SlideShare uma empresa Scribd logo
1 de 4
Baixar para ler offline
Seguridad de la Información: Criptografía Cobit vs ITIL
Página 1 de 4
Sponsored by:
This story appeared on Network World Fusion at
http://www.nwfusion.com/research/2005/011005cobit.html
Feature /
Best practice, practice, practice
COBIT is a proven standard that can help with compliance, business accountability and
auditing.
By John Morency
Network World, 01/10/05
In general, IT executives implement best practices because they need to increase IT
predictability and efficiency, reduce support costs, improve customer service quality or
meet regulatory requirements.
The two most well-known standards - the IT Infrastructure Library (ITIL) and the
Control Objectives for IT (COBIT) - have existed for at least 10 years, support a broad
range of management services, are sponsored by very well-respected organizations
(COBIT by the Information Systems Audit and Control Organization and ITIL by the IT
Service Management Forum) and have been implemented by thousands of organizations
of all sizes.
However, COBIT and ITIL are very different in their orientation, definition, classes of
problems they address and the specific implications regarding "implementation."
The COBIT standard, which the IT Auditors Association first released in 1996, was
designed with business accountability and auditability in mind. For example, a frequent
application of COBIT is control definition that helps businesses comply with federal
government mandates, such as the Sarbanes-Oxley Act.
Seguridad de la Información: Criptografía Cobit vs ITIL
Página 2 de 4
Think of a control as a logical safety valve designed to ensure that a specific operation
that supports the creation of production financial data executes as intended, without
introducing any erroneous or fraudulent data that could compromise the quality of the
company's financial reporting.
An example is a set of traceable (and auditable) flows across one or more production
applications that reliably increase product inventory when shipments are received from
suppliers and decrease product inventory when finished products are shipped to
customers. An example of an IT control is the installation of anti-virus software on
every new desktop that is installed within a specific facility, along with the ongoing
distribution of new virus signatures to each licensed desktop.
IT control definition, testing and progress measurement are task categories that are
natural COBIT strengths. The COBIT model is very specific in its definition of the
processes and the auditable controls that need to be in place to ensure reliable and
predictable IT processes.
The processes defined in COBIT are grouped into four separate domains that align with
the IT implementation cycle. They are: Planning and Organization, Acquisition and
Implementation, Delivery and Support, and Monitoring.
Each of the 34 processes also has its own assigned number within its parent domain for
identification. For example, Problem Management controls and their associated metrics
are the 10th process defined in the Delivery and Support domain, while Change
Management is the sixth process defined within the Acquisition and Implementation
domain.
The definition of each COBIT process also clearly states the control objectives of the
process, the critical success factors needed to successfully implement the process,
specific quantitative metrics that can be used to measure process quality improvement
and a process-specific maturity model that defines the process functionality that
progresses from predominantly manual to fully automated and optimized.
In addition, process-specific success factors and quantitative improvement metrics
(referred to as the Key Goal Indicators and Key Performance Indicators) are also
defined. These can be used as part of a continuous improvement process.
As defined by its authors, COBIT's Management Guidelines are broadly applicable to
all major product segments (network, server, storage, application and desktop) within
the networked application infrastructure. They are also action-oriented and very relevant
to addressing a number of key questions that often are asked when the focus is
improving IT governance. This includes:
• How far should we go, and does the benefit justify the cost?
• What are the indicators of good performance?
• What are the critical success factors?
Seguridad de la Información: Criptografía Cobit vs ITIL
Página 3 de 4
• What are the risks of not achieving our objectives?
• What do others do? How do we measure and compare?
Specific guidelines for support process maturity improvement can help answer some of
these questions by providing an objective and measurable set of criteria for assessing
the state of current processes, and determining the steps required to achieve and
quantify measurable improvement.
1 COBIT vs. ITIL
COBIT and ITIL are more complementary than they are competitive.
COBIT focuses on the definition, implementation, auditing, measurement and
improvement of controls for specific processes that span the entire IT implementation
life cycle. As such, it is an excellent reference model for IT governance across the entire
implementation life cycle.
The primary focus of ITIL is to provide best practice definitions and criteria for
operations management. More specifically, ITIL primarily focuses on defining the
functional, operational and organizational attributes that need to be in place for
operations management to be fully optimized in two key categories. These categories
are called Service Support Management and Service Delivery Management, each of
which has a number of supporting subcategories.
The management subcategories for Service Support Management include Service Desk,
Incident, Problem, Configuration, Change and Release management, while those for
Service Delivery Management include Service Level, Financial, Capacity, Service
Continuity and Availability.
Each subcategory definition includes best practice criteria for many areas, including
organizational support, cross management component integration, management
reporting, product capability, implementation quality and customer service quality.
If your goal is improving the quality and measurability of IT governance across the
entire networked application implementation life cycle or implementing a control
system for improved regulatory compliance, COBIT probably would be a more
effective choice.
On the other hand, if the objective is to continuously improve IT operations efficiency
and IT customer service quality, ITIL would probably be the better bet.
However, one should not look at these comparisons as a COBIT vs. ITIL analysis. It's
important to understand the design center differences of each approach and adapt them
as needed to meet the specific requirements of your own unique environment.
Seguridad de la Información: Criptografía Cobit vs ITIL
Página 4 de 4
Given the substantial implementation experience with both standards that exists in the
industry today, you'll have plenty of peers to call on for advice. The even better news is
that, unlike hardware or software products, their acquisition cost is extremely low.
Morency is a managing director of Transitional Data Services, a service provider in
Hopkinton, Mass., that specializes in IT orchestration for small and midsize companies.
He can be reached at jmorency@transitionaldata.com.
RELATED LINKS
All contents copyright 1995-2003 Network World, Inc. http://www.nwfusion.com

Mais conteúdo relacionado

Mais procurados

Cobit, itil and cmmi - a tutorial
Cobit, itil and cmmi  - a tutorialCobit, itil and cmmi  - a tutorial
Cobit, itil and cmmi - a tutorialseveman
 
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change ManagementITIL Indonesia
 
COBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated FrameworkCOBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated FrameworkMohammad Reda Katby
 
Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811faau09
 
COBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-EndCOBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-EndMohammad Reda Katby
 
EA foundations (Views, Repository, Artifacts and Metamodel)
EA foundations (Views, Repository, Artifacts and Metamodel)EA foundations (Views, Repository, Artifacts and Metamodel)
EA foundations (Views, Repository, Artifacts and Metamodel)Mohamed Zakarya Abdelgawad
 
ITIL With Information Security
ITIL With Information SecurityITIL With Information Security
ITIL With Information Securityvikasraina
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)Muhammad Azmy
 
Cobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder NeedsCobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder NeedsMohammad Reda Katby
 
Iti Lprocessmgmt
Iti LprocessmgmtIti Lprocessmgmt
Iti Lprocessmgmtparamalways
 
COBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From ManagementCOBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From ManagementMohammad Reda Katby
 
Global Artificial Intelligence (AI) Index
Global Artificial Intelligence (AI) IndexGlobal Artificial Intelligence (AI) Index
Global Artificial Intelligence (AI) IndexMohammad Reda Katby
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Meghna Verma
 
(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...
(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...
(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...ITIL Indonesia
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachMohammad Reda Katby
 
SDLC Control
SDLC ControlSDLC Control
SDLC Controlbenji00
 
In Automated Controls It’s No Longer the Traditional Build vs. Buy
In Automated Controls It’s No Longer the Traditional Build vs. BuyIn Automated Controls It’s No Longer the Traditional Build vs. Buy
In Automated Controls It’s No Longer the Traditional Build vs. BuyMelissa Luongo
 
WLS Services Brochure March 2013
WLS Services Brochure March 2013WLS Services Brochure March 2013
WLS Services Brochure March 2013Mike Wright
 

Mais procurados (20)

Cobit, itil and cmmi - a tutorial
Cobit, itil and cmmi  - a tutorialCobit, itil and cmmi  - a tutorial
Cobit, itil and cmmi - a tutorial
 
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
 
COBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated FrameworkCOBIT 5 - Principal 3 Applying A Single Integrated Framework
COBIT 5 - Principal 3 Applying A Single Integrated Framework
 
Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811
 
COBIT5 Introduction
COBIT5 IntroductionCOBIT5 Introduction
COBIT5 Introduction
 
COBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-EndCOBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-End
 
EA foundations (Views, Repository, Artifacts and Metamodel)
EA foundations (Views, Repository, Artifacts and Metamodel)EA foundations (Views, Repository, Artifacts and Metamodel)
EA foundations (Views, Repository, Artifacts and Metamodel)
 
ITIL With Information Security
ITIL With Information SecurityITIL With Information Security
ITIL With Information Security
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
 
Cobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder NeedsCobit5 Principal 1 Meeting Stakeholder Needs
Cobit5 Principal 1 Meeting Stakeholder Needs
 
Iti Lprocessmgmt
Iti LprocessmgmtIti Lprocessmgmt
Iti Lprocessmgmt
 
COBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From ManagementCOBIT 5 - Principal 5 Separating Governance From Management
COBIT 5 - Principal 5 Separating Governance From Management
 
Global Artificial Intelligence (AI) Index
Global Artificial Intelligence (AI) IndexGlobal Artificial Intelligence (AI) Index
Global Artificial Intelligence (AI) Index
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799
 
COBIT 5.0 vs COBIT 2019
COBIT 5.0 vs COBIT 2019COBIT 5.0 vs COBIT 2019
COBIT 5.0 vs COBIT 2019
 
(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...
(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...
(ONLINE) ITIL Indonesia Community – Meetup “Modern IT Service Management Tran...
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic Approach
 
SDLC Control
SDLC ControlSDLC Control
SDLC Control
 
In Automated Controls It’s No Longer the Traditional Build vs. Buy
In Automated Controls It’s No Longer the Traditional Build vs. BuyIn Automated Controls It’s No Longer the Traditional Build vs. Buy
In Automated Controls It’s No Longer the Traditional Build vs. Buy
 
WLS Services Brochure March 2013
WLS Services Brochure March 2013WLS Services Brochure March 2013
WLS Services Brochure March 2013
 

Semelhante a Cobi t vs itil

Semelhante a Cobi t vs itil (20)

IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance Framework
 
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
 
Using ITIL 4 and IT4IT together
Using ITIL 4 and IT4IT togetherUsing ITIL 4 and IT4IT together
Using ITIL 4 and IT4IT together
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
Cobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiCobit 4.1 ivooktavianti
Cobit 4.1 ivooktavianti
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
ITIL , DevOps and IT4IT
ITIL , DevOps and IT4ITITIL , DevOps and IT4IT
ITIL , DevOps and IT4IT
 
Itil 2
Itil 2Itil 2
Itil 2
 
CISSPills #3.02
CISSPills #3.02CISSPills #3.02
CISSPills #3.02
 
IT Management Toolkit - ITIL Is Not Enough
IT Management Toolkit - ITIL Is Not EnoughIT Management Toolkit - ITIL Is Not Enough
IT Management Toolkit - ITIL Is Not Enough
 
A Beginner's Guide to Navigating the Frameworks.pdf
 A Beginner's Guide to Navigating the Frameworks.pdf A Beginner's Guide to Navigating the Frameworks.pdf
A Beginner's Guide to Navigating the Frameworks.pdf
 
Dit yvol3iss16
Dit yvol3iss16Dit yvol3iss16
Dit yvol3iss16
 
Itil the basics
Itil the basicsItil the basics
Itil the basics
 
COBIT 5 FAQ
COBIT 5 FAQCOBIT 5 FAQ
COBIT 5 FAQ
 
Cobit 4.1 indri
Cobit 4.1 indriCobit 4.1 indri
Cobit 4.1 indri
 
IT frameworks
IT frameworksIT frameworks
IT frameworks
 
Audit rizkie hafizzah
Audit rizkie hafizzahAudit rizkie hafizzah
Audit rizkie hafizzah
 
02. cobit 41 dan iso 17799
02. cobit 41 dan iso 1779902. cobit 41 dan iso 17799
02. cobit 41 dan iso 17799
 
CobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast SeminarCobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast Seminar
 
Cobi t 4.1-brochure
Cobi t 4.1-brochureCobi t 4.1-brochure
Cobi t 4.1-brochure
 

Último

(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICSHARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICSRajkumarAkumalla
 
OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...
OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...
OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...Soham Mondal
 
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur EscortsCall Girls in Nagpur High Profile
 
KubeKraft presentation @CloudNativeHooghly
KubeKraft presentation @CloudNativeHooghlyKubeKraft presentation @CloudNativeHooghly
KubeKraft presentation @CloudNativeHooghlysanyuktamishra911
 
High Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur EscortsHigh Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur EscortsCall Girls in Nagpur High Profile
 
(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escortsranjana rawat
 
Introduction to IEEE STANDARDS and its different types.pptx
Introduction to IEEE STANDARDS and its different types.pptxIntroduction to IEEE STANDARDS and its different types.pptx
Introduction to IEEE STANDARDS and its different types.pptxupamatechverse
 
Top Rated Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...
Top Rated  Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...Top Rated  Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...
Top Rated Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...Call Girls in Nagpur High Profile
 
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130Suhani Kapoor
 
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...Christo Ananth
 
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...roncy bisnoi
 
result management system report for college project
result management system report for college projectresult management system report for college project
result management system report for college projectTonystark477637
 
College Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
College Call Girls Nashik Nehal 7001305949 Independent Escort Service NashikCollege Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
College Call Girls Nashik Nehal 7001305949 Independent Escort Service NashikCall Girls in Nagpur High Profile
 
(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
UNIT-II FMM-Flow Through Circular Conduits
UNIT-II FMM-Flow Through Circular ConduitsUNIT-II FMM-Flow Through Circular Conduits
UNIT-II FMM-Flow Through Circular Conduitsrknatarajan
 
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICSAPPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICSKurinjimalarL3
 

Último (20)

(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANJALI) Dange Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICSHARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
 
OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...
OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...
OSVC_Meta-Data based Simulation Automation to overcome Verification Challenge...
 
Water Industry Process Automation & Control Monthly - April 2024
Water Industry Process Automation & Control Monthly - April 2024Water Industry Process Automation & Control Monthly - April 2024
Water Industry Process Automation & Control Monthly - April 2024
 
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
 
KubeKraft presentation @CloudNativeHooghly
KubeKraft presentation @CloudNativeHooghlyKubeKraft presentation @CloudNativeHooghly
KubeKraft presentation @CloudNativeHooghly
 
High Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur EscortsHigh Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Meera Call 7001035870 Meet With Nagpur Escorts
 
(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(MEERA) Dapodi Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
 
Introduction to IEEE STANDARDS and its different types.pptx
Introduction to IEEE STANDARDS and its different types.pptxIntroduction to IEEE STANDARDS and its different types.pptx
Introduction to IEEE STANDARDS and its different types.pptx
 
Top Rated Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...
Top Rated  Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...Top Rated  Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...
Top Rated Pune Call Girls Budhwar Peth ⟟ 6297143586 ⟟ Call Me For Genuine Se...
 
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
 
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
 
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
 
result management system report for college project
result management system report for college projectresult management system report for college project
result management system report for college project
 
College Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
College Call Girls Nashik Nehal 7001305949 Independent Escort Service NashikCollege Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
College Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
 
Roadmap to Membership of RICS - Pathways and Routes
Roadmap to Membership of RICS - Pathways and RoutesRoadmap to Membership of RICS - Pathways and Routes
Roadmap to Membership of RICS - Pathways and Routes
 
(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(PRIYA) Rajgurunagar Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
UNIT-II FMM-Flow Through Circular Conduits
UNIT-II FMM-Flow Through Circular ConduitsUNIT-II FMM-Flow Through Circular Conduits
UNIT-II FMM-Flow Through Circular Conduits
 
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICSAPPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
 

Cobi t vs itil

  • 1. Seguridad de la Información: Criptografía Cobit vs ITIL Página 1 de 4 Sponsored by: This story appeared on Network World Fusion at http://www.nwfusion.com/research/2005/011005cobit.html Feature / Best practice, practice, practice COBIT is a proven standard that can help with compliance, business accountability and auditing. By John Morency Network World, 01/10/05 In general, IT executives implement best practices because they need to increase IT predictability and efficiency, reduce support costs, improve customer service quality or meet regulatory requirements. The two most well-known standards - the IT Infrastructure Library (ITIL) and the Control Objectives for IT (COBIT) - have existed for at least 10 years, support a broad range of management services, are sponsored by very well-respected organizations (COBIT by the Information Systems Audit and Control Organization and ITIL by the IT Service Management Forum) and have been implemented by thousands of organizations of all sizes. However, COBIT and ITIL are very different in their orientation, definition, classes of problems they address and the specific implications regarding "implementation." The COBIT standard, which the IT Auditors Association first released in 1996, was designed with business accountability and auditability in mind. For example, a frequent application of COBIT is control definition that helps businesses comply with federal government mandates, such as the Sarbanes-Oxley Act.
  • 2. Seguridad de la Información: Criptografía Cobit vs ITIL Página 2 de 4 Think of a control as a logical safety valve designed to ensure that a specific operation that supports the creation of production financial data executes as intended, without introducing any erroneous or fraudulent data that could compromise the quality of the company's financial reporting. An example is a set of traceable (and auditable) flows across one or more production applications that reliably increase product inventory when shipments are received from suppliers and decrease product inventory when finished products are shipped to customers. An example of an IT control is the installation of anti-virus software on every new desktop that is installed within a specific facility, along with the ongoing distribution of new virus signatures to each licensed desktop. IT control definition, testing and progress measurement are task categories that are natural COBIT strengths. The COBIT model is very specific in its definition of the processes and the auditable controls that need to be in place to ensure reliable and predictable IT processes. The processes defined in COBIT are grouped into four separate domains that align with the IT implementation cycle. They are: Planning and Organization, Acquisition and Implementation, Delivery and Support, and Monitoring. Each of the 34 processes also has its own assigned number within its parent domain for identification. For example, Problem Management controls and their associated metrics are the 10th process defined in the Delivery and Support domain, while Change Management is the sixth process defined within the Acquisition and Implementation domain. The definition of each COBIT process also clearly states the control objectives of the process, the critical success factors needed to successfully implement the process, specific quantitative metrics that can be used to measure process quality improvement and a process-specific maturity model that defines the process functionality that progresses from predominantly manual to fully automated and optimized. In addition, process-specific success factors and quantitative improvement metrics (referred to as the Key Goal Indicators and Key Performance Indicators) are also defined. These can be used as part of a continuous improvement process. As defined by its authors, COBIT's Management Guidelines are broadly applicable to all major product segments (network, server, storage, application and desktop) within the networked application infrastructure. They are also action-oriented and very relevant to addressing a number of key questions that often are asked when the focus is improving IT governance. This includes: • How far should we go, and does the benefit justify the cost? • What are the indicators of good performance? • What are the critical success factors?
  • 3. Seguridad de la Información: Criptografía Cobit vs ITIL Página 3 de 4 • What are the risks of not achieving our objectives? • What do others do? How do we measure and compare? Specific guidelines for support process maturity improvement can help answer some of these questions by providing an objective and measurable set of criteria for assessing the state of current processes, and determining the steps required to achieve and quantify measurable improvement. 1 COBIT vs. ITIL COBIT and ITIL are more complementary than they are competitive. COBIT focuses on the definition, implementation, auditing, measurement and improvement of controls for specific processes that span the entire IT implementation life cycle. As such, it is an excellent reference model for IT governance across the entire implementation life cycle. The primary focus of ITIL is to provide best practice definitions and criteria for operations management. More specifically, ITIL primarily focuses on defining the functional, operational and organizational attributes that need to be in place for operations management to be fully optimized in two key categories. These categories are called Service Support Management and Service Delivery Management, each of which has a number of supporting subcategories. The management subcategories for Service Support Management include Service Desk, Incident, Problem, Configuration, Change and Release management, while those for Service Delivery Management include Service Level, Financial, Capacity, Service Continuity and Availability. Each subcategory definition includes best practice criteria for many areas, including organizational support, cross management component integration, management reporting, product capability, implementation quality and customer service quality. If your goal is improving the quality and measurability of IT governance across the entire networked application implementation life cycle or implementing a control system for improved regulatory compliance, COBIT probably would be a more effective choice. On the other hand, if the objective is to continuously improve IT operations efficiency and IT customer service quality, ITIL would probably be the better bet. However, one should not look at these comparisons as a COBIT vs. ITIL analysis. It's important to understand the design center differences of each approach and adapt them as needed to meet the specific requirements of your own unique environment.
  • 4. Seguridad de la Información: Criptografía Cobit vs ITIL Página 4 de 4 Given the substantial implementation experience with both standards that exists in the industry today, you'll have plenty of peers to call on for advice. The even better news is that, unlike hardware or software products, their acquisition cost is extremely low. Morency is a managing director of Transitional Data Services, a service provider in Hopkinton, Mass., that specializes in IT orchestration for small and midsize companies. He can be reached at jmorency@transitionaldata.com. RELATED LINKS All contents copyright 1995-2003 Network World, Inc. http://www.nwfusion.com