The purpose of the oversight activity is to ensure that all other activities are following standards and guidelines set forth by the organization. These standards may be imposed internally due to corporate policies (e.g., CMMI or ISO) or externally focused due to legislation (e.g., Sarbanes-Oxley or HIPAA). In any case it is imperative that an audit trail is maintained and reviewed to ensure compliance and mitigate risk. Specific tooling can be put in place to help ease the additional workload that oversight brings.
In addition to a pure audit-focus, oversight also works to define what compliance means. For example, best practices and templates in project management, solutions architecture, development and change management are all candidates for standardization, streamlining and oversight.
Sub Activities
Although most organizations will have some variants, oversight activities typically include the following:
- Creating and communicating standards and guidelines.
- Capturing audit information.
- Creating oversight reports.
- Reviewing reports.