AI5  Install and Accredit Systems
Control over the IT process of ...
installing and accreditting systems
    with the business goal
    of verifying and confirming that the solution is fit for the intended purpose
     
      is enabled by
      • the realisation of a well-formalised installation, migration, conversion and acceptance plan

        and takes consideration

        • Critical Success Factors that leverage
        • specific IT Resources and is measured by
        • Key Performance Indicators

Record of Assessment
Assignment ID:  * Enter Name: *
Reference Code:  * Enter Location: * Tel. Num: *
Enter Full e-mail Address: *
  Control Objective:

Install and Accredit Systems

CRITICAL SUCCESS FACTORS
Selected Status
Description
*
The acquisition and implementation methodology is established and consistently applied
*
Resources are available to support a separate test environment and sufficient time is allowed for the test process
*
Commitment and involvement of stakeholders is assured in the testing, training and transition processes
*
Test data is available and representative of live data in kind and quantity, and the test environment reflects as close as possible the live environment
*
A feedback mechanism is implemented for optimising and continuously improving the process
*
Stress testing is performed for new systems before they are rolled out and regression testing is conducted for existing systems when changes are implemented
*
Procedures for formally certifying and accrediting systems for security are consistently defined and adhered to
*
There is clear understanding and verification of operational requirements
*
*
*
*
*
*
KEY GOAL INDICATORS
*
Reduced number of missed installation and accreditation milestones
*
Time to complete the installation and accreditation process, from beginning to the end of the security certification and accreditation process
*
Reduced number of operational systems not accredited, in the instance where the process did not occur
*
Number of changes to installed systems needed to optimise operations
*
Number of changes required following system acceptance testing
*
Number of findings during internal or external audits regarding the installation and accreditation process
*
Number of changes required to correct problems after solutions are put into production
*
*
*
*
KEY PERFORMANCE INDICATORS
*
Degree of stakeholder involvement in the installation and accreditation process
*
Number of automated installation and accreditation processes
*
Frequency of reporting of lessons learned
*
Reported user satisfaction with the installation and accreditation process (lessons learned)
*
Number of findings during the quality assurance review of installation and accreditation functions
*
Reusability of the test platform
*
*
*
*
*
*
*
*
  Conclusions:
* Non-existent 
There is a complete lack of formal installation or accreditation processes and senior management or IT staff does not recognise the need to verify that solutions are fit for the intended purpose.
* Optimised 
The installation and accreditation processes have been refined to a level of best practice, based on the results of continuous improvement and refinement. IT installation and accreditation processes are fully integrated into the system life cycle and automated when advisable, facilitating the most efficient training, testing and transition to production status of new systems. Well-developed test environments, problem registers and fault resolution processes ensure efficient and effective transition to the production environment. Accreditation takes place usually with limited rework and post implementation problems are normally limited to minor corrections. Post-implementation reviews are also standardised, with lessons learned channelled back into the process to ensure continuous quality improvement. Stress testing for new systems and regression testing for amended systems is consistently applied.
* Managed and Measurable 
The procedures are formalised and developed to be well organised and practical with defined test environments and accreditation procedures. In practice, all major changes to systems follow this formalised approach. Evaluation of meeting user requirements is standardised and measurable, producing metrics that can be effectively reviewed and analysed by management. The quality of systems entering production is satisfactory to management, with reasonable levels of post-implementation problems. Automation of the process is ad hoc and project dependent. Neither post-implementation evaluations nor continuous quality reviews are consistently employed, although management may be satisfied with the current level of efficiency. The test system adequately reflects the live environment. Stress testing for new systems and regression testing for existing systems is applied for major projects.
* Defined Process 
A formal methodology relating to installation, migration, conversion and acceptance is in place. However, management does not have the ability to assess compliance. IT installation and accreditation processes are integrated into the system life cycle and automated to some extent. Training, testing and transition to production status and accreditation are likely to vary from the defined process, based on individual decisions. The quality of systems entering production is inconsistent, with new systems often generating a significant level of post-implementation problems.
* Repeatable but Intuitive 
There is some consistency between the testing and accreditation approaches, but they are not based on any methodology. The individual development teams normally decide the testing approach and there is usually an absence of integration testing. There is an informal approval process, not necessarily based on standardised criteria. Formal accreditation and sign-off is inconsistently applied.. 
* Initial / Adhoc 
There is an awareness of the need to verify and confirm that implemented solutions serve the intended purpose. Testing is performed for some projects, but the initiative for testing is left to the individual project teams and the approaches taken vary. Formal accreditation and sign-off is rare or non-existent.
Settings will expire on: 

(Do NOT edit.) Field set by Form.
Save and E-mail this form. (Saves only "*" fields & sends E-mail to address above):


Maintenance Functions

Note: If using Netscape on a Macintosh you may have to submit twice, the first will fail, or you can push the "Save Changes and/or Set New Expiration" then Submit.