Stopping shadow IT
Published: 19 Jul 2004 12:00 BST
Spafford added that management needs to understand the risks associated with the current IT model and make a decision about whether it is willing to accept the risks. "Management must be willing to formally document what they are willing to accept," he said.
Further, Spafford said that management must understand that shadow IT is part of the overall control environment and is not exempt from regulatory compliance. "If the shadow IT remains, then they must play by the same rules as [corporate] IT," he noted.
"Shadow IT is a fascinating dynamic to watch," said Spafford. "It's all about people, resources, and meeting expectations. If management fails to set the proper control environment tone from the top, shadow IT will always exist."







