*
unknown
inadequate
acceptable
good
Policy enforcement
is considered and decided upon at the time of policy development
*
unknown
inadequate
acceptable
good
A confirmation
process is in place to measure awareness, understanding and compliance
with policies
*
unknown
inadequate
acceptable
good
Well-defined
and clearly articulated mission statements and policies are available
*
unknown
inadequate
acceptable
good
Information
control policies are aligned with the overall strategic plans
*
unknown
inadequate
acceptable
good
Management
endorses and is committed to the information control policies,
stressing the need for communication, understanding and compliance
*
unknown
inadequate
acceptable
good
Management
is leading by example
*
unknown
inadequate
acceptable
good
There is
practical guidance with respect to implementation of policies
and procedures
*
unknown
inadequate
acceptable
good
Diverse attention-catching
methods are used to repeatedly communicate important messages
*
unknown
inadequate
acceptable
good
Information
control policies are current and up-to-date
*
unknown
inadequate
acceptable
good
There is
a consistently applied policy development framework that guides
formulation, roll out, understanding and compliance
*
unknown
inadequate
acceptable
good
*
KEY
GOAL INDICATORS
*
unknown
inadequate
acceptable
good
Percent of
IT plans and policies covering mission, vision, goals, values,
and code of conduct which are developed and documented
*
unknown
inadequate
acceptable
good
Percent of
IT plans and policies which are communicated to all stakeholders
*
unknown
inadequate
acceptable
good
Percent of
the organisation that has been trained in policies and procedures
*
unknown
inadequate
acceptable
good
Improved
measure of user awareness based on regular surveys
*
unknown
inadequate
acceptable
good
Number of
policies and procedures addressing information control
*
unknown
inadequate
acceptable
good
*
*
unknown
inadequate
acceptable
good
*
*
unknown
inadequate
acceptable
good
*
*
unknown
inadequate
acceptable
good
*
KEY
PERFORMANCE INDICATORS
*
unknown
inadequate
acceptable
good
Time lag
between changes in the IT strategic plan and the IT human resources
management plan
*
unknown
inadequate
acceptable
good
Percent of
IT personnel with completed professional development plans
*
unknown
inadequate
acceptable
good
Percent of
IT personnel with documented and validated performance reviews
*
unknown
inadequate
acceptable
good
Percent of
training time per person
*
unknown
inadequate
acceptable
good
Percent of
critical personnel cross-trained and assigned back-up personnel
*
unknown
inadequate
acceptable
good
Number of
projects delayed or cancelled due to lack of IT personnel resources
*
unknown
inadequate
acceptable
good
Percent of
the human resources budget assigned to the development and maintenance
of the IT human resources management plan
*
unknown
inadequate
acceptable
good
Percent of
IT personnel positions with documented job descriptions and hiring
qualifications
*
unknown
inadequate
acceptable
good
*
*
unknown
inadequate
acceptable
good
*