Tudor IT Process Assessment

Last updated

Tudor IT Process Assessment (TIPA) is a methodological framework for process assessment. Its first version was published in 2003 by the Public Research Centre Henri Tudor based in Luxembourg. TIPA is now a registered trademark of the Luxembourg Institute of Science and Technology (LIST). TIPA offers a structured approach to determine process capability compared to recognized best practices. TIPA also supports process improvement by providing a gap analysis and proposing improvement recommendations. [1]

Contents

TIPA combines domain-specific process models with the generic TIPA Process Assessment Method. The TIPA framework structure.PNG
TIPA combines domain-specific process models with the generic TIPA Process Assessment Method.

TIPA uses the generic approach for process assessment published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in ISO/IEC 15504 [2] – Process Assessment (now ISO/IEC 33000). The ISO/IEC 15504-2 requirements on performing assessments are structured and documented in the TIPA Assessment Process. Additional guidance, contextual advice and return of experience complete the TIPA Process Assessment Method and support the usability of the TIPA framework. The TIPA Process Assessment Method (TIPA) can be used to assess processes from any field of activity.

The TIPA framework is supported by an exhaustive toolbox that provides templates and tools for every single step of the assessment process. It can be customized to any application domain.

Overview

A process assessment is conducted to get a clear view of the current practices in an organization in a particular domain (e.g. the IT service management domain in TIPA for ITIL). The goal is to compare these practices to a renowned reference so that the current status of the processes can be measured and appropriate suggestions for process improvement can be made.

The gap analysis helps identify SWOTs, get a clear picture of the current state and identify improvement recommendations.

Interviews with process actors are used to understand the way the process is performed and a process maturity rating scale is used to measure the gap between the frame of reference and the field reality. An assessment project starts with a clear goal statement to define the scope of the project. The project involves a series of roles who take part in the assessment. The project is organized in 6 phases. It is supported by several tools (templates and spreadsheets) provided in the TIPA Toolbox. [3]

History

In 2002, the first cases of adoption of ITIL were observed on the Luxembourg market. At the same period, the ISO/IEC TR 15504 Process Assessment standard series was upgraded towards the creation of a generic standard for process assessment, enabling the assessment processes in any kind of domain. Researchers from CRP Henri Tudor, being active members of the ISO working group in charge of that transformation within ISO/IEC JTC 1/SC 7, got the idea to apply and experiment this new generic assessment framework to both software and IT operation processes.

This led to the definition of the AIDA (Assessment and Improvement integrateD Approach) research & development project in 2003, aiming at applying a common method for the definition and assessment of processes for both the software development and IT operations sides. The project resulted in the creation of a structured process assessment method for IT Service Management based on ITIL. That method was fully compatible with the method described in ISO/IEC 15504 originally designed to assess software development processes.

The first Process Assessment model for ITIL v2 was developed and experimented during the years 2004-2005 in partnership with ITIL experts. More experimentation took place in the following years locally in Luxembourg and several other regions of the world. In 2009 AIDA was rebranded as TIPA (Tudor IT Process Assessment) and this brand officially registered. [4] The complete method was published in the book “ITSM Process Assessment Supporting ITIL“, released in 2009. A major upgrade of TIPA for ITIL took place in 2013 to align the framework with ITIL 2011. That upgrade has also been the opportunity to improve the overall quality of the framework based on the 8 years of experience by Tudor and historical users of the method. The last upgrade was done in March 2014 to introduce classes of assessment aligned with the requirements of the ISO/IEC 3300x [5] series, evolution of the ISO/IEC 15504.

On 1 January 2015, the Public Research Centre Henri Tudor and the Public Research Center Gabriel Lippmann merged to form a new RTO (Research and Technology Organisation), the Luxembourg Institute of Science & Technology (LIST). The current original TIPA team continues to maintain and develop content around TIPA as part of the LIST.

Applications

TIPA for ITIL

TIPA for ITIL is the application of the TIPA framework to the IT Service Management domain. It applies the TIPA assessment method to the IT Service Management best practices described in ITIL 2011 [6] [7] [8] [9] [10]

ISO/IEC 15504

Processes are defined by 9 attributes. The definition of the attributes helps understanding the process capability. The ISO IEC 15504 Capability Scale.PNG
Processes are defined by 9 attributes. The definition of the attributes helps understanding the process capability.

TIPA is applying the assessment approach defined in ISO/IEC 15504, which can be used:

a) By or on behalf of an organization with the objective of understanding the state of its own processes for process improvement;
b) By or on behalf of an organization with the objective of determining the suitability of its own processes for a particular requirement or class of requirements;
c) By or on behalf of one organization with the objective of determining the suitability of another organization’s processes for a particular contract or class of contracts.

TIPA has structured its assessment method targeting mostly the first application area of ISO/IEC 15504 (process improvement) but supports the two other ones also.

TIPA is using the rating scale and capability levels defined in the ISO/IEC 15504 measurement framework. The four point ordinal rating scale (Not achieved, Partially achieved, Largely achieved and Fully achieved) is used to express the levels of achievement of the process attributes.

ITIL

ITIL is a set of best practices for IT service management (ITSM) that focus on aligning IT services with the needs of business. ITIL has structured these best practices as processes. TIPA for ITIL enables to assess these processes. But ISO/IEC 15504 process assessment is to be performed against a compliant process assessment model, which combines the description of the process in terms of process purpose and outcomes, with performance and capability indicators. The TIPA process assessment model for ITIL contains that structured description of the ITIL processes. It was developed applying requirements engineering techniques that support the quality characteristics expected from a compliant process model (traceability, comprehensiveness, usability, assessability).

TIPA specifics

TIPA:

TIPA Components

6 phases

An assessment is structured as a project, each phase being a prerequisite for the next one. Some activities may be optional for Class 3 assessments. The TIPA Assessment Process.PNG
An assessment is structured as a project, each phase being a prerequisite for the next one. Some activities may be optional for Class 3 assessments.

Definition phase

During the definition phase, the main objectives are to define the scope of the assessment, to identify the key actors, to agree on a service offer and to agree on the assessment scope agreement.

Preparation phase

In this phase, the objective is to discover the organizational context, and then to do an assessment planning and define the organization (by preparing the Assessment team, the supporting documents used during the assessment and the people who will be interviewed).

Assessment phase

The phase is the key of the process assessment, during which interviews are done and documents reviewed to enable process rating and process capability level determination.

Analysis phase

After the Assessment phase the collected information are analysed and a SWOT analysis is performed before making improvement recommendations

Result presentation phase

The results are presented to the relevant stakeholders, and the detailed assessment report is rendered.

Assessment closure phase

The assessment project can then be closed.

Roles

The six phases are supervised by at one Lead Assessor and are implemented by one or several Assessor(s).

TIPA Assessor: he conducts the interviews and analyses the results to draw conclusions on the assessed process maturity.

TIPA Lead Assessor: he is accountable for the compliance of the method delivered and for the assessment results. He is the project manager of the assessment project. A TIPA assessment cannot be done without a Lead Assessor.

The TIPA classes of assessment

Like in the Standard CMMI Appraisal Method for Process Improvement (SCAMPI), there are three different classes of assessment in TIPA. A TIPA assessment can be performed using Class 1, 2 or 3 depending on the level of confidence required on the assessment results, and on the amount of resources available to perform that assessment. TIPA Class 1 requires more resources than TIPA Class 2 and TIPA Class 2 requires more resource than TIPA Class 3.

TIPA Class 1 is the most reliable class, it allow having a very high level of objectivity, rigor and confidence in the assessment result thanks to a large collection of evidence, more than the two other classes.

TIPA Class 2 corresponds to the original TIPA assessment method; it is a good balance between required resources and the usability of the assessment results.

TIPA Class 3 is the less exhaustive assessment method. It requires less resources, rating evidence and time than the two other classes, but also provides limited assessment results with minimal process analysis.

Comparative table of assessment classes

TIPA Class 1TIPA Class 2TIPA Class 3
Management of the assessment project1 certified TIPA Lead Assessor required
Number of Assessors

(per process)

2 certified TIPA Assessors (one can be the project’s Lead Assessor)2 certified TIPA Assessors (one can be the project’s Lead Assessor)1 certified TIPA Assessor (who can be the project’s Lead Assessor)
Independence of the Assessment TeamAssessment Team fully independent from the organization being assessedAssessment Team with separation of responsibility from the personnel in the organization being assessedNo requirement on the independence of the Assessment Team
Minimum number of interviews (per process)432
Rating of interviews1 rating per interview1 rating per interview1 single rating allowed for all interviews
Level of rigor++++++++
Level of confidence+++++++
Repeatability+++++++
Costs++++++
Publication of resultsCertificateCertificateCertificate

Tools

The TIPA toolbox gathers methodological and office tools to support all phases of a TIPA assessment. All TIPA Certified Assessors can use this toolbox to perform their TIPA assessment. The TIPA toolbox contains:

TIPA Certifications

The transfer of TIPA for ITIL on the market is supported by a training and certification program run in partnership between ITpreneurs (training provider) and the Luxembourg Institute of Science and Technology (certification authority). Certifications available are: TIPA Assessor for ITIL and TIPA Lead Assessor.

CMMI

CMMI-SVC can be considered as the nearest competitor of TIPA, but differences remain. Indeed, CMMI-SVC targets assessment of services in general whereas TIPA for ITIL concentrates its efforts on IT services. CMMI supports both process capability and organisational maturity.

ISO/IEC 20000

ISO/IEC 20000 is the international standard that allows companies to demonstrate their excellence in IT management through the certification of their IT service management system. TIPA for ITIL can help organizations get prepared for ISO/IEC 20000 certification as TIPA for ITIL covers a large part of the process used in ISO/IEC 20000, but provides more support for the assessment and improvement of these processes.

ISO/IEC 33000

ISO/IEC 33000 is an evolution of ISO/IEC 15504 published at the end of February 2015. The recent works on TIPA, including the introduction of the classes of assessment are aligned with the works conducted at ISO on the ISO/IEC 33000 series.

Partnership

TIPA was developed by Public Research Centre Henri Tudor thanks to the support of several partners amongst which:

Limitations

TIPA has renamed process capability as process maturity, which may cause confusion.

TIPA for ITIL does not allow making an assessment of organisational maturity. Moreover, no benchmarking data is available so far.[ citation needed ]

Related Research Articles

Information technology (IT)governance is a subset discipline of corporate governance, focused on information technology (IT) and its performance and risk management. The interest in IT governance is due to the ongoing need within organizations to focus value creation efforts on an organization's strategic objectives and to better manage the performance of those responsible for creating this value in the best interest of all stakeholders. It has evolved from The Principles of Scientific Management, Total Quality Management and ISO 9001 Quality management system.

ISO/IEC 15504Information technology – Process assessment, also termed Software Process Improvement and Capability dEtermination (SPICE), is a set of technical standards documents for the computer software development process and related business management functions. It is one of the joint International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) standards, which was developed by the ISO and IEC joint subcommittee, ISO/IEC JTC 1/SC 7.

Information technology service management (ITSM) are the activities performed by an organization to design, build, deliver, operate and control information technology (IT) services offered to customers.

Capability Maturity Model Integration (CMMI) is a process level improvement training and appraisal program. Administered by the CMMI Institute, a subsidiary of ISACA, it was developed at Carnegie Mellon University (CMU). It is required by many U.S. Government contracts, especially in software development. CMU claims CMMI can be used to guide process improvement across a project, division, or an entire organization.

Quality management ensures that an organization, product or service consistently functions well. It has four main components: quality planning, quality assurance, quality control and quality improvement. Quality management is focused not only on product and service quality, but also on the means to achieve it. Quality management, therefore, uses quality assurance and control of processes as well as products to achieve more consistent quality. Quality control is also part of quality management. What a customer wants and is willing to pay for it, determines quality. It is a written or unwritten commitment to a known or unknown consumer in the market. Quality can be defined as how well the product performs its intended function.

COBIT is a framework created by ISACA for information technology (IT) management and IT governance.

ISO/IEC 20000 is the international standard for IT service management. It was developed in 2005 by ISO/IEC JTC1/SC7 and revised in 2011 and 2018. It was originally based on the earlier BS 15000 that was developed by BSI Group.

Capability Immaturity Model (CIMM) in software engineering is a parody acronym, a semi-serious effort to provide a contrast to the Capability Maturity Model (CMM). The Capability Maturity Model is a five point scale of capability in an organization, ranging from random processes at level 1 to fully defined, managed and optimized processes at level 5. The ability of an organization to carry out its mission on time and within budget is claimed to improve as the CMM level increases.

The ISO/IEC 15288Systems and software engineering — System life cycle processes is a technical standard in systems engineering which covers processes and lifecycle stages, developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Planning for the ISO/IEC 15288:2002(E) standard started in 1994 when the need for a common systems engineering process framework was recognized.

ITIL security management describes the structured fitting of security into an organization. ITIL security management is based on the ISO 27001 standard. "ISO/IEC 27001:2005 covers all types of organizations. ISO/IEC 27001:2005 specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented Information Security Management System within the context of the organization's overall business risks. It specifies requirements for the implementation of security controls customized to the needs of individual organizations or parts thereof. ISO/IEC 27001:2005 is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties."

A maturity model is a framework for measuring an organization's maturity, or that of a business function within an organization, with maturity being defined as a measurement of the ability of an organization for continuous improvement in a particular discipline. The higher the maturity, the higher will be the chances that incidents or errors will lead to improvements either in the quality or in the use of the resources of the discipline as implemented by the organization.

In software engineering, a software development process or software development life cycle (SDLC) is a process of planning and managing software development. It typically involves dividing software development work into smaller, parallel, or sequential steps or sub-processes to improve design and/or product management. The methodology may include the pre-definition of specific deliverables and artifacts that are created and completed by a project team to develop or maintain an application.

Automotive SPICE is a maturity model adapted for the automotive industry. It assesses the maturity of development processes for electronic and software-based systems. It is based on an initiative of the Special Interest Group Automotive and the Quality Management Center (QMC) in the German Association of the Automotive Industry (VDA).

<span class="mw-page-title-main">Axios Systems</span> IT Management Software Vendor

Axios Systems is a provider of Service Desk, IT Service Management and IT Asset Management software. The assyst enterprise application suite was the first to support ITIL best practices.

IEC 62443 is an international series of standards that address cybersecurity for operational technology in automation and control systems. The standard is divided into different sections and describes both technical and process-related aspects of automation and control systems cybersecurity.

The Service Design Package (SDP) contains the core documentation of a service and is attached to its entry in the ITIL Service Portfolio.

The Service Portfolio is described in the ITIL books Service Strategy and Service Design. The Service Portfolio is the core repository for all information for all services in an organization. Each service is listed along with its current status and history. The main descriptor in the Service Portfolio is the Service Design Package (SDP).

FitSM is the name for a family of standards for lightweight IT service management (ITSM).

The Information Technology Infrastructure Library (ITIL) is a set of practices and a framework for IT activities such as IT service management (ITSM) and IT asset management (ITAM) that focus on aligning IT services with the needs of the business.

ISO/IEC 33001Information technology - Process assessment - Concepts and terminology is a set of technical standards documents for the computer software development process and related business management functions.

References

  1. "Assess and Improve Your IT Processes with the TIPA Framework".
  2. ISO_IEC 15504-2
  3. The TIPA toolbox
  4. TIPA® is a Registered Trade Mark of the Centre de Recherche Public Henri Tudor.
  5. ISO_IEC 33002
  6. FSM. David Cannon (2011). ITIL Service Strategy 2011 Edition. The Stationery Office. ISBN   978-0113313044.
  7. Lou Hunnebeck (2011). ITIL Service Design. The Stationery Office. ISBN   978-0113313051.
  8. Stuart Rance (2011). ITIL Service Transition. The Stationery Office. ISBN   978-0113313068.
  9. Randy A. Steinberg (2011). ITIL Service Operation. The Stationery Office. ISBN   978-0113313075.
  10. Vernon Lloyd (2011). ITIL Continual Service Improvement. The Stationery Office. ISBN   978-0113313082.
  11. Van Haren Publishing
  12. ITpreneurs

Bibliography