÷µéÀÌ ÀÌ·¯ÇÑ ÇÁ·¹ÀÓ¿öÅ©¸¦ ÀÚ±âµé ÈûÀ¸·Î ½±°Ô µµÀÔÇÒ °ÍÀ̶ó ÃßÃøÇÏ´Â °ÍÀº Çö½Ç¼ºÀÌ ¾ø´Ù. ±×·¸±â¿¡, ÀÌ ÇÁ·¹ÀÓ¿öÅ©µéÀº Çö¾÷°úÀÇ º¸´Ù ³ªÀº ¼ÒÅëÀ» ÇÏ°í ÇÊ¿äÇÑ Çö¾÷ Âü¿©¸¦ ÀÚ±ØÇϱâ À§Çؼ­ ÇÊ¿äÇÑ °³³ä°ú Á¢±Ù¹æ¹ýÀ» Áö´Ñ IT °íÀ§ °æ¿µÀÚ¿¡°Ô Á¦°øÇÑ´Ù. ÀÌ·± Àǹ̿¡¼­, CobiT°ú Val IT´Â IT Ä¿¹Â´ÏƼ°¡ IT °Å¹ö³Í½º·ÎºÎÅÍ Àü»ç IT °Å¹ö³Í½º·Î À̵¿Çϴµ¥ È°¿ëÇÒ ¼ö ÀÖ´Â ¼ö´ÜÀÌ´Ù.

 

¿ªÀÚÁÖ) ÀÌ ±Û¿¡¼­ »ç¿ëµÈ ¡°IT °Å¹ö³Í½º¡±´Â ¡°IT ¼­ºñ½º °Å¹ö³Í½º¡±·Î °£ÁÖÇÏ´Â °ÍÀÌ ´Ù¸¥ ±Ûµé°úÀÇ ¿ÀÇظ¦ ¾ø¾Ù ¼ö ÀÖ´Ù°í »ý°¢ÇÕ´Ï´Ù. Áö±Ý±îÁö ºñÁî´Ï½º °üÁ¡¿¡¼­ IT °Å¹ö³Í½º¸¦ ÀνÄÇÑ »ç¶÷µéÀº IT Áß½ÉÀÇ IT °Å¹ö³Í½º¸¦ ¡°low level IT °Å¹ö³Í½º¡±·Î ºÎ¸£°í, »ó´ëÀûÀ¸·Î Àü»ç IT °Å¹ö³Í½º¿Í ¼­·Î ÅëÇÏ´Â IT °Å¹ö³Í½ºÀÇ À̸§À» ¡°high level IT governance¡± ¡°proper IT governance¡±·Î Â÷º°ÇÏ¿© »ç¿ëÇϱ⵵ ÇÕ´Ï´Ù.

 

±×¸®°í ÀÌ Ä¿¹Â´ÏƼ¿¡ ½Ç¸° ÀúÀÇ ¸ðµç ±Û ¼Ó¿¡ Ç¥ÇöµÈ IT °Å¹ö³Í½º´Â Àü»ç IT °Å¹ö³Í½º °üÁ¡¿¡¼­ ¾´ °ÍÀÓÀ» ¹àÇôµå¸³´Ï´Ù.

 

Endnote

1 Van Grembergen, Wim; Steven De Haes;

Enterprise Governance of IT: Achieving Strategic Alignment and Value, Springer, 2009

 

Steven De Haes, Ph.D., is responsible for the information systems management executive programs and research at the University of Antwerp Management School (Belgium) and is a guest lecturer on information systems management at the University of Antwerp. He is managing director of the Information Technology and Alignment (ITAG) Research Institute. He has been involved in research and development activities of CobiT, Val IT and Risk IT. He can be contacted at steven.dehaes@ua.ac.be.

 

Wim Van Grembergen, Ph.D., is a professor in the economics and management faculty of the University of Antwerp (Belgium) and executive professor at the University of Antwerp Management School. He is academic director of the Information Technology and Alignment (ITAG) Research Institute and has conducted research in the areas of IT governance, IT audit and IT performance management. He has been involved in research and development activities for ISACA and ITGI, and is a member of ISACA¡¯s IT Governance Committee. He can be contacted at wim.vangrembergen@ua.ac.be .

 


ISACA Journal, formerly Information Systems Control Journal, is published by ISACA, a nonprofit organization created for the public in 1969. Membership in the association, a voluntary organization serving IT governance professionals, entitles one to receive an annual subscript-xion to the ISACA Journal.

Opinions expressed in the ISACA Journal represent the views of the authors and advertisers. They may differ from policies and official statements of ISACA and/or the IT Governance Institute and their committees, and from opinions endorsed by authors, employers or the editors of this Journal. ISACA Journal does not attest to the originality of authors¡¯ content.

Instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. For other copying, reprint or republication, permission must be obtained in writing from the association. Where necessary, permission is granted by the copyright owners for those registered with the Copyright Clearance Center (CCC), 27 Congress St., Salem, Mass. 01970, to photocopy articles owned by ISACA, for a flat fee of US $2.50 per article plus 25¢ per page. Send payment to the CCC stating the ISSN (1526-7407), date, volume, and first and last page number of each article. Copying for other than personal use or internal reference, or of articles or columns not owned by the association without express permission of the association or the copyright owner is expressly prohibited.

Subscript-xion Rates:
US: one year (6 issues) $75.00
All international orders: one year (6 issues) $90.00
Remittance must be made in US funds.


ÀÇ°ß¾²±â

¹øÈ£ Á¦¸ñ ±Û¾´ÀÌ ³¯Â¥ Á¶È¸ Ãßõ
¹ø¿ª¿¡ ´ëÇÑ º¯ (1) ½ÅÀÎö 07-03-24 7830 17
23 IT À§Çè Ž±¸: IT À§Çè °ü¸® ºÐ·ù ¹× ÁøÈ­ By Steve Schlarman, CISM, CISSP ½ÅÀÎö 09-07-09 3713 15
22 IT °Å¹ö³Í½º¿¡¼­ Àü»ç IT °Å¹ö³Í½º·Î À̵¿ By Steven De Haes, Ph.D. and Wim Van Grembergen, Ph.D. ½ÅÀÎö 09-06-03 3059 18
21 Àü»ç IT °Å¹ö³Í½º¿Í IT ¼­ºñ½º °Å¹ö³Ê½ºÀÇ ºñ±³Ç¥ ½ÅÀÎö 09-05-14 3211 12
20 Val IT¸¦ µµÀÔÇϱâ À§ÇÑ 5°¡Áö Çٽɼº°ø¿äÀÎ By Sarah Harries and Peter Harrison ½ÅÀÎö 09-05-06 3831 12
19 ÀÌÀÍ ½ÇÇö°ú ÇÁ·Î±×·¥ °ü¸®: ºñÁî´Ï½º ÄÉÀ̽º¸¦ ³Ê¸Ó¼­ By Sarah Harries and Peter Harrison ½ÅÀÎö 09-04-10 4892 13
18 Æ÷Æ®Æú¸®¿À °ü¸® ±¸ÇöÀÇ µµÀü °úÁ¦ by Sarah Harries and Peter Harrison ½ÅÀÎö 09-03-31 3790 10
17 4 °³ÀÇ »ç¼ÒÇÑ ´Ü¾î: À§Çù, Ãë¾à¼º, °¡´É¼º, À§Çè (Four Little Words) By Steven J. Ross ½ÅÀÎö 09-02-13 7691 18
16 IT °Å¹ö³Í½º ´ë´ã: IT °Å¹ö³Í½º Ãß¼¼ ½ÅÀÎö 08-11-16 3217 7
15 ºñ±ØÀ¸·ÎºÎÅÍ ±³ÈÆ (Lessons from Tragedy) By Steven J. Ross ½ÅÀÎö 08-10-11 3160 7
14 ºñ±ØÀ¸·ÎºÎÅÍ ±³ÈÆ, Àç°í (Lessons from Tragedy, Revisited) By Steven J. Ross ½ÅÀÎö 08-10-08 3300 8
13 CMMI, TOGAF 8.1, IT BPM, NIST 800-14 ¼Ò°³ ½ÅÀÎö 08-06-25 4253 10
12 FIPS PUB 200, ISO/IEC TR 13335, ISO/IEC 15408:2005/COMMON CRITERIA/ITSEC, TickIT ¼Ò°³ ½ÅÀÎö 08-06-24 4001 12
11 PRINCE2, ISO/IEC 17799, PMBOK, ITIL, COBIT ¼Ò°³ ½ÅÀÎö 08-06-24 8033 21
10 °¡Ä¡ °ü¸® ¿ø¸®(Value Management Principles) by Erik Guldentops ½ÅÀÎö 08-06-05 3861 21
9 IT ÇÁ·ÎÁ§Æ® Ãë¼Ò: ´ë°¡ ÁöºÒ, Áö±ÝÀÌ³Ä ³ªÁßÀÌ³Ä by John Thorp ½ÅÀÎö 08-05-05 3602 6
 1  2  3