Background Image
Table of Contents Table of Contents
Previous Page  52 / 280 Next Page
Basic version Information
Show Menu
Previous Page 52 / 280 Next Page
Page Background

50

BLUE LABEL INTEGRATED ANNUAL REPORT 2014

AIRTIME

GOVERNANCE

OF RISK

CONTINUED

TECHNOLOGY GOVERNANCE

The Board is responsible for the Group’s technology

governance risk and compliance. The Board has

delegated its responsibility for the implementation of

IT governance to management. Management has

developed an IT Governance Framework which has

been adopted, and the Information Security Officer is

driving a number of programmes across the

organisation to ensure it is effectively communicated

and that all Group companies are informed of the

framework and associated policies. Management is

implementing a number of controls to ensure that the

policies are effectively adopted and maintained across

the organisation.

A number of areas relating to technology governance

have progressed. There has been a significant drive to

formalise controls in order to ensure consistent and

adequate risk management. The operation’s

environment has been assessed to ascertain the

process requirements from both an enhancement

as well as a compliance perspective. On the disaster

recovery side, resilience has been added to key

platforms that are able to continue operations in the

event of single-node failures. The next phase has

been initiated to consider multi-node failure as well as

location outages.

On the project and system changes side, processes

have been formalised to streamline work activity as

well as ensure focus is maintained appropriately.

With the growth in business there has been a marked

increase in new requests for technology

enhancements. We are confident that we have

adequate controls to assist our internal customers to

meet their objectives, while maintaining acceptable

performance levels from our systems.

In order to gear the technology function to support

the growing business environment, a number of

governance, risk and compliance objectives have been

set. We have compiled a governance framework by

initially identifying generic technology risks. A policy

framework has been implemented to manage these

risks and an implementation plan is in place to

complete the rollout of the policy framework.