<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>program - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/program/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/program/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Tue, 05 Jan 2021 21:39:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>program - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/program/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Bug Bounty: insight and benchmark on the banking industry 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/01/bug-bounty-insight-and-benchmark-on-the-banking-industry-2021/</link>
		
		<dc:creator><![CDATA[Jérôme de Lisle]]></dc:creator>
		<pubDate>Wed, 06 Jan 2021 07:00:43 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14940</guid>

					<description><![CDATA[<p>&#160; What is a bug bounty and what is it used for? Mere buzzwords a few years ago, bug bounty programmes and vulnerability disclosure initiatives have since permeated the cyber-related vocabularies of a wide range of organisations, whether it be...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/01/bug-bounty-insight-and-benchmark-on-the-banking-industry-2021/">Bug Bounty: insight and benchmark on the banking industry 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-14941 media-14941" class="align-none"><img fetchpriority="high" decoding="async" class="size-full wp-image-14941 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-1.png" alt="" width="1375" height="508" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-1.png 1375w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-1-437x161.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-1-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-1-768x284.png 768w" sizes="(max-width: 1375px) 100vw, 1375px" /></figure>
<p>&nbsp;</p>
<h2 style="text-align: justify;">What is a bug bounty and what is it used for?</h2>
<p style="text-align: justify;">Mere buzzwords a few years ago, bug bounty programmes and vulnerability disclosure initiatives have since permeated the cyber-related vocabularies of a wide range of organisations, whether it be digital giants, top investment banks, or government bodies. The basic principle is the following: companies provide a financial incentive or reward for well-intentioned hackers to find and report vulnerabilities discovered in their assets. The catch is that the company behind the initiative sets a fixed window of opportunity for hackers to discover and fix these vulnerabilities. Wavestone has studied the adoption of these initiatives within the banking sector and the good practices to be drawn from such initiatives.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">3 levels of maturity: Reporting Channel, Vulnerability Disclosure Policy and Bug Bounty Programmes</h2>
<p style="text-align: justify;">When it comes to vulnerability disclosure, the initiatives are various and the terminology is broad, whether it is Coordinated Vulnerability Disclosure, Responsible Vulnerability Disclosure or Vulnerability Disclosure Policy. All of these initiatives aim at providing researchers with a safe way to report vulnerabilities, yet the level of detail regarding the reporting process, rules for searching for vulnerabilities and the expectations of the organisation in question varies greatly from one programme to another. In the light of these observations, we identified 3 levels of maturity as follows: Reporting Channel, Vulnerability Disclosure Policy (VDP) and Bug Bounty Programmes (BBP).</p>
<p style="text-align: justify;">The first level of maturity, <em>Reporting Channel, </em>generally consists of a simple web page providing very basic instructions and a dedicated channel to report vulnerabilities. This first step toward vulnerability disclosure acts as a safety net in case someone discovers a vulnerability, but it doesn’t actively attract hackers, particularly due to the lack of monetary incentive. Reporting Channel is the second most common type of initiative, accounting for 28% of the identified initiatives.</p>
<p style="text-align: justify;">The second level of maturity, <em>Vulnerability Disclosure Policies,</em> also takes the format of a dedicated web page but this time with much more detail. It contains advanced information on reporting processes, the assets in scope, and the preferences, rules and exceptions for vulnerability researching. Furthermore, in most cases (90%), information regarding the expectations that hackers may have after submitting a report in terms of both service-level agreements (SLAs) and public recognition for their work are outlined. In many of these initiatives (77%), companies commit to providing hackers with safe harbour and not pursuing legal action against hackers if they follow the rules and act in good faith. This kind of initiative can be managed internally or by a third-party platform (HackerOne, BugCrowd, Synack…) that will communicate with hackers and oversee bug triage.</p>
<p style="text-align: justify;">Finally, <em>Bug Bounty Programmes </em>represent the highest level of maturity, as it features the same level of information as <em>Vulnerability Disclosure Policy</em> but this time, hackers are financially rewarded for reporting vulnerabilities. This aims to attract talented hackers and make bug bounties a fully-fledged tool in banks’ cyber-ecosystems. Third-party platforms can either manage these programmes or set up private programmes to which only vetted hackers will have access (following a background and skills check). In many cases, private programmes are used as a steppingstone to bug bounty, allowing companies to gain experience with the concept before moving on to a public programme. They also make it possible to implement advanced security features (full research monitoring through VPNs, Non-Disclosure Agreements, advanced vetting, on-location research&#8230;) which make it easier to comply with the security and confidentiality standards that are common in the banking sector.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">The banking industry is not outdistanced by other industries</h2>
<p style="text-align: justify;">These initiatives were implemented by 18% of the studied banks, which is 2.5 times higher than the average reported in the Forbes Global 2000<em>.</em> Therefore, it can be said that the banking sector has well-integrated vulnerability disclosure processes as part of its cyber ecosystem, with the banking and insurance sector ranking in 3rd position in terms of number of programmes for Internet and online services and computer software. However, it is not the most attractive from a financial point of view, ranking in 12th place in terms of the average remuneration for a critical vulnerability, with blockchains and crypto currencies offering an average remuneration that is almost 3 times higher (source: HackerOne’s Hacker Powered Security Report 2019).</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">Western banks are more confident about engaging in vulnerability disclosure processes</h2>
<p style="text-align: justify;">Although the adoption of vulnerability disclosure processes in the banking sector seems to be global, this research found that initiatives are mainly adopted by European and American banks with some specificities. These observations can be explained by several factors.</p>
<p style="text-align: justify;">In the US, vulnerability disclosure has long been part of the culture of tech industry giants such as Google and Facebook which, among other companies, launched their own programmes before 2012. The US are also home to players that now rank among the world&#8217;s leading bug bounty platforms, including BugCrowd (2011), HackerOne (2012) and Synack (2013). It is therefore not a surprise to see that these platforms are managing most of the American banks&#8217; vulnerability disclosure programmes.</p>
<p style="text-align: justify;">In Europe, the situation is different and there are fewer key players. After several major cyber incidents, the Netherlands was the first country in Europe to launch a national initiative by publishing the <em>Guidelines for Coordinated Vulnerability Disclosure (2013)</em> &#8211; a collaborative effort between the Dutch Government&#8217;s National Cyber Security Centrum (NCSC) and various private sector companies. Today, nearly 70% of the major Dutch banks have a self-managed bug bounty programme and the country has played a key role in the construction of EU guidelines on the subject matter. It is also regularly referred to as an example to be followed by several European authorities. Other initiatives and platforms have also emerged elsewhere in Europe, such as YesWeHack, Intigriti, HackenProof, Yogosha, etc. However, it is difficult to precisely assess the emergence of bug bounty programmes across Europe, as more than half of them are private and lack publicly available information for the purpose of confidentiality.</p>
<p style="text-align: justify;">In Asia, banks are less proactive on vulnerability disclosure on account of reservations about private programmes and other cultural factors. However, the last few years have seen growing initiatives from both Asian technology giants and government institutions, notably in Singapore and Japan. This is not surprising, as many government institutions have launched this type of initiative in the past (for example, Hack The Pentagon in the USA or the recent StopCovid application&#8217;s bug bounty that is managed by YesWeHack in France).</p>
<p>&nbsp;</p>
<figure id="post-14943 media-14943" class="align-none"><img decoding="async" class="alignnone size-full wp-image-14943" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-2-1.png" alt="" width="1369" height="822" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-2-1.png 1369w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-2-1-318x191.png 318w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-2-1-65x39.png 65w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-2-1-768x461.png 768w" sizes="(max-width: 1369px) 100vw, 1369px" /></figure>
<p>&nbsp;</p>
<h2 style="text-align: justify;">Getting into vulnerability disclosure will require truly effective preparation</h2>
<p style="text-align: justify;">With many success stories and a growing number of companies from all sectors launching vulnerability disclosure programmes, it is tempting to follow the trend. However, to ensure the success of this type of initiative, it is crucial to address a few points. First, a vulnerability or bug bounty disclosure programme should be part of a global cyber security approach and be complementary to more traditional measures such as regular code reviews, security by design and security/pentest audits. Reporting bugs and flaws is only the first step of the process. The company must then have the in-house skills to analyse the provided reports and remediate the vulnerabilities as soon as possible. Second, to avoid wasting both the hackers’ and the company’s time, the scope of the programme must be carefully designed in order to maximize its effectiveness and prevent intrusion on unwanted assets. The same rules apply when it comes to the rules for searching and reporting. Finally, it is crucial to address hackers’ motivations to ensure the success of a bug bounty programme. Expectations for submitting a report must be clearly specified and address the process, response time and reward. Constant communication with the hacker community as well as an evolution of the programme or the rewards are some key elements that can ensure the sustainability of the programme and the motivation of hackers, thus contributing to the programme’s success.</p>
<p>&nbsp;</p>
<figure id="post-14945 media-14945" class="align-none"><img decoding="async" class="size-full wp-image-14945 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-3-1.png" alt="" width="1369" height="686" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-3-1.png 1369w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-3-1-381x191.png 381w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-3-1-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-3-1-768x385.png 768w" sizes="(max-width: 1369px) 100vw, 1369px" /></figure>
<p>&nbsp;</p>
<h2 style="text-align: justify;">The image of hackers is still often associated with criminal actions&#8230;</h2>
<p style="text-align: justify;">When it comes to bug bounty, one of the main concerns is security, with organisations questioning whether exposing their platforms to hackers might lead to exploitation of any discovered vulnerabilities through the sale of user data or the vulnerabilities themselves directly on the black market.</p>
<p style="text-align: justify;">These fears are partly justified, as user data can now easily be sold on the black market: credit cards, passports, medical records or authentication information can be sold for less than EUR 15 and targeted phishing using this information can generate even more profit. A critical flaw can also be exploited and result in a much larger cyber-attack, as demonstrated by the havoc wreaked by cryptolockers in recent years. However, these incidents are rarely linked to bug bounty programmes, as malicious hackers do not wait for organisations to launch bug bounty programmes in order to attack them. Rather, these attacks can occur at any time.</p>
<p style="text-align: justify;">Secondly, different skills and levels of preparation are required to find vulnerabilities and exploit them.</p>
<p style="text-align: justify;">Finally, money is the primary motivation for hackers participating in these programmes in less than 15% of cases, according to HackerOne. For the majority of hackers, hacking is a passion and they are mostly looking for challenges and opportunities to improve their skills and make the web more secure &#8211; in this case, financial rewards are just a small bonus and getting on the wrong side of the law is not worth it.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">Vulnerability Disclosure Policy: a first step to improve cyber security</h2>
<p style="text-align: justify;">Vulnerability disclosure and bug bounty initiatives are now a mainstream topic in the cyber security field, and the banking sector is no exception. Although bug bounty programmes are not miracle solutions and some effort is required in order to ensure that they are really effective, implementing a Vulnerability Disclosure Policy appears to add a great additional layer of security for a low investment. We can therefore only recommend implementing such a policy as soon as an organisation’s cyber maturity allows for it.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/01/bug-bounty-insight-and-benchmark-on-the-banking-industry-2021/">Bug Bounty: insight and benchmark on the banking industry 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hong Kong launches a major cybersecurity program for its banking industry</title>
		<link>https://www.riskinsight-wavestone.com/en/2016/08/hong-kong-cybersecurity-program-cybersecurite-banking-industry/</link>
		
		<dc:creator><![CDATA[Chadi Hantouche]]></dc:creator>
		<pubDate>Tue, 16 Aug 2016 08:00:55 +0000</pubDate>
				<category><![CDATA[Cyber for Financial Services]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[Hong Kong]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[règlementation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/en/?p=9477</guid>

					<description><![CDATA[<p>At the end of June 2016, while SWIFT (the worldwide financial messaging system) was disclosing substantial losses due to cyber-attacks, the authorities of Hong Kong were announcing new regulations for the financial institutions. During the 2016 edition of the Cyber...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/08/hong-kong-cybersecurity-program-cybersecurite-banking-industry/">Hong Kong launches a major cybersecurity program for its banking industry</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>At the end of June 2016, while SWIFT (the worldwide financial messaging system) was disclosing substantial losses due to cyber-attacks, the authorities of Hong Kong were announcing new regulations for the financial institutions.</em></p>
<p>During the<a href="http://www.cybersecuritysummithk.net/"> 2016 edition of the Cyber Security Summit</a> – one of the main local cybersecurity events – the Hong Kong Monetary Authority (HKMA) announced the <strong>launch of its CyberSecurity Fortification Initiative (CFI)</strong>, a multi-year approach to <strong>strengthen the security of local banks</strong>.</p>
<p>Here are the main points to keep in mind about this initiative, which brings best-of-breed cybersecurity international practices, but also an innovative approach to cyber threat intelligence.</p>
<p>&nbsp;</p>
<h2>A three-fold initiative to improve the level of security</h2>
<p>The CFI is an initiative on which the HKMA has been working to strengthen cyber-resilience (i.e. the capacity to resist/survive cyber-attacks). It targets all the Authorized Institutions<a target="_blank" rel="nofollow noopener noreferrer">[1]</a> (AIs), in other words the banks of Hong Kong. It is underpinned by three pillars:</p>
<h3>1. Cyber Resilience Assessment Framework</h3>
<p>This framework will have to be deployed by each bank, thus allowing the HKMA to “get a holistic view of the preparedness of individual AIs as well as the entire banking sector”. It consists of 3 steps:</p>
<div>
<ul>
<li><strong>Inherent risk assessment:</strong> an evaluation of an institution’s riskiness. It includes technological and business factors that will require a good understanding of both areas. The risk level will be rated as High, Medium or Low.</li>
</ul>
<ul>
<li><strong>Maturity assessment:</strong> an evaluation of the institution’s actual level of maturity in terms of cybersecurity</li>
</ul>
<ul>
<li><strong>Intelligence-led Cyber Attack Simulation Testing (iCAST), only for banks with High or Medium risk level</strong>. The goal is to simulate cyber-attacks not only from a technical perspective, but also taking into account the “people” and “process” elements.</li>
</ul>
<p>While all the details are not yet public, the first two steps are similar to the United States <a href="https://www.ffiec.gov/cyberassessmenttool.htm">FFIEC Cybersecurity Assessment Tool</a>, which has been deployed by many major banks since 2015. A matching has to be done between the risk level and the actual maturity level. In case of gaps, the bank will have to provide a roadmap to fill them.</p>
<p>iCAST is more innovative as a regulatory requirement, in the way that it does not only rely on penetration testing, but will also replicate real-life attacks, based on specific and up-to-date threat intelligence. This type of testing is referred to as “red team”. As of today, it is the most realistic way to test the actual security level of an organization.</p>
<h3>2. Professional Development Programme</h3>
<p>This programme aims at improving the overall skillset of security professionals, by implementing a certification scheme and trainings that will offer three levels of competence: “foundation”, “practitioner” and “expert”. The British <a href="https://www.euroclear.com/en.html">CREST </a>will be part of this professional development, and suitable arrangements will also be introduced to “ensure that relevant or equivalent experience and expertise in the cybersecurity field will be appropriately recognized”.</p>
<h3>3. Cyber Intelligence Sharing Platform</h3>
<p>In cyber-warfare, as in conventional warfare, threat intelligence has become key. Each company can develop its own skills and methods, but the very success of intelligence goes through sharing the information. Therefore, the HKMA is going to launch a Cyber Intelligence Sharing Platform, with access open to all the licensed banks in Hong Kong. Its goal will be to offer a secure and comfortable system to share relevant data, without compromising proprietary information.<strong><em> </em></strong></p>
<p>&nbsp;</p>
<h2>What are the next steps for banks?</h2>
<p>For banks in Hong Kong, few milestones were defined:</p>
<ul>
<li><strong>Starting from end of May 2016, a three-month consultation</strong> has been launched by HKMA with the banking industry, in order to have feedbacks and comments on a draft version of the risk-based Cyber Resilience Assessment Framework.</li>
</ul>
<ul>
<li>It is important to note that HKMA demands an <strong>involvement of the AIs’ Boards or senior management</strong>. The assessment will have to be conducted by “qualified professionals who possess the necessary knowledge and expertise”.</li>
</ul>
<ul>
<li>HKMA has worked with the professional and public organizations to <strong>roll-out the first training courses and set-up the Cyber Intelligence Sharing Platform</strong> by the end of 2016.</li>
</ul>
<p>&nbsp;</p>
<h2>Evolving standards in Hong Kong</h2>
<p>This move by the HKMA falls within a rapidly evolving regulatory context in Hong Kong. Several game-changing approaches will indeed shape the future of information security in the coming years. Among others, we can list the <a href="http://www.sfc.hk/edistributionWeb/gateway/EN/circular/doc?refNo=16EC17">recent circular on cybersecurity</a> that targets organizations regulated by the Securities and Futures Commission (SFC), and the <a href="http://www.reuters.com/article/us-finance-summit-privacy-idUSKCN0YB19Q">upcoming review of the data privacy laws</a>.</p>
<p>With around 200 banks, Hong Kong clearly takes the full measure of the cybersecurity challenge in order to keep its position as a leading financial hub in Asia.</p>
<p>&nbsp;</p>
<p>[1] An Authorized Institution in Hong Kong is an institution authorized under the Banking Ordinance to carry on the business of taking deposits. Hong Kong maintains a Three-tier Banking System, which comprises banks, restricted license banks and deposit-taking companies. Authorized Institutions are supervised by the HKMA.</p>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/08/hong-kong-cybersecurity-program-cybersecurite-banking-industry/">Hong Kong launches a major cybersecurity program for its banking industry</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>PERFORMANCE &#8211; Concept relativiste ou vecteur d’excellence ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2011/12/la-performance-concept-relativiste-ou-vecteur-dexcellence/</link>
		
		<dc:creator><![CDATA[GEneviEveLardon]]></dc:creator>
		<pubDate>Mon, 19 Dec 2011 09:35:56 +0000</pubDate>
				<category><![CDATA[Métiers - Stratégie & projets IT]]></category>
		<category><![CDATA[gains]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[programme]]></category>
		<category><![CDATA[simplicité]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=1021</guid>

					<description><![CDATA[<p>Quels que soient leurs noms, les programmes d’amélioration de la performance sont à la mode au sein des DSI. Ils sont d’autant plus à la mode que, magie de la performance, ces programmes finissent quasiment tous par réussir sur le...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2011/12/la-performance-concept-relativiste-ou-vecteur-dexcellence/">PERFORMANCE &#8211; Concept relativiste ou vecteur d’excellence ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Quels que soient leurs noms, les programmes d’amélioration de la performance sont à la mode au sein des DSI. Ils sont d’autant plus à la mode que, magie de la performance, ces programmes finissent quasiment tous par réussir sur le papier et font l’objet d’une communication et d’une autosatisfaction généralisée auprès des équipes concernées. Pourtant, cela cache souvent un concept des plus relativistes tant il est facile d’afficher dans le domaine des SI des résultats positifs à des décideurs et des métiers non spécialistes du domaine. Quelques idées pour faire du plan de performance 2012 de votre DSI un vecteur d’excellence permettant de délivrer une performance durable et objectivement mesurable par tous.</p>
<h4>Cibler le bon levier de performance</h4>
<p>Les leviers de performance existent en nombre : réduction des coûts, <em>cloud</em>, évolution des relations MOA/MAE, développement du savoir-faire économique au sein des DSI, poursuite de l’<em>offshore</em>, évolution des usages, etc. Une des clés de la réussite d’un plan de performance sera le choix des bons leviers. Ces leviers doivent être limités en nombre et doivent concerner des périmètres de maturité moyenne pour la DSI. Les périmètres maintes fois optimisés génèreront des gains faibles en volume et les périmètres peu matures ne permettront pas de gain à court terme, les actions étant plus compliquées à mettre en œuvre que sur un périmètre maîtrisé.</p>
<h4>Responsabiliser l’ensemble des acteurs</h4>
<p>La responsabilisation des acteurs du plan de performance est un sujet délicat parce qu’à court terme, les actions proposées vont aller à l’encontre des intérêts desdits acteurs : réduction des moyens, changement des modes de fonctionnement, mise en lumière des dysfonctionnements, etc. Il faut donc s’assurer que les acteurs soient responsabilisés sur l’atteinte des objectifs globaux du plan de performance et non sur des sous périmètres pouvant entraîner des actions locales ayant un effet finalement contraire aux objectifs globaux.</p>
<h4>Choisir des critères de mesures simples et opposables</h4>
<p>Bon nombre de plans de performance sont analysés à l’aulne de critères peu opposables car décorrélés des indicateurs de suivi de l’activité de la DSI. Le biais est évident et tout à fait humain, les acteurs en charge de la mesure passeront plus de temps à chercher comment faire évoluer positivement l’indicateur plutôt qu’à réaliser les actions de performance identifiées. Typiquement, la mesure de gains économiques décorrélés du résultat de la DSI &#8211; auditable dans les comptes &#8211; est rarement pertinente parce que directement dépendante de la méthodologie de calcul des gains (prise en compte des coûts évités, euros constants versus euros courants, etc.). Ce type d’approche peut par exemple conduire à afficher, en toute bonne foi, des gains théoriques conséquents mais une augmentation de la facture pour le client ! <em>A contrario</em>, un classique objectif de réduction des coûts par rapport à ceux inscrits au budget est un objectif simple, mesurable et opposable.</p>
<p>Le facteur clé de la réussite d’un plan de performance, c’est donc sa simplicité : un périmètre circonscrit et une responsabilisation sur un objectif global, opposable et mesurable. Cette simplicité est la garantie de faire d’un plan de performance un vecteur d’excellence pour les clients et pour l’ensemble des équipes impliquées. Pourquoi ne pas le vérifier dès 2012 ?</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2011/12/la-performance-concept-relativiste-ou-vecteur-dexcellence/">PERFORMANCE &#8211; Concept relativiste ou vecteur d’excellence ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
