SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Project Management

IT procurement: seeking out best practices

IT procurement: seeking out best practices

By:  Robert Fabian  On: 10 Jun 2004 For: ComputerWorld Canada Creator

In a previous column I argued for the importance of IT procurement, and for the benefits that can flow from following best practices in IT procurement.

In a previous column I argued for the importance of IT procurement, and for the benefits that can flow from following best practices in IT procurement. That column introduced the procurement review process developed by the U.K. government, The OGC Gateway Review, which identifies what needs to be accomplished, but offers little help in determining how it should be accomplished.

The Software Engineering Institute (www.sei.cmu.edu) has developed a Software Acquisition Capability Maturity Model (ESC-TR-2002-010). The full model is available on the institute's Web site for unlimited distribution for internal purposes. It follows the general maturity model approach SEI has used in other areas, identifying five maturity levels and describing what is required for an organization to reach each level.

At the lowest level, initial, success depends on a hero who manages to get it right. The organization has very little in place to help with software acquisition. Procurement discipline emerges only at the next level, repeatable, where "basic acquisition project management processes are established to plan all aspects of the audition." For many organizations, this would be a significant improvement over current practice.

Each maturity level has key process areas that must be mastered; the repeatable level has seven:

- software acquisition planning

- solicitation

- requirements development and management

- project management

- contract tracking and oversight

- evaluation

- transition to support

Subsequent levels add new key process areas to be mastered. It will typically take an organization one year or more to move from one level to the next.

Each key process area has one or more associated goals. Against each key process area there are targets for commitment to perform, ability to perform, activities performed, measurement and analysis, and verification. This model provides a considerable level of guidance; for example, there are seven activities identified with software acquisition planning, and most of the activities are described in some detail.

One of the activities is establishing and maintaining appropriate documentation. That, in turn, is broken down into seven documents that are typically included in the documentation set. They range from a document that lists all relevant policies for the areas of the acquisition, to a document that describes the measurements to determine the progress of the acquisition.

The next level, defined, adds another six key process areas, ranging from process definition and maintenance to training program management. Key process areas are added as the organization advances to the quantitative level, and then to the optimizing level, where there is "continuous process improvement, empowered by quantitative feedback from the process and from piloting innovative ideas and technologies."

The SA-CMM can be a useful tool to help an organization improve its IT procurement process. The IEEE (www.ieee.org) has also established a standard for software acquisition. It doesn't include a maturity model, but it does include a 16-page long checklist to "assist organizations in establishing their own software acquisition process."


Sign up for our Newsletters












Print |  Views: 582   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Robert Fabian Robert Fabian is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Gartner's top 10 strategic technologies for 2008
Gartner's top 10 strategic technologies for 2008At the top of Gartner Inc.'s 10 strategic technologies for next year is "Green IT". The research firm says that if businesses don't improve data centre energy efficiency, the government may force them to do so.
EMC to acquire RSA Security
EMC to acquire RSA Security In a deal that marries one of the IT industry's biggest data storage vendors and one of its best-known security companies, EMC Corp. unveiled plans to acquire RSA Security Inc. Under the deal, Hopkinton, Mass.-based EMC will pay US$28 a share, or almost $2.1 billion, for Bedford, Mass.-based RSA, according to the companies.
Does this sound like your IT Department?
does this sound like the situation facing your it department?... it probably supports an installed set of information systems that are used by the business to control and report on its operations. there is always more than just one system, and possibly hundreds, many doing the same work as many others. some may be decades-old, a few may be recent and using fairly new technologies, with
Project management's dirty little secret
in speaking with michael sheppard, a phd student at the university of waterloo and a veteran it project manager, i heard a refreshing bit of insight into the minefield that is the art of project management. sheppard pointed out, quite matter-of-factly, that a big part of a team's responsiblity lies not just in ensuring the successful completion of the project, but also in managing expectations an
Dan Swanson's Security Resources: #20
dan’s security resource educational column (#020) l
blog comments powered by Disqus