IT °Å¹ö³Í½º¿¡¼ Àü»ç IT °Å¹ö³Í½º·Î À̵¿
Moving From IT Governance to Enterprise Governance of IT
By Steven De Haes, Ph.D. and Wim Van Grembergen, Ph.D.
ISACA Journal Volume 3, 2009
IT °Å¹ö³Í½º´Â °©ÀÛ½º·´°Ô ³ªÅ¸³ª Á¤º¸±â¼úÀÇ Áß¿äÇÑ À̽´°¡ µÈ °³³äÀÌ´Ù. ±× °³³äÀÌ Åº»ýÇÑ ½Ã±â´Â ºÐ¸íÇÏÁö ¾Ê´Ù. ¡°IT °Å¹ö³Í½º °³¼±Çϱ⡱´Â 2003³â¿¡ óÀ½À¸·Î °¡Æ®³ÊÀÇ »óÀ§ 10°³ CIO °ü¸® ¿ì¼±¼øÀ§¿¡ Æ÷ÇԵǾúÀ¸¸ç, 3À§¸¦ Â÷ÁöÇÏ¿´´Ù. 1998³â¿¡´Â IT °Å¹ö³Í½º °³³äÀ» ³Î¸® º¸±ÞÇϱâ À§ÇÏ¿© IT °Å¹ö³Í½º Çùȸ(ITGI)°¡ ¼³¸³µÇ¾ú´Ù. ÇÐ°è ¹× Àü¹® ¹®Çå¿¡ À־ Á¦¸ñ ¼Ó¿¡ IT °Å¹ö³Í½º¸¦ ¾ð±ÞÇÑ ³í¹®µéÀÌ 1990³â´ë ÈĹݺÎÅÍ ³ªÅ¸³ª±â ½ÃÀÛÇß´Ù. °¡Æ®³Ê¿¡¼´Â 2003³â 3À§¿¡ ·©Å©µÈ »óÀ§ 10°³ CIO °ü¸® ¿ì¼±¼øÀ§¿¡¼ óÀ½À¸·Î IT °Å¹ö³Í½º¸¦ °³¼±Çϱâ À§ÇÑ ¾ÆÀ̵ð¾î¸¦ ¼Ò°³ÇÏ¿´´Ù.
IT °Å¹ö³Í½º °³³äÀÇ ÃâÇö ÀÌÈÄ¿¡, ÀÌ °³³äÀº ¸¹Àº ÁÖ¸ñÀ» ¹Þ¾Ò´Ù. ±×·¯³ª, À̸§¿¡ µé¾îÀÖ´Â ¡°IT¡±¿¡ °üÇÑ ÁýÁßÀûÀÎ °ü½É ´öºÐ¿¡, IT °Å¹ö³Í½º Åä·ÐÀÌ ÁÖ·Î IT ³»¿¡¼¸¸ ¸Ó¹°·¯ ÀÖ¾ú´Ù. IT ºÐ¾ß¿¡¼, ¸¹Àº IT °Å¹ö³Í½º ±¸ÇöÀÌ IT Á¶Á÷¿¡ ÀÇÇØ ÃßÁøµÇ¾úÀ¸³ª, »ç¶÷µéÀº ºñÁî´Ï½º Á¶Á÷¿¡¼ ÁÖµµÀû ¿ªÇÒÀ» ÇØÁֱ⸦ ±â´ëÇÏ¿´´Ù. IT ÅõÀڷκÎÅÍÀÇ ºñÁî´Ï½º °¡Ä¡´Â IT¿¡ ÀÇÇؼ´Â ½ÇÇöµÇ¾îÁú ¼ö ¾ø°í, ±×°ÍÀº ¾ðÁ¦³ª ºñÁî´Ï½º Ãø¸é¿¡¼ âÃâµÈ´Ù´Â Á¡Àº ºÐ¸íÇÑ »ç½ÇÀÌ´Ù. ¿¹¸¦ µé¾î, IT°¡ »õ·Î¿î °í°´°ü°è°ü¸®(CRM) ¾ÖÇø®ÄÉÀ̼ÇÀ» Àû±â¿¡, ¿¹»ê ¹üÀ§ ³»¿¡¼ ±×¸®°í ±â´É¼ºÀ» °®Ãç Àü´ÞÇÏ´õ¶óµµ, ±× ÀÌÈÄ¿¡ ºñÁî´Ï½º°¡ »õ·Î¿î IT ½Ã½ºÅÛÀ» ºñÁî´Ï½º ¿î¿µ¿¡ ÅëÇÕ½ÃÅ°Áö ¾Ê´Â´Ù¸é ºñÁî´Ï½º °¡Ä¡´Â ÀüÇô âÃâµÇÁö ¾ÊÀ» °ÍÀÌ´Ù. ȸ»çÀÇ ¿µ¾÷ ºÎ¼°¡ ¸ÅÃâ°ú ÀÌÀÍÀ» Áõ´ëÇÒ ¼ö ÀÖµµ·Ï »õ·Ó°í ÀûÇÕÇÑ ºñÁî´Ï½º ÇÁ·Î¼¼½ºµéÀ» ¼³°èÇÏ¿© ½ÇÇàÇÒ ¶§¿¡ ºñÁî´Ï½º °¡Ä¡´Â âÃâµÉ °ÍÀÌ´Ù.
ºñÁî´Ï½ºÀÇ Âü¿©°¡ ÇÊ¿¬ÀûÀÏ ¼ö¹Û¿¡ ¾ø´Â °¡Ä¡ ½ÇÇöÀº ±×°ÍÀ» Á¤ÀÇÇϴµ¥ ÀÖ¾î¼ Àü»çÀû IT °Å¹ö³Í½º(enterprise governance of IT)·ÎÀÇ À̵¿À» Ã˹߽ÃÄ×´Ù. Àü»çÀû IT °Å¹ö³Í½º´Â ±â¾÷ °Å¹ö³Í½º(corporate governance)ÀÇ ÇʼöÀûÀÎ ±¸¼º¿ä¼ÒÀ̸ç, ¶ÇÇÑ ±×°ÍÀº ºñÁî´Ï½º/IT ¿¬°è¿Í IT-È°¼º ÅõÀڷκÎÅÍ ºñÁî´Ï½º °¡Ä¡ âÃâ¿¡ µ¿Á¶ÇÏ¿© ºñÁî´Ï½º ¹× IT Àη ¸ðµÎ ÀڽŵéÀÇ Ã¥ÀÓÀ» ÀÌÇàÇÒ ¼ö ÀÖ°Ô ÇÏ´Â Á¶Á÷ÀÇ ÇÁ·Î¼¼½º, ±¸Á¶ ±×¸®°í °ü·Ã ¸ÞÄ¿´ÏÁòµéÀÇ Á¤ÀÇ¿Í ±¸Çö¿¡ ÃÊÁ¡À» ¸ÂÃá´Ù.©ö Àü»çÀû IT °Å¹ö³Í½º´Â ºÐ¸í IT-°ü·Ã Ã¥ÀÓÀ» ³Ñ¾î¼ ºñÁî´Ï½º °¡Ä¡ âÃâÀ» À§ÇØ ÇÊ¿äÇÑ IT-°ü·Ã ºñÁî´Ï½º ÇÁ·Î¼¼½ºµé·Î È®´ëµÈ´Ù. ´õ±¸³ª, ±¹Á¦Ç¥Áرⱸ(ISO)µµ ±â¾÷ IT °Å¹ö³Í½º(¡°Corporate Governance of IT¡±)·Î Á¤ÀÇÇÑ ±¹Á¦ Ç¥ÁØÀÇ 2008³â ¹ßÇ๰(ISO/IEC 38500:2008)¿¡¼ ±×¿Í °°Àº ¹æÇâ¿¡¼ Á¢±ÙÇÏ¿´´Ù. ±× Ç¥ÁØ¿¡¼, ISO´Â ºñÁî´Ï½º¿Í ITÀÇ ¿ªÇÒ ¹× Ã¥ÀÓÀ» ¾ð±ÞÇÏ¸é¼ IT-°ü·Ã ÀÇ»ç°áÁ¤¿¡ ´ëÇÑ °¡À̵带 À§ÇÑ ¿ì¼±Àû ÇൿÀ» Ç¥ÇöÇÑ IT °Å¹ö³Í½º¸¦ À§ÇÑ 6°¡Áö ¿øÄ¢À» Á¦½ÃÇÏ°í ÀÖ´Ù.
¸íĪ°ú ÃÊÁ¡¿¡ ÀÖ¾î¼ÀÇ ÀÌ·¯ÇÑ º¯È´Â ¹Ì¹ÌÇÏ¸ç ±×¸®°í ȹ±âÀûÀÌÁö ¾ÊÀº °ÍÀ¸·Î º¸ÀÏ ¼ö ÀÖÁö¸¸, Çö¾÷ »ç¶÷µéÀÇ ¸¶À½ ¼Ó¿¡´Â Áß´ëÇÑ º¯È¸¦ °¡Á® ¿Ô´Ù. IT °Å¹ö³Í½º¿¡ ÀÖ¾î¼ ITÀÇ ÁÖµµÀû ¿ªÇÒÀº Ç×»ó ¸ð¼øµÈ´Ù. ºñÁî´Ï½º ÇÁ·Î¼¼½ºµé°ú ºñÁî´Ï½º °¡Ä¡ âÃâÀº ºÐ¸í ºñÁî´Ï½º »ç¶÷µéÀÇ ¼öÁß¿¡ ÀÖÀ¸¸ç ¶ÇÇÑ ÀÖ¾î¾ß¸¸ ÇÏ´Â °ÍÀÌ´Ù. ÇÑÆí, »ç¶÷µéÀº ±×·¯ÇÑ ¸¶À½ÀÇ º¯È°¡ ÀúÀý·Î ȤÀº ±× °³³ä¿¡ ´ëÇÑ ¸íĪ¸¸À» ¹Ù²Û´Ù°í ÀϾÁö ¾ÊÀ¸¸®¶ó´Â °ÍÀ» ½ÇÁúÀûÀ¸·Î ±ú´Þ¾Æ¾ß¸¸ ÇÑ´Ù. IT °æ¿µÀڴ ȸ»ç¿¡¼ º¯ÈÀÇ Áß°³ÀÎÀ¸·Î È°µ¿ÇÏ°í ½Ã°£ÀÌ Áö³²¿¡ µû¶ó¼ ¿µ¾÷ ¸ÅÃâ(business buy-in)À» Çâ»ó½ÃÅ°´Â À¯ÀÏÇÑ À§Ä¡¿¡ ÀÖ´Ù. ±×·± Á¡À» ±ú´Ý°Ô Çϱâ À§Çؼ, ITGIÀÇ ÁÖ¿ä ÇÁ·¹ÀÓ¿öÅ©µéÀº, CobiT ¹× Val IT, °·ÂÇÑ Ã˸ÅÁ¦·Î ÀÛ¿ëÇÒ ¼ö ÀÖ´Ù. CobiTÀº IT °ü·Ã ¼öÇàÃ¥ÀÓ¿¡ ÃÊÁ¡ÀÌ ¸ÂÃçÁ® ÀÖÀ¸¸ç Val IT´Â ºñÁî´Ï½º °ü·Ã Ã¥ÀÓ¿¡ ÃÊÁ¡ÀÌ ¸ÂÃçÁ® ÀÖ´Ù. Çö¾÷ »ç¶÷µéÀÌ ÀÌ·¯ÇÑ ÇÁ·¹ÀÓ¿öÅ©¸¦ ÀÚ±âµé ÈûÀ¸·Î ½±°Ô µµÀÔÇÒ °ÍÀ̶ó ÃßÃøÇÏ´Â °ÍÀº Çö½Ç¼ºÀÌ ¾ø´Ù. ±×·¸±â¿¡, ÀÌ ÇÁ·¹ÀÓ¿öÅ©µéÀº Çö¾÷°úÀÇ º¸´Ù ³ªÀº ¼ÒÅëÀ» ÇÏ°í ÇÊ¿äÇÑ Çö¾÷ Âü¿©¸¦ ÀÚ±ØÇϱâ À§Çؼ ÇÊ¿äÇÑ °³³ä°ú Á¢±Ù¹æ¹ýÀ» Áö´Ñ IT °íÀ§ °æ¿µÀÚ¿¡°Ô Á¦°øÇÑ´Ù. ÀÌ·± Àǹ̿¡¼, CobiT°ú Val IT´Â IT Ä¿¹Â´ÏƼ°¡ IT °Å¹ö³Í½º·ÎºÎÅÍ Àü»ç IT °Å¹ö³Í½º·Î À̵¿Çϴµ¥ È°¿ëÇÒ ¼ö ÀÖ´Â ¼ö´ÜÀÌ´Ù.
¿ªÀÚÁÖ) ÀÌ ±Û¿¡¼ »ç¿ëµÈ ¡°IT °Å¹ö³Í½º¡±´Â ¡°IT ¼ºñ½º °Å¹ö³Í½º¡±·Î °£ÁÖÇÏ´Â °ÍÀÌ ´Ù¸¥ ±Ûµé°úÀÇ ¿ÀÇظ¦ ¾ø¾Ù ¼ö ÀÖ´Ù°í »ý°¢ÇÕ´Ï´Ù. Áö±Ý±îÁö ºñÁî´Ï½º °üÁ¡¿¡¼ IT °Å¹ö³Í½º¸¦ ÀνÄÇÑ »ç¶÷µéÀº IT Áß½ÉÀÇ IT °Å¹ö³Í½º¸¦ ¡°low level IT °Å¹ö³Í½º¡±·Î ºÎ¸£°í, »ó´ëÀûÀ¸·Î Àü»ç IT °Å¹ö³Í½º¿Í ¼·Î ÅëÇÏ´Â IT °Å¹ö³Í½ºÀÇ À̸§À» ¡°high level IT governance¡± ¡°proper IT governance¡±·Î Â÷º°ÇÏ¿© »ç¿ëÇϱ⵵ ÇÕ´Ï´Ù.
±×¸®°í ÀÌ Ä¿¹Â´ÏƼ¿¡ ½Ç¸° ÀúÀÇ ¸ðµç ±Û ¼Ó¿¡ Ç¥ÇöµÈ IT °Å¹ö³Í½º´Â Àü»ç IT °Å¹ö³Í½º °üÁ¡¿¡¼ ¾´ °ÍÀÓÀ» ¹àÇôµå¸³´Ï´Ù.
Endnote
1 Van Grembergen, Wim; Steven De Haes;
Enterprise Governance of IT: Achieving Strategic Alignment and Value, Springer, 2009
Steven De Haes, Ph.D., is responsible for the information systems management executive programs and research at the University of Antwerp Management School (Belgium) and is a guest lecturer on information systems management at the University of Antwerp. He is managing director of the Information Technology and Alignment (ITAG) Research Institute. He has been involved in research and development activities of CobiT, Val IT and Risk IT. He can be contacted at steven.dehaes@ua.ac.be.
Wim Van Grembergen, Ph.D., is a professor in the economics and management faculty of the University of Antwerp (Belgium) and executive professor at the University of Antwerp Management School. He is academic director of the Information Technology and Alignment (ITAG) Research Institute and has conducted research in the areas of IT governance, IT audit and IT performance management. He has been involved in research and development activities for ISACA and ITGI, and is a member of ISACA¡¯s IT Governance Committee. He can be contacted at wim.vangrembergen@ua.ac.be .
ISACA Journal, formerly Information Systems Control Journal, is published by ISACA, a nonprofit organization created for the public in 1969. Membership in the association, a voluntary organization serving IT governance professionals, entitles one to receive an annual subscript-xion to the ISACA Journal.
Opinions expressed in the ISACA Journal represent the views of the authors and advertisers. They may differ from policies and official statements of ISACA and/or the IT Governance Institute and their committees, and from opinions endorsed by authors, employers or the editors of this Journal. ISACA Journal does not attest to the originality of authors¡¯ content.
Instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. For other copying, reprint or republication, permission must be obtained in writing from the association. Where necessary, permission is granted by the copyright owners for those registered with the Copyright Clearance Center (CCC), 27 Congress St., Salem, Mass. 01970, to photocopy articles owned by ISACA, for a flat fee of US $2.50 per article plus 25¢ per page. Send payment to the CCC stating the ISSN (1526-7407), date, volume, and first and last page number of each article. Copying for other than personal use or internal reference, or of articles or columns not owned by the association without express permission of the association or the copyright owner is expressly prohibited.
Subscript-xion Rates:
US: one year (6 issues) $75.00
All international orders: one year (6 issues) $90.00
Remittance must be made in US funds.