Читать книгу Capability Security A Complete Guide - 2020 Edition - Gerardus Blokdyk - Страница 8
ОглавлениеCRITERION #2: DEFINE:
INTENT: Formulate the stakeholder problem. Define the problem, needs and objectives.
In my belief, the answer to this question is clearly defined:
5 Strongly Agree
4 Agree
3 Neutral
2 Disagree
1 Strongly Disagree
1. Have all basic functions of Capability security been defined?
<--- Score
2. What are the boundaries of the scope? What is in bounds and what is not? What is the start point? What is the stop point?
<--- Score
3. Have specific policy objectives been defined?
<--- Score
4. What is the context?
<--- Score
5. What is in scope?
<--- Score
6. How have you defined all Capability security requirements first?
<--- Score
7. What are the rough order estimates on cost savings/opportunities that Capability security brings?
<--- Score
8. Is special Capability security user knowledge required?
<--- Score
9. Are approval levels defined for contracts and supplements to contracts?
<--- Score
10. Do you have a Capability security success story or case study ready to tell and share?
<--- Score
11. Scope of sensitive information?
<--- Score
12. What is the scope?
<--- Score
13. How do you hand over Capability security context?
<--- Score
14. Does the scope remain the same?
<--- Score
15. Will team members perform Capability security work when assigned and in a timely fashion?
<--- Score
16. How did the Capability security manager receive input to the development of a Capability security improvement plan and the estimated completion dates/times of each activity?
<--- Score
17. Are audit criteria, scope, frequency and methods defined?
<--- Score
18. What happens if Capability security’s scope changes?
<--- Score
19. What are the record-keeping requirements of Capability security activities?
<--- Score
20. What are the dynamics of the communication plan?
<--- Score
21. Has the Capability security work been fairly and/or equitably divided and delegated among team members who are qualified and capable to perform the work? Has everyone contributed?
<--- Score
22. What is out-of-scope initially?
<--- Score
23. Is full participation by members in regularly held team meetings guaranteed?
<--- Score
24. How do you gather requirements?
<--- Score
25. What gets examined?
<--- Score
26. How can the value of Capability security be defined?
<--- Score
27. Who is gathering information?
<--- Score
28. Are different versions of process maps needed to account for the different types of inputs?
<--- Score
29. Do you all define Capability security in the same way?
<--- Score
30. What intelligence can you gather?
<--- Score
31. Does the team have regular meetings?
<--- Score
32. Do the problem and goal statements meet the SMART criteria (specific, measurable, attainable, relevant, and time-bound)?
<--- Score
33. How do you manage scope?
<--- Score
34. What are the core elements of the Capability security business case?
<--- Score
35. What was the context?
<--- Score
36. What is out of scope?
<--- Score
37. What is the definition of success?
<--- Score
38. What would be the goal or target for a Capability security’s improvement team?
<--- Score
39. What are the Capability security use cases?
<--- Score
40. Has the improvement team collected the ‘voice of the customer’ (obtained feedback – qualitative and quantitative)?
<--- Score
41. How would you define the culture at your organization, how susceptible is it to Capability security changes?
<--- Score
42. What sort of initial information to gather?
<--- Score
43. What is the scope of Capability security?
<--- Score
44. Are all requirements met?
<--- Score
45. What system do you use for gathering Capability security information?
<--- Score
46. Are roles and responsibilities formally defined?
<--- Score
47. What are the tasks and definitions?
<--- Score
48. Who defines (or who defined) the rules and roles?
<--- Score
49. Are the Capability security requirements testable?
<--- Score
50. Is there a completed, verified, and validated high-level ‘as is’ (not ‘should be’ or ‘could be’) stakeholder process map?
<--- Score
51. The political context: who holds power?
<--- Score
52. When are meeting minutes sent out? Who is on the distribution list?
<--- Score
53. Who are the Capability security improvement team members, including Management Leads and Coaches?
<--- Score
54. Will team members regularly document their Capability security work?
<--- Score
55. What are the Capability security tasks and definitions?
<--- Score
56. Has the direction changed at all during the course of Capability security? If so, when did it change and why?
<--- Score
57. Is there regularly 100% attendance at the team meetings? If not, have appointed substitutes attended to preserve cross-functionality and full representation?
<--- Score
58. Is Capability security linked to key stakeholder goals and objectives?
<--- Score
59. Are there different segments of customers?
<--- Score
60. What are the requirements for audit information?
<--- Score
61. Who is gathering Capability security information?
<--- Score
62. Is the current ‘as is’ process being followed? If not, what are the discrepancies?
<--- Score
63. Are task requirements clearly defined?
<--- Score
64. How do you keep key subject matter experts in the loop?
<--- Score
65. What information should you gather?
<--- Score
66. Is the scope of Capability security defined?
<--- Score
67. How do you catch Capability security definition inconsistencies?
<--- Score
68. How do you manage changes in Capability security requirements?
<--- Score
69. What specifically is the problem? Where does it occur? When does it occur? What is its extent?
<--- Score
70. What critical content must be communicated – who, what, when, where, and how?
<--- Score
71. What is in the scope and what is not in scope?
<--- Score
72. Is the work to date meeting requirements?
<--- Score
73. Will a Capability security production readiness review be required?
<--- Score
74. Is there a completed SIPOC representation, describing the Suppliers, Inputs, Process, Outputs, and Customers?
<--- Score
75. Have all of the relationships been defined properly?
<--- Score
76. Is the team adequately staffed with the desired cross-functionality? If not, what additional resources are available to the team?
<--- Score
77. What Capability security requirements should be gathered?
<--- Score
78. How does the Capability security manager ensure against scope creep?
<--- Score
79. What scope do you want your strategy to cover?
<--- Score
80. How do you manage unclear Capability security requirements?
<--- Score
81. Are improvement team members fully trained on Capability security?
<--- Score
82. What is the scope of the Capability security effort?
<--- Score
83. Are accountability and ownership for Capability security clearly defined?
<--- Score
84. What are the Roles and Responsibilities for each team member and its leadership? Where is this documented?
<--- Score
85. Are stakeholder processes mapped?
<--- Score
86. How would you define Capability security leadership?
<--- Score
87. Has everyone on the team, including the team leaders, been properly trained?
<--- Score
88. How do you gather the stories?
<--- Score
89. Is the team equipped with available and reliable resources?
<--- Score
90. What is the scope of the Capability security work?
<--- Score
91. Are customer(s) identified and segmented according to their different needs and requirements?
<--- Score
92. What sources do you use to gather information for a Capability security study?
<--- Score
93. In what way can you redefine the criteria of choice clients have in your category in your favor?
<--- Score
94. What is the definition of Capability security excellence?
<--- Score
95. If substitutes have been appointed, have they been briefed on the Capability security goals and received regular communications as to the progress to date?
<--- Score
96. Is Capability security currently on schedule according to the plan?
<--- Score
97. When is the estimated completion date?
<--- Score
98. Has/have the customer(s) been identified?
<--- Score
99. What baselines are required to be defined and managed?
<--- Score
100. What key stakeholder process output measure(s) does Capability security leverage and how?
<--- Score
101. Is it clearly defined in and to your organization what you do?
<--- Score
102. What Capability security services do you require?
<--- Score
103. Is Capability security required?
<--- Score
104. Are required metrics defined, what are they?
<--- Score
105. When is/was the Capability security start date?
<--- Score
106. How will the Capability security team and the group measure complete success of Capability security?
<--- Score
107. What defines best in class?
<--- Score
108. Is the team sponsored by a champion or stakeholder leader?
<--- Score
109. What constraints exist that might impact the team?
<--- Score
110. Has anyone else (internal or external to the group) attempted to solve this problem or a similar one before? If so, what knowledge can be leveraged from these previous efforts?
<--- Score
111. Who approved the Capability security scope?
<--- Score
112. How do you build the right business case?
<--- Score
113. What are (control) requirements for Capability security Information?
<--- Score
114. What customer feedback methods were used to solicit their input?
<--- Score
115. Is data collected and displayed to better understand customer(s) critical needs and requirements.
<--- Score
116. Are the Capability security requirements complete?
<--- Score
117. Is the improvement team aware of the different versions of a process: what they think it is vs. what it actually is vs. what it should be vs. what it could be?
<--- Score
118. Is there a critical path to deliver Capability security results?
<--- Score
119. Has a Capability security requirement not been met?
<--- Score
120. What scope to assess?
<--- Score
121. How often are the team meetings?
<--- Score
122. How was the ‘as is’ process map developed, reviewed, verified and validated?
<--- Score
123. Is there a Capability security management charter, including stakeholder case, problem and goal statements, scope, milestones, roles and responsibilities, communication plan?
<--- Score
124. Is the Capability security scope manageable?
<--- Score
125. What knowledge or experience is required?
<--- Score
126. Are team charters developed?
<--- Score
127. What information do you gather?
<--- Score
128. Do you have organizational privacy requirements?
<--- Score
129. Is scope creep really all bad news?
<--- Score
130. Is the team formed and are team leaders (Coaches and Management Leads) assigned?
<--- Score
131. Has your scope been defined?
<--- Score
132. Have the customer needs been translated into specific, measurable requirements? How?
<--- Score
133. How will variation in the actual durations of each activity be dealt with to ensure that the expected Capability security results are met?
<--- Score
134. What is the worst case scenario?
<--- Score
135. Has a high-level ‘as is’ process map been completed, verified and validated?
<--- Score
136. How and when will the baselines be defined?
<--- Score
137. How is the team tracking and documenting its work?
<--- Score
138. Has a project plan, Gantt chart, or similar been developed/completed?
<--- Score
139. Are there any constraints known that bear on the ability to perform Capability security work? How is the team addressing them?
<--- Score
140. What are the compelling stakeholder reasons for embarking on Capability security?
<--- Score
141. Has a team charter been developed and communicated?
<--- Score
Add up total points for this section: _____ = Total points for this section
Divided by: ______ (number of statements answered) = ______ Average score for this section
Transfer your score to the Capability security Index at the beginning of the Self-Assessment.