Learn IT Resources (CGEIT) with Interactive Flashcards

Master key concepts in IT Resources through our interactive flashcard system. Click on each card to reveal detailed explanations and enhance your understanding.

Sourcing Strategies

In the CGEIT framework, sourcing strategies fall under the IT Resources domain. They concern how an enterprise obtains the IT capabilities, services, skills and infrastructure it needs to deliver business value while managing risk and optimizing resources. Sourcing is a governance decision, not just a procurement task. The board and executive management must ensure that sourcing choices align with enterprise strategy, risk appetite, regulatory obligations and long-term objectives.

Common sourcing models include:
- Insourcing: delivering services with internal staff and assets, which keeps control and protects intellectual property.
- Outsourcing: contracting third parties to provide services, which can bring cost efficiency, scalability and specialized expertise.
- Offshoring and nearshoring: using providers in other countries, either distant or nearby.
- Shared services: consolidating functions across business units.
- Cloud sourcing: using IaaS, PaaS or SaaS models.
- Multisourcing: combining several providers under an integrated governance model.

From a governance perspective, sourcing decisions should start with a clear business case. That case should assess core versus non-core capabilities, total cost of ownership, strategic value, market maturity and internal competencies. Leaders must also evaluate risks such as vendor lock-in, data privacy and sovereignty, security, regulatory compliance, concentration risk and loss of critical knowledge.

An important principle is that accountability cannot be outsourced. The enterprise remains responsible for outcomes even when execution is delegated. Effective governance therefore requires strong vendor selection criteria and well-structured contracts. Service level agreements and key performance indicators should be clearly defined, and the enterprise should retain rights to audit. A defined exit or transition strategy is also needed.

Ongoing vendor and relationship management keeps providers aligned with business needs. It does this through performance monitoring, periodic reviews, risk assessments and continuous improvement. Frameworks such as COBIT support these practices, for example through the APO10 objective, Managed Vendors.

Ultimately, a sound sourcing strategy gives the enterprise the right resources at the right time and cost. It also maintains flexibility, resilience and value delivery while keeping risks within acceptable levels.

Cloud and Multi-Sourcing Governance

In the CGEIT (Certified in the Governance of Enterprise IT) framework, Cloud and Multi-Sourcing Governance falls under the IT Resources domain. It covers how an enterprise directs, evaluates, and monitors IT services delivered by external providers, including cloud vendors (SaaS, PaaS, IaaS), managed service providers, and outsourcers, alongside internal capabilities. The goal is to optimize value, manage risk, and keep resources aligned with business strategy. The key principle is that accountability cannot be outsourced. While service delivery can be delegated to third parties, the board and executive management stay responsible for outcomes, compliance, and risk.

Core elements include:

1. Sourcing strategy: Leaders decide what to build, buy, or subscribe to, based on strategic importance, cost, capability, and risk appetite. Core differentiating capabilities may stay in-house, while commodity services move to the cloud or to specialized vendors.

2. Vendor selection and contracts: Due diligence assesses each provider's financial stability, security posture, certifications (such as ISO 27001 and SOC 2), and data residency. Contracts should define service level agreements (SLAs), right-to-audit clauses, exit and transition terms, data ownership, and liability.

3. Integration and coordination: In multi-sourcing, several vendors must work together seamlessly. This often calls for a Service Integration and Management (SIAM) model, with clear roles, end-to-end SLAs, and processes for resolving issues that span vendors.

4. Risk management: Key risks include vendor lock-in, concentration risk, shadow IT, regulatory non-compliance, and data breaches. The shared responsibility model clarifies which security duties the provider handles and which the customer retains.

5. Performance and value monitoring: Organizations use KPIs, balanced scorecards, regular service reviews, and cost management practices such as FinOps to confirm that sourcing arrangements deliver the expected benefits.

6. Frameworks: COBIT 2019 supports this area through objectives such as APO09 (Managed Service Agreements) and APO10 (Managed Vendors), along with policies covering the whole vendor lifecycle.

Effective governance ensures that cloud and multi-sourcing arrangements stay strategic, secure, cost-effective, and adaptable to changing business needs.

Resource Capacity Planning

In the CGEIT (Certified in the Governance of Enterprise IT) framework, Resource Capacity Planning sits within the IT Resources domain. It is the governance-driven process of making sure the enterprise has the right IT resources, in the right quantity and quality, at the right time, to meet current and future business needs cost-effectively. Resources include infrastructure, applications, information, and people. From a governance perspective, the board and executive management do not perform detailed capacity calculations. Instead, they ensure that a structured, repeatable capacity planning practice exists, is aligned with enterprise strategy, and supports value delivery while optimizing risk and resources. This reflects the COBIT objective of ensuring resource optimization (EDM04) and the management practices for managing availability and capacity (BAI04) and managing human resources (APO07). Key elements include: (1) Demand forecasting, which translates business plans, growth projections, and the IT investment portfolio into expected resource requirements. (2) Assessment of current capacity and utilization, which uses performance monitoring, benchmarks, and skills inventories to identify gaps or excess. (3) Gap analysis and sourcing decisions, which determine whether to build, buy, outsource, or use cloud services, and whether to hire, train, or contract staff. (4) Alignment with financial planning, so that capacity investments fit budgets and are justified by business cases and expected value. (5) Risk consideration, which addresses the risk of under-capacity (service degradation, missed opportunities, lost revenue) and over-capacity (wasted spending, idle assets). (6) Continuous monitoring and review, using KPIs such as utilization rates, service-level attainment, and skills coverage to adjust plans as conditions change. Effective resource capacity planning enables agility, supports service levels and business continuity, and prevents bottlenecks in critical initiatives. For CGEIT candidates, the essential point is that capacity planning must be strategic, business-aligned, and overseen through clear accountability. It should ensure that resource allocation reflects enterprise priorities and maximizes the value derived from IT investments.

Acquisition of Resources and Make-Versus-Buy Decisions

In the CGEIT framework, the acquisition of resources falls under the Resource Optimization domain. Its goal is to ensure the enterprise has adequate, appropriate and cost-effective IT capabilities, including people, processes, applications, infrastructure and information, to meet current and future strategic objectives. Governance is less about operational buying and more about ensuring acquisition decisions align with enterprise strategy, deliver value, optimize risk and use resources efficiently. COBIT 2019 supports this through objectives such as EDM04 (Ensured Resource Optimization), APO07 (Managed Human Resources), APO10 (Managed Vendors) and BAI03 (Managed Solutions Identification and Build).

The make-versus-buy decision is central to resource acquisition. Leaders must choose among several sourcing options: developing a solution in-house, purchasing commercial off-the-shelf software, subscribing to cloud or SaaS services, outsourcing to third parties, or combining these in a hybrid model.

Key evaluation criteria include:

1. **Strategic importance:** Capabilities that provide competitive differentiation or represent core competencies are often built or tightly controlled. Commodity functions are usually bought.
2. **Total cost of ownership:** This covers acquisition, implementation, licensing, maintenance, support, upgrades and exit costs over the full life cycle.
3. **Time to market:** Buying usually speeds deployment, while building may delay benefits.
4. **Skills and capacity:** The decision depends on whether internal staff have the expertise and availability to develop and maintain the solution.
5. **Control, customization and intellectual property:** Building offers flexibility and ownership. Buying may require adapting business processes to the product.
6. **Risk:** Relevant risks include vendor viability, lock-in, security, regulatory compliance, data sovereignty and project delivery risk.
7. **Scalability and integration:** The solution must fit the enterprise architecture.

Effective governance requires a formal business case that compares alternatives objectively, using techniques such as cost-benefit analysis and NPV. It also requires clear decision rights, often exercised through an IT steering or investment committee, and alignment with sourcing policies and enterprise architecture standards. When the choice is to buy or outsource, governance extends to vendor selection, contract management, service level agreements, performance monitoring and exit strategies. Ultimately, the board and executives remain accountable for outcomes, even when execution is outsourced. Decisions should be revisited periodically as business needs, technology and markets evolve.

Procurement Governance

In the CGEIT framework, Procurement Governance falls under the IT Resources domain. It is the set of policies, structures, decision rights, and oversight mechanisms that ensure the enterprise acquires IT products, services, and capabilities in a way that supports business objectives, optimizes value, and manages risk. Its purpose is not to run individual purchases. Instead, it sets the direction and controls that make sourcing decisions consistent, transparent, and accountable.

The first element is strategic alignment. IT acquisitions should follow from the enterprise strategy and the IT strategy. A sourcing strategy defines when to build, buy, outsource, or use cloud services. Governance bodies such as the board, IT steering committee, or investment committee approve major acquisitions based on business cases that show expected benefits, costs, and risks.

The second element is policy and decision rights. The organization sets clear procurement policies, authorization limits, and segregation of duties. These cover vendor selection criteria, competitive bidding requirements, and approval thresholds. A RACI model clarifies who requests, evaluates, approves, and oversees each acquisition. This helps prevent conflicts of interest, fraud, and unauthorized spending.

The third element is risk management. Procurement governance requires due diligence on vendors, covering financial stability, security posture, regulatory compliance, and concentration or lock-in risk. Contracts should include service level agreements, right-to-audit clauses, data protection terms, exit strategies, and escrow arrangements where appropriate.

The fourth element is vendor and contract lifecycle management. Governance extends past signing the contract. It includes ongoing performance monitoring, relationship management, periodic reviews, renewals, and orderly termination.

The fifth element is value and performance measurement. Metrics such as total cost of ownership, SLA compliance, benefits realized, and vendor scorecards help confirm that acquisitions deliver their promised value. These measures connect procurement to Benefits Realization.

Frameworks such as COBIT support procurement governance, especially its objectives for managed vendors, agreements, and portfolio. Together, these elements give stakeholders assurance that IT resources are acquired efficiently, ethically, and in line with the organization's risk appetite.

IT Resource Lifecycle and Asset Management

In the CGEIT framework, IT Resource Lifecycle and Asset Management falls within the IT Resources domain. It focuses on how governance ensures that IT resources, including infrastructure, applications, information, and people, are planned, acquired, used, maintained, and retired in ways that optimize value, manage risk, and support enterprise objectives. The lifecycle typically includes five stages. Planning identifies resource needs based on business strategy, capacity forecasts, and architecture standards. Acquisition covers sourcing decisions such as build versus buy, outsourcing, cloud services, and vendor selection, guided by business cases and procurement policies. Deployment and operation ensure resources are configured, secured, and used efficiently to deliver services. Maintenance and optimization cover patching, upgrades, performance monitoring, and periodic reviews of continued fitness for purpose. Disposal or retirement manages secure decommissioning, data sanitization, license reclamation, and environmental compliance. Asset management is the discipline that supports this lifecycle. It maintains an accurate inventory of hardware, software, licenses, contracts, and cloud subscriptions, often through a configuration management database (CMDB) or IT asset management tools. Good asset management enables cost transparency, total cost of ownership (TCO) analysis, license compliance, vulnerability management, and informed investment decisions. It also links assets to the business services and owners they support, clarifying accountability. From a governance perspective, the board and executive management do not manage assets directly. Instead, they set direction through policies, define roles and responsibilities, establish risk appetite, and require performance metrics such as utilization rates, asset age, compliance levels, and cost per service. Frameworks like COBIT, especially its Build, Acquire and Implement objectives such as BAI09 Managed Assets, together with ISO/IEC 19770 and ITIL, provide practices for this oversight. Effective governance in this area prevents waste, reduces security and legal exposure, avoids technical debt, and ensures that resource investments remain aligned with strategy throughout their useful life. This supports the broader CGEIT goals of benefits realization and risk optimization.

Software Licensing and Technology Refresh

Within the CGEIT framework, Software Licensing and Technology Refresh fall under the Resources domain. This domain focuses on ensuring that IT resources, including applications, infrastructure, information and people, are acquired, used and retired in ways that optimize value and manage risk. Governance professionals do not manage licenses or hardware directly. Instead, they make sure that policies, accountability structures and oversight mechanisms exist so these activities support enterprise objectives.

Software Licensing governance addresses the legal, financial and operational risks of using third-party and open-source software. Key concerns include compliance with vendor terms, avoiding over-licensing (wasted spend) and under-licensing (audit penalties and reputational damage), and understanding licensing models such as perpetual, subscription, per-user, per-core and cloud consumption-based. Effective governance requires a software asset management (SAM) policy, a centralized license inventory, clear ownership, periodic true-ups and internal audits, and alignment with procurement and contract management. Boards and executives should receive meaningful metrics, such as compliance status, license utilization and cost trends. These metrics show whether licensing decisions support strategy, for example when shifting to SaaS models.

Technology Refresh governance ensures that hardware, software and platforms are replaced or upgraded before they become obsolete, unsupported, insecure or too costly to maintain. A sound refresh strategy is based on lifecycle management, including defined useful lives, vendor end-of-support dates, total cost of ownership and risk assessments. Refresh decisions should be portfolio-driven and prioritized according to business value, risk exposure and capacity needs rather than ad hoc requests. Governance bodies such as IT steering committees evaluate investment business cases, balance innovation against stability, and ensure funding is planned within budgets.

Together, these practices support CGEIT principles of value delivery, risk optimization and resource optimization. Frameworks such as COBIT (for example, BAI09 Managed Assets and APO06 Managed Budget and Costs) give structured guidance. They help ensure that licensing compliance and timely technology refresh reduce technical debt, strengthen security and sustain the enterprise's ability to achieve its strategic goals.

Human Resource Competency Assessment

In the CGEIT framework, Human Resource Competency Assessment belongs to the IT Resources domain. It is the structured process of evaluating whether the enterprise's IT workforce has the knowledge, skills, behaviors and capacity needed to deliver business value and support strategic objectives. Governance professionals treat people as a critical IT resource, alongside information, applications and infrastructure, and ensure that human capabilities are optimized, developed and aligned with enterprise goals.

The assessment begins with defining required competencies. These are derived from the enterprise strategy, the IT strategic plan, and architecture roadmaps. Frameworks such as SFIA (Skills Framework for the Information Age), the e-Competence Framework (e-CF), and COBIT practices (for example, APO07 Managed Human Resources) provide standardized competency definitions and proficiency levels. Each role is mapped to a profile of required technical, managerial and soft skills.

Next, current competencies are measured using methods such as self-assessments, manager evaluations, certifications, performance reviews, skills inventories and 360-degree feedback. Comparing current capabilities against required profiles produces a gap analysis. The analysis highlights shortages, surpluses, key-person dependencies and succession risks.

Governance oversight ensures that the results drive decisions. These include training and development programs, recruitment, outsourcing or sourcing strategies, job rotation, mentoring, and succession planning. The board and executive management should receive reports showing whether IT human resources are sufficient to execute the portfolio of programs and manage risk.

Key governance considerations include:
- Aligning competency requirements with business strategy.
- Ensuring assessments are objective, repeatable and periodically refreshed.
- Integrating results into resource planning and investment decisions.
- Managing risks from skill gaps or reliance on critical individuals.
- Measuring effectiveness through metrics such as training completion, staff retention, skill coverage and project success rates.

Ultimately, competency assessment allows the enterprise to optimize its investment in people. It sustains capabilities for innovation and operations and ensures that IT can reliably deliver value, which is a core CGEIT objective of resource optimization.

Skills Development, Succession and Key-Person Dependency

Within the CGEIT domain of IT Resources (resource optimization), people are treated as a critical enterprise asset that governance must deliberately manage, alongside infrastructure, applications and information. Skills development, succession planning and key-person dependency management help ensure that the enterprise has the human capability needed to deliver IT-enabled value, both now and in the future.

Skills Development: The board and executive management must ensure that IT staff and business users have the competencies needed to achieve strategic objectives. Governance practices include conducting periodic skills inventories and gap analyses against the IT strategy, defining competency frameworks such as SFIA or e-CF, and funding training, certification, mentoring and job rotation. COBIT objectives such as APO07 (Managed Human Resources) and APO01 support this by requiring skills to be planned, monitored and aligned with enterprise goals. Effective skills development also covers decisions about whether to build capabilities internally or acquire them through sourcing partners.

Succession Planning: Governance requires that critical IT leadership and specialist roles, such as the CIO, enterprise architect or security lead, have identified and prepared successors. This involves talent assessment, development plans for high-potential staff, documented role profiles and regular review by HR and senior management. Succession planning protects strategic continuity, preserves institutional knowledge and reduces disruption during turnover, retirement or reorganization.

Key-Person Dependency: This is the risk that essential knowledge, skills or system access is concentrated in one individual or a small group, creating a single point of failure. Governance responses include cross-training, documentation of procedures and architectures, knowledge-management repositories, segregation of duties, mandatory vacations, backup staffing and retention incentives. These dependencies should be recorded in the IT risk register and reported to risk owners.

Together, these practices support benefits realization and risk optimization. They ensure that human resources are adequate, resilient and aligned with business needs, and that the enterprise can sustain IT services despite staff changes.

Management of Contracted Services

In the CGEIT framework, Management of Contracted Services sits within the IT Resources domain. It covers how an enterprise governs third-party providers, such as outsourcers, cloud vendors, managed service providers and consultants, so that external resources deliver value, manage risk and support business objectives in the same way internal resources should. The guiding principle is that responsibility can be delegated but accountability cannot. The board and executive management remain accountable for outcomes even when services are outsourced. Governance therefore begins with a sourcing strategy that defines which capabilities to keep in-house, which to contract out and why. Those decisions should rest on cost, capability, strategic importance and risk appetite. Vendor selection should follow a structured, transparent process. This includes clear requirements, due diligence on financial stability, security posture, compliance and reputation, and objective evaluation criteria. Contracts must then translate business needs into enforceable terms. Typical terms include scope, service level agreements (SLAs), key performance indicators, pricing, data ownership, confidentiality, right-to-audit clauses, regulatory compliance, liability, intellectual property, dispute resolution and termination conditions. Once services are running, the enterprise must monitor performance continuously. This involves regular reporting, service reviews, scorecards and audits that compare actual delivery against SLAs and the expected benefits. Risk management extends to the vendor, covering concentration risk, fourth-party dependencies, information security, business continuity and geopolitical exposure. Relationship management complements contract enforcement by building collaboration and trust and encouraging continuous improvement. Clear governance structures, such as vendor management offices and defined escalation paths, help keep these arrangements consistent. Exit and transition planning is essential to avoid lock-in and ensure an orderly handover if a contract ends or fails. Frameworks such as COBIT support this area through practices for managing supplier relationships, agreements and performance. Effective management of contracted services ensures that external partners deliver value, optimize costs, comply with policies and regulations, and remain aligned with enterprise strategy. In this way, it strengthens overall IT governance and resource optimization.

Service Level Agreements and Vendor Performance

In the Certified in the Governance of Enterprise IT (CGEIT) framework, Service Level Agreements (SLAs) and vendor performance management are central to governing IT resources and making sure that externally and internally sourced services deliver value aligned with enterprise objectives. An SLA is a formal, negotiated agreement between a service provider and a customer that defines the expected level of service in measurable terms. Typical elements include service scope, availability targets, response and resolution times, capacity, security and compliance requirements, roles and responsibilities, reporting frequency, escalation procedures, and remedies or penalties for non-compliance. Internally, Operational Level Agreements (OLAs) support SLAs by defining commitments between IT units, while underpinning contracts govern third-party suppliers. From a governance perspective, the board and executive management do not write SLAs themselves. Instead, they set direction by ensuring that sourcing strategies, contract policies, and risk appetite are defined, and that SLAs are derived from business requirements rather than technical convenience. This links SLAs to value delivery, resource optimization, and risk optimization, the core governance objectives reflected in COBIT. Vendor performance management is the ongoing process of monitoring, evaluating, and improving supplier delivery against contractual commitments. It relies on key performance indicators, balanced scorecards, regular service reviews, audits, customer satisfaction surveys, and benchmarking. Effective governance requires clear accountability, often through a vendor management office, and transparent reporting to senior stakeholders. Key governance concerns include vendor lock-in, concentration risk, financial viability of suppliers, data protection, regulatory compliance, right-to-audit clauses, exit and transition planning, and continuous improvement provisions. Performance results should feed back into decisions on contract renewal, renegotiation, or replacement. For the CGEIT candidate, the key point is that SLAs and vendor oversight are governance mechanisms. They translate strategic expectations into enforceable, measurable commitments and give leadership the assurance that IT investments and outsourced services are delivering expected benefits, managing risk, and using resources responsibly.

Vendor Risk, Right to Audit and Exit Strategies

Within CGEIT (Certified in the Governance of Enterprise IT), vendor management falls under the Resources and Risk Optimization domains. The board and executive management stay accountable for IT outcomes even when services are outsourced. Vendor Risk, Right to Audit and Exit Strategies are three linked controls that protect enterprise value across the third-party lifecycle.

Vendor Risk: This is the potential for a third party to harm the enterprise through operational failure, poor performance, financial instability, security breaches, regulatory non-compliance, concentration risk or reputational damage. Governance requires a formal third-party risk management framework aligned with enterprise risk appetite. Key elements include due diligence before contracting, risk-tiering vendors by criticality, and clear SLAs and KPIs. Ongoing monitoring should cover performance, financial health, certifications (such as SOC reports or ISO 27001) and fourth-party (subcontractor) exposure. Outsourcing transfers execution, not accountability.

Right to Audit: This is a contractual clause that lets the enterprise, its internal or external auditors, or regulators examine the vendor's controls, processes, facilities and records relevant to the service. It provides independent assurance that contractual, security and compliance obligations are being met. Governance should ensure the clause defines:
- scope, frequency and notice periods;
- cost allocation;
- access to subcontractors;
- acceptable alternatives, such as third-party attestation reports.
Without this right, the enterprise cannot verify vendor claims or meet regulatory evidence requirements.

Exit Strategies: These are predefined plans for ending a vendor relationship in an orderly way, whether due to contract expiry, poor performance, vendor failure, a change of ownership or a strategic shift. Effective strategies address:
- data ownership, return and certified destruction;
- transition assistance and knowledge transfer;
- intellectual property and escrow arrangements;
- termination triggers and notice periods;
- avoidance of vendor lock-in through portability and open standards;
- continuity of critical services during migration.
Exit plans should be negotiated before signing, when the enterprise has the most leverage, and tested periodically.

Together, these mechanisms preserve value delivery, keep risk within appetite and maintain accountability throughout outsourcing arrangements.

IT Cost Management and Chargeback

In the CGEIT framework, IT Cost Management and Chargeback fall mainly under the IT Resources domain and support Benefits Realization. They help ensure that IT spending is transparent, controlled, and aligned with enterprise objectives. Governance professionals do not manage budgets day to day. Instead, they make sure the right policies, structures, and accountability exist so leaders can make informed investment decisions.

IT Cost Management is the disciplined process of identifying, measuring, planning, controlling, and optimizing the cost of IT services and resources across their full lifecycle. Key elements include:

- **Total Cost of Ownership (TCO):** capturing acquisition, operation, maintenance, support, and retirement costs.
- **Cost categorization:** separating capital from operating expenses, direct from indirect costs, and run-the-business from change-the-business spending.
- **Budgeting and forecasting:** setting spending plans and projecting future needs.
- **Benchmarking:** comparing costs against peers or industry standards.
- **Ongoing optimization:** for example, through vendor management, consolidation, or cloud cost controls.

Frameworks such as COBIT 2019 (APO06 Managed Budget and Costs) give practical guidance.

Chargeback is a cost-allocation mechanism that bills business units for the IT services they consume. Common models include:

- **Usage-based allocation:** charges per transaction, user, or gigabyte.
- **Fixed or subscription fees:** a set price for a defined service.
- **Tiered service pricing:** prices that vary by service level.
- **Simple overhead allocation:** charges based on headcount or revenue.

A softer alternative is showback, which reports consumption costs without actually transferring funds. It builds awareness without creating friction.

From a governance perspective, chargeback has several benefits. It increases transparency, encourages responsible demand, links IT costs to business value, and supports accountability. However, poorly designed models can cause disputes, drive behavior that suboptimizes the enterprise, or prompt units to bypass IT and create shadow IT. Effective chargeback therefore requires:

- a clear IT service catalog;
- accurate cost drivers;
- simple, fair, and understandable rates;
- executive sponsorship;
- periodic review by governance bodies such as an IT steering committee.

Ultimately, the CGEIT goal is not cost reduction alone. It is optimizing IT investment so that resources deliver measurable value at acceptable risk.

Aligning IT Resource Management with Enterprise Resource Management

In the CGEIT framework, the IT Resources domain addresses how the enterprise ensures that IT has adequate, capable and optimized resources to deliver value and support strategic goals. Aligning IT resource management with enterprise resource management means that IT resources such as people, skills, information, applications, infrastructure, funding and vendor relationships are not managed in isolation. Instead, they are planned, acquired, allocated and monitored using the same enterprise-wide principles, policies and processes that govern all organizational resources. Governance establishes this alignment by ensuring IT resource strategies derive from enterprise strategy and business priorities. For example, IT workforce planning should integrate with enterprise human resources practices for recruitment, competency frameworks, performance management, succession planning and training. IT budgeting should follow enterprise financial planning cycles, investment criteria and cost allocation models. IT asset management should align with enterprise asset registers, depreciation policies and lifecycle management. IT procurement and sourcing should comply with enterprise purchasing policies, contract standards and supplier risk management. COBIT 2019 supports this through objectives such as EDM04 Ensured Resource Optimization, which directs the board to set principles for resource allocation and capability, and management objectives such as APO06 Managed Budget and Costs, APO07 Managed Human Resources, APO10 Managed Vendors and BAI09 Managed Assets. Key benefits of alignment include avoiding duplicated or conflicting processes, improving transparency of total cost of ownership, enabling consistent prioritization of scarce resources across business and IT, and strengthening accountability. It also helps identify capability gaps early so the enterprise can decide whether to build, buy or partner. Governance professionals should ensure clear roles and responsibilities, defined resource principles, regular capability assessments, and metrics such as resource utilization, skills coverage, budget variance and vendor performance. Ultimately, alignment ensures IT resources are treated as enterprise resources, optimized to deliver business value while managing risk and cost effectively.

Centralized, Decentralized and Shared-Service IT Resourcing

In the CGEIT framework, IT resource optimization is a core governance objective. It ensures that people, infrastructure, applications and information are sourced, organized and allocated so that they deliver business value efficiently. The resourcing model an enterprise chooses (centralized, decentralized or shared-service) shapes accountability, cost, agility and alignment with strategy. The board and executive management must select and oversee that model.

Centralized IT resourcing places IT staff, budgets, infrastructure and decision rights under a single corporate IT function, typically led by the CIO. Its strengths are economies of scale, standardized architecture, consistent security and compliance controls, stronger negotiating power with vendors, and clear enterprise-wide visibility of IT spending and risk. Its weaknesses include slower responsiveness to individual business units, a perception of IT as bureaucratic, and weaker alignment with local needs.

Decentralized IT resourcing distributes IT resources and decision authority to business units, divisions or geographic regions. Each unit controls its own systems and staff. This model offers close business alignment, faster local decision-making and greater ownership by business leaders. However, it often leads to duplicated investments, inconsistent standards, fragmented data, higher total cost of ownership and increased risk because governance oversight is harder to enforce.

The shared-service model is a hybrid. Common, non-differentiating services such as data centers, networks, help desks, ERP support and procurement are consolidated into a service organization. That organization operates like an internal provider, often with service level agreements (SLAs), chargeback or showback mechanisms, and a service catalog. Business units keep control over strategic, differentiating capabilities. This approach balances efficiency with responsiveness and supports a customer-oriented, performance-measured IT culture.

From a CGEIT perspective, no single model is inherently correct. Governance requires choosing the model that fits enterprise strategy, culture, risk appetite and maturity. It also requires defining clear decision rights (for example, through RACI charts), establishing portfolio and investment oversight, monitoring performance and benefits, and periodically reassessing the model as business conditions change.

More IT Resources questions
449 questions (total)
Practice questions
One session at a time, always new questions