Hari’i ICT Hosi Zero, Roteiru Prátiku Loron 90 atu Estabelese Divizaun ICT

Hosi Avaliasaun ICT no Governasaun ba Cybersecurity, Jestaun Servisu no Transformasaun Dijitál

Iha organizasaun sira iha tempu ohin, Information and Communication Technology (ICT) la’ós de’it funsaun suporte ne’ebé responsabiliza ba komputadór, rede no rezolve problema tékniku.

Divizaun ICT ne’ebé di’ak no estruturadu tenke bele apoia operasaun organizasaun, proteje informasaun, aumenta produtividade, ajuda tomada desizaun, jere risku teknolojia no kria baze forte ba transformasaun dijitál.

Ba organizasaun ne’ebé foin hahú estabelese Divizaun ICT ka hakarak hametin funsaun ICT ne’ebé eziste ona dezafiu boot la’ós de’it atu hili teknolojia saida mak atu sosa.

Dezafiu boot liu mak atu hari’i kombinasaun ne’ebé loos entre ema, governasaun, prosesu, seguransa, infraestrutura, sistema no servisu.

Artigu ida-ne’e aprezenta abordagem prátika ida atu estabelese Divizaun ICT hosi baze, ho fó atensaun liu ba loron 90 dahuluk.

1. Hahú Hosi Organizasaun, La’ós Hosi Teknolojia

Erro komún ida bainhira estabelese funsaun ICT mak hahú diretamente hosi teknolojia.

Pergunta dahuluk sira la presiza:

Servidór saida mak ita tenke sosa?

Software saida mak ita tenke instala?

Komputadór hira mak ita presiza?

Pergunta importante liu mak:

  • Saida mak objetivu estratéjiku organizasaun nian?
  • Saida mak prosesu negósiu ne’ebé krítiku?
  • Departamentu saida mak depende ba ICT?
  • Informasaun saida mak krítiku ba organizasaun?
  • Sistema saida mak uza ona?
  • Problema saida mak utilizadór sira hasoru?
  • Risku ICT saida mak eziste agora?
  • Saida mak organizasaun presiza hosi ICT iha tinan tolu to’o lima mai?

ICT tenke dezenvolve tuir nesesidade negósiu organizasaun nian.

Teknolojia mak enabler – la’ós objetivu final.

2. Define Mandatu ICT

Molok hari’i Divizaun ICT, lideransa organizasaun tenke define klaramente ninia mandatu.

Funsaun ICT bele inklui:

  • Estratéjia no planeamentu ICT
  • ICT Governasaun
  • Information Security no Cybersecurity
  • Infraestrutura ICT
  • Rede no konektividade
  • Sistema no aplikasaun
  • Microsoft 365 no Cloud Services
  • ICT Asset Management
  • Procurement no Vendor Management
  • User Support no Service Management
  • Data no Information Management
  • Backup no Disaster Recovery
  • Business Continuity
  • Digital Transformation
  • ICT Risk Management
  • Polítika no SOP ICT

Responsabilidade exata depende ba tamanhu, estrutura no natureza organizasaun nian.

Maibé, define mandatu hosi inísiu sei ajuda evita konfusaun kona-ba sé mak responsavel ba desizaun teknolojia no risku ICT.

3. Halo ICT Current-State Assessment

Atividade prinsipál dahuluk tenke mak halo ICT Current-State Assessment.

Objetivu mak atu kria baseline ida ne’ebé klaru kona-ba situasaun ICT atual organizasaun nian.

Avaliasaun ida ne’ebé kompletu tenke haree pelo menus ba área sira tuir mai.

Governance

  • Estrutura organizasional ICT
  • Papel no responsabilidade
  • Polítika
  • SOP
  • Mekanizmu tomada desizaun
  • ICT reporting

Infraestrutura

  • Servidór
  • Storage
  • Network equipment
  • Internet
  • Wi-Fi
  • Firewall
  • Infrastruktur komunikasaun

Cybersecurity

  • Identity and Access Management
  • Multi-Factor Authentication
  • Endpoint Protection
  • Patch Management
  • Vulnerability Management
  • Security Monitoring
  • Incident Response

Microsoft 365 no Cloud

  • Entra ID
  • Exchange
  • SharePoint
  • Teams
  • OneDrive
  • Intune
  • Defender
  • Licensing
  • Security configuration

Aplikasaun

  • Business applications
  • Financial systems
  • HR systems
  • Operational systems
  • Database
  • Web applications

Data no Information

  • Information ownership
  • Data classification
  • Data storage
  • Data sharing
  • Data retention
  • Data protection

ICT Assets

  • Desktop
  • Laptop
  • Mobile devices
  • Server
  • Network equipment
  • Software licences

Backup no Disaster Recovery

  • Backup arrangement
  • Recovery procedures
  • Recovery objectives
  • Disaster recovery capability
  • Testing

ICT Service Management

  • Helpdesk
  • Incident management
  • Service request
  • Change management
  • Service level
  • User satisfaction

Ema

  • ICT staffing
  • Skills
  • Training
  • Capacity
  • Roles and responsibilities

Fornesedór

  • ICT vendors
  • Contracts
  • SLA
  • Support arrangements
  • Third-party risks

Avaliasaun tenke bazeia ba evidénsia, la’ós de’it ba opiniaun ka asumsaun.

4. Rona Utilizadór ICT Sira

Teknolojia iha objetivu atu apoia ema no prosesu negósiu.

Tanba ne’e, ICT assessment tenke rona perspetiva hosi parte oioin.

Abordagem prátika ida mak uza instrumentu avaliasaun tolu:

ICT Staff Questionnaire

Foka ba:

  • Infraestrutura
  • Sistema
  • Security
  • Governance
  • Assets
  • Backup
  • Risku tékniku
  • Kapasidade no skills

All-Staff ICT User Survey

Foka ba:

  • Esperiénsia utilizadór
  • Internet no konektividade
  • Device
  • Aplikasaun
  • ICT support
  • Collaboration
  • Security awareness
  • Nesessidade negósiu

Management Interview/ Entrevista Jestaun nian

Foka ba:

  • Prioridade estratéjika
  • Risku negósiu
  • Sistema krítiku
  • Digital transformation
  • Investimentu
  • Expectativa management
  • Nesessidade ICT iha futuru

Kombinasaun perspetiva tolu ne’e sei fó imajen ne’ebé luan liu kona-ba situasaun ICT.

5. Estabelese ICT Governasaun

Depois de kompriende situasaun atual, pasu tuir mai mak Governasaun.

Divizaun ICT profesional presiza regra no responsabilidade ne’ebé klaru kona-ba oinsá teknolojia sei jere.

ICT Governance tenke define:

  • Sé mak halo desizaun ICT
  • Sé mak owner ba informasaun
  • Sé mak aprova investimentu ICT
  • Sé mak jere ICT risk
  • Sé mak aprova user access
  • Sé mak jere change
  • Sé mak jere ICT vendors
  • Sé mak responsavel ba cybersecurity
  • Oinsá ICT performance sei report ba management

Dokumentu prinsipál bele inklui:

  • ICT Governance Framework
  • ICT Strategy
  • ICT Policy
  • Information Security Policy
  • ICT Risk Management Policy
  • ICT Asset Management Policy
  • ICT Procurement Policy
  • ICT Change Management Policy
  • Backup and Recovery Policy
  • Business Continuity Policy
  • Disaster Recovery Policy

Polítika sira tenke apoiadu hosi SOP ne’ebé klaru no prátiku.

6. Hari’i Cybersecurity Hosi Loron Dahuluk

Cybersecurity la bele sai buat ida ne’ebé ita hahú de’it depois de infraestrutura ICT hotu hari’i ona.

Security tenke sai parte hosi dezenhu ICT hosi inísiu.

Baseline cybersecurity tenke konsidera:

Identity

  • Multi-Factor Authentication
  • Least privilege
  • Role-based access
  • Privileged accounts
  • Account lifecycle management
  • Periodic access review

Endpoint

  • Endpoint protection
  • Secure configuration
  • Patch management
  • Encryption
  • Device management
  • Vulnerability management

Network

  • Firewall
  • Network segmentation
  • Secure Wi-Fi
  • VPN
  • Administrative controls
  • Monitoring

Cloud

  • Secure Microsoft 365 configuration
  • Conditional Access
  • Defender
  • Intune
  • Exchange security
  • SharePoint permissions
  • Audit logging

Ema

  • Security awareness
  • Phishing awareness
  • Acceptable use
  • Incident reporting
  • Security responsibilities

7. Uza ISO/IEC 27001 nu’udar Referénsia Governance

Ba organizasaun ne’ebé hakarak abordagem estruturadu ba Information Security, ISO/IEC 27001 bele sai baze importante ida.

ISO/IEC 27001 fó framework bazeadu ba risku atu estabelese, implementa, mantén no kontinua hadi’a Information Security Management System (ISMS).

Organizasaun la presiza diretamente hahú ho objetivu certification.

Hahú ho estabelese ISO/IEC 27001-aligned ISMS bele sai abordagem prátika ida.

ISMS tenke inklui:

  • Information-security governance
  • Risk assessment
  • Risk treatment
  • Security policies
  • Security controls
  • Responsibility
  • Security awareness
  • Incident management
  • Monitoring
  • Internal review
  • Management review
  • Continual improvement

Dokumentu importante ida mak Statement of Applicability (SoA), ne’ebé esplika control sira ne’ebé relevante no oinsá control sira ne’e sei implementa.

Objetivu prinsipál la’ós de’it atu hetan certification.

Objetivu mak atu hari’i sistema seguransa ne’ebé funsiona duni iha operasaun loroloron.

8. Estabelese ICT Asset Register

Divizaun ICT la bele jere asset sira ho di’ak se la hatene ho loos asset saida mak organizasaun iha.

ICT Asset Register tenke inklui:

  • Asset ID
  • Device type
  • Manufacturer
  • Model
  • Serial number
  • Assigned user
  • Department
  • Location
  • Purchase date
  • Warranty
  • Operating system
  • Security status
  • Lifecycle status

Lifecycle asset tenke kontrola hosi:

Planning → Procurement → Receipt → Registration → Configuration → Assignment → Maintenance → Return → Disposal

Asset Management tenke liga ho Procurement, Finance, HR no ICT.

9. Estabelese Identity and Access Management

User access mak área importante ida iha ICT Security.

Organizasaun tenke estabelese prosesu Joiner–Mover–Leaver.

Joiner

HR notification → account creation → licence → device → access → MFA → security awareness

Mover

Role change → access review → permission adjustment → remove unnecessary access

Leaver

HR notification → account disable → session revocation → device recovery → access removal → information transfer/retention

Prosesu ida-ne’e tenke dokumentadu no halo review periodikamente.

10. Hari’i ICT Service Management

Divizaun ICT profesional la presiza de’it ema ne’ebé iha kapasidade téknika.

Presiza mos sistema servisu ne’ebé previsível.

Prosesu básiku bele hanesan:

Request → Ticket → Prioritise → Assign → Resolve → Verify → Close → Report

ICT tenke monitoriza:

  • Incident sira
  • Service request sira
  • Response time
  • Resolution time
  • SLA compliance
  • Problema repetitivu
  • User satisfaction

Ho ida-ne’e, ICT muda hosi sistema informal “telefone ema ICT bainhira computador iha problema” ba servisu profissional ne’ebé bele sukat no reporta.

11. Backup, Business Continuity no Disaster Recovery

Organizasaun barak fó atensaun boot ba prevene incidente, maibé menus preparasaun ba recovery.

ICT tenke identifika:

  • Sistema krítiku
  • Informasaun krítika
  • Dependénsia negósiu
  • Recovery Time Objective (RTO)
  • Recovery Point Objective (RPO)
  • Backup frequency
  • Backup location
  • Recovery procedures
  • Emergency contacts
  • Alternative connectivity
  • Disaster recovery procedures

Prinsípiu importante ida mak:

Backup ne’ebé nunka testadu la hanesan ho recovery capability ne’ebé prova ona.

Tanba ne’e, restore testing tenke sai parte hosi programa ICT.

12. Jere Vendor no Third Parties

ICT moderno depende barak ba service provider liur.

Ezemplu:

  • Internet provider
  • Cloud provider
  • Software vendor
  • Hardware supplier
  • Managed service provider
  • Cybersecurity provider
  • Consultant

Vendor Management tenke haree ba:

  • Contract
  • Scope
  • SLA
  • Security requirements
  • Data responsibilities
  • Availability
  • Support
  • Incident notification
  • Business continuity
  • Exit arrangement

Risku teknolojia la lakon de’it tanba servisu ida outsource ona.

13. Dezenvolve ICT Team

Estrutura ICT tenke bazeia ba nesessidade organizasaun.

Funsaun sira bele inklui:

  • ICT leadership
  • Service desk/user support
  • Infrastructure and network
  • Systems/application administration
  • Cybersecurity
  • Data/information management
  • Cloud/Microsoft 365
  • ICT governance

La’ós organizasaun hotu-hotu presiza ema ida-idak ba funsaun hotu.

Iha organizasaun ki’ik, ema ida bele hala’o responsabilidade barak, ho apoiu hosi consultant ka managed service provider.

Importante liu mak:

Responsabilidade krítika hotu tenke iha owner ne’ebé klaru.

14. Implementa Abordagem Loron 90

Loron 90 dahuluk bele fahe ba etapa tolu.

Loron 1–30: Kompriende no Avalia

Foka ba:

  • Hasoru management no departamentu sira
  • Kompriende nesessidade negósiu
  • Haree dokumentasaun ezistente
  • Halo inventáriu ICT assets
  • Avalia infraestrutura
  • Avalia sistema
  • Avalia M365/Cloud
  • Avalia cybersecurity
  • Haree vendor
  • Haree backup/DR
  • Halo survey utilizadór
  • Identifika risku

Deliverable:

ICT Current-State Assessment Report

Loron 31–60: Secure no Govern

Foka ba melhoria imediata:

  • MFA
  • Access review
  • Privileged account controls
  • Inactive account cleanup
  • Critical patching
  • Endpoint security
  • Backup verification
  • Asset register
  • Incident management
  • Risk register
  • Priority policies no SOPs

Rejultadu:

ICT Governance & Cybersecurity Baseline

Loron 61–90: Planeia no Transformasaun

Dezenvolve:

  • ICT Strategy
  • ICT Roadmap
  • Cybersecurity Roadmap
  • Digital Transformation Roadmap
  • ICT Organisational Structure
  • ICT Budget
  • Technology Investment Plan
  • ISMS Roadmap
  • Training Plan
  • Project Priorities

Rejultadu:

ICT Strategy & 12–36 Month Roadmap

15. Sukat ICT Maturity

Divizaun ICT tenke iha baseline ida no halo medisaun ba progresu.

Modelu simples ida mak:

NivelMaturity
1Initial / Ad Hoc
2Developing
3Defined
4Managed
5Optimised

Área sira bele inklui:

  • Governance
  • Cybersecurity
  • Infrastructure
  • Cloud/M365
  • Applications
  • Data
  • Asset management
  • Service management
  • Backup/DR
  • Risk management
  • ICT skills

Objetivu la’ós atu hetan númeru de’it.

Objetivu mak atu hatene:

Ita iha ne’ebé agora, ita hakarak to’o iha ne’ebé, no saida mak ita presiza halo atu to’o iha ne’ebá?

16. Hari’i ICT Performance Dashboard

Depois de Divizaun ICT hahú funsiona, management tenke hetan reporting regular.

Service

  • System availability
  • Network availability
  • Number of incidents
  • SLA performance
  • User satisfaction

Security

  • MFA coverage
  • Endpoint protection coverage
  • Critical vulnerabilities
  • Security incidents
  • Security training completion

Assets

  • Asset register accuracy
  • Devices under management
  • Warranty status
  • Unsupported systems

Resilience

  • Backup success rate
  • Restore testing
  • DR testing

Governance

  • Open ICT risks
  • Risk treatment progress
  • Policies reviewed
  • Audit findings
  • Corrective actions

Ho dashboard ida-ne’e, management bele haree performance no risku ICT ho klaru.

17. Continual Improvement

Estabelese Divizaun ICT la’ós projetu ida ne’ebé remata iha loron ida.

Teknolojia, cyber threats, nesessidade negósiu no estrutura organizasaun muda kontinua.

Tanba ne’e, ICT tenke uza siklu melhoria kontínua:

Assess → Plan → Implement → Measure → Review → Improve

Siklu ida-ne’e tenke sai parte hosi kultura ICT.

18. Papel Lideransa ICT

Lider ICT la bele haree de’it nu’udar ema ne’ebé responsavel ba problema tékniku.

Papel ICT leadership tenke liga:

Business Strategy ↔ People ↔ Processes ↔ Technology ↔ Security ↔ Risk

Lider ICT tenke bele servisu no ko’alia ho:

  • Senior management
  • Finance
  • HR
  • Procurement
  • Operations
  • Legal
  • HSE
  • ICT team
  • Vendors
  • End users

Objetivu mak transforma nesessidade negósiu sai solusaun teknolojia ne’ebé prátiku, seguru no sustentável.

19. Modelu Prátiku atu Hari’i Divizaun ICT

Konkluzaun

Estabelese Divizaun ICT la’ós liu-liu kona-ba sosa teknolojia.

Ida-ne’e mak prosesu atu hari’i ema, governance, prosesu, seguransa, infraestrutura, sistema no servisu ne’ebé bele permite organizasaun opera ho di’ak agora no prepara-an ba futuru.

Abordagem ne’ebé di’ak liu la’ós atu hahú ho sosa teknolojia.

Hahú ho:

Kompriende → Avalia → Secure → Govern → Standardiza → Transforma → Hadi’a Kontinua.

Abordagem loron 90 fó baze prátiku ba estabelese funsaun ICT, enquanto framework ISO/IEC 27001-aligned bele fó baze longu-prazu ba jestaun informasaun no cybersecurity risk.

Ikus mai, objetivu Divizaun ICT simples:

Halo organizasaun servisu di’ak liu, opera ho seguransa, halo desizaun bazeia ba informasaun, no prontu ba futuru dijitál.

Referénsia no Leitura Adisionál

1. ISO/IEC 27001:2022

International Organization for Standardization (ISO). ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements.

ISO/IEC 27001 define requisitos atu estabelese, implementa, mantén no hadi’a kontinua Information Security Management System (ISMS).

ISO/IEC 27001:2022 — ISO Official Standard

2. ISO/IEC 27002:2022

ISO/IEC 27002:2022 — Information security, cybersecurity and privacy protection — Information security controls.

Standard ida-ne’e fó orientasaun kona-ba control sira ba information security, inklui access control, cryptography, human-resource security no incident response.

ISO/IEC 27002:2022 — ISO Official Standard

3. NIST Cybersecurity Framework 2.0

National Institute of Standards and Technology (NIST). (2024). The NIST Cybersecurity Framework (CSF) 2.0.

NIST CSF 2.0 fó abordagem fleksível ba organizasaun sira atu kompriende, avalia, determina prioridade no jere cybersecurity risk.

NIST Cybersecurity Framework (CSF) 2.0

4. ISO 22301:2019

ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements.

ISO 22301 fó framework ba organizasaun atu prepara, responde no recovery hosi eventu disruptivu ne’ebé bele afeta operasaun.

ISO 22301:2019 — ISO Official Standard

Nota kona-ba Artigu

Artigu ida-ne’e bazeia ba abordagem prátika ba ICT governance, cybersecurity, information security, risk management, business continuity no digital transformation.

Framework no standard sira refere iha leten tenke adapta tuir tamanhu organizasaun, natureza negósiu, risku, rekizitu legal/regulatóriu no rekursu disponivel.

ISO/IEC 27001-aligned la’ós hanesan ho ISO/IEC 27001 certified. Certification formal presiza organizasaun estabelese no opera ISMS ne’ebé kumpre requisitos relevante no liu hosi prosesu certification independente.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *