Secure Application Development

Talking to senior management

Learning objectives

  • understand senior management's frame of reference,
  • effectively communicate secure development concerns to senior management,
  • develop value and risk related argumentation to support process improvement activities,
  • share experience with other organisations.

Overview

This is an interactive session to exchange ideas and opinions in relation to how to convince senior management to improve and invest in better development methods and tools. It identifies senior management's typical concerns in relation to the five focus areas of IT governance:

  • Business-IT alignment: What are the developments, investments and operations that are key to our strategy?
  • Value generation: How to generate value from all activities and investments?
  • Risk management: How to avoid enterprise risk such as not reaching objectives, financial losses, security breaches and unacceptable delays?
  • Resource management: How can we better inventory and manage our resources? What architecture has more long term value? What technical decisions could be directly translated into business results/impacts?
  • Performance measurement: What performance metrics to put in place to keep the visibility of our objectives and of progress toward them?
Participants are invited to share their experience and opinions on their management's position and expectations: how do they perceive their management's concerns in the light of the five focus areas? How does this reflect on application development activities? What approaches to value creation work? Which risk reduction activities were successful? We identify and inventory responses to management decisons that could strenghten attendees' positions and formulate reasonable courses of action:
  • how can we explain to senior management that our proposals to introduce secure application development methods address their concerns?
  • what is required from Executive Management?

We hold an open discussion on participants’ actions to improve relationship with management and how to address their concerns through the proactive use of the five IT Governance focus areas.

To view a recording of this session Get Adobe Flash player