SlideShare uma empresa Scribd logo
1 de 121
CobiT Update NSAA IT Conference Richmond, VA John W. Beveridge September 27, 2007
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],John Beveridge, CISA, CISM, CGFM, CFE, CQA
[object Object],[object Object],What is CobiT?
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],CobiT's Scope
C OBI T   ,[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],Focus on Information and IT Management
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],CobiT was Driven from Recognition of
[object Object],[object Object],[object Object],[object Object],The Challenge of Managing IT
[object Object],[object Object],[object Object],The Challenge of Managing IT
[object Object],[object Object],[object Object],Criticality of Managing IT
Management Issues ,[object Object],[object Object],[object Object],[object Object]
Management Issues ,[object Object],[object Object],[object Object]
Management Issues ,[object Object],[object Object],[object Object],[object Object],[object Object]
Management Questions ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],Management Questions
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],Assessing the Entity's Ability:
IT Value ,[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],Need for IT Governance Control Framework
Organizations require a structured approach for managing these and other challenges. Need to ensure that IT objectives are agreed to, good management controls are in place, and there is effective monitoring of performance to keep on track and avoid unexpected outcomes. ,[object Object],Keeping  IT Running Security Value/Cost Managing  Complexity Aligning IT with  Business Regulatory  Compliance
[object Object],[object Object],[object Object],[object Object],Need for IT Governance Control Framework
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],COBIT helps bridge the gaps between business risks, control needs and technical issues. It provides good practices across a domain and process framework and presents activities in a manageable and logical structure. IT resources need to be managed by a set of naturally grouped processes.  C OBI T provides a framework that achieves this objective.  ,[object Object]
How Does C OBI T View IT Governance? ,[object Object],[object Object]
IT Governance Objectives ,[object Object],[object Object],[object Object]
IT Governance ,[object Object],[object Object]
C OBI T  IT Governance ,[object Object],[object Object],[object Object],[object Object]
IT Governance Focus Areas ,[object Object],[object Object],[object Object],[object Object],[object Object]
IT Governance Focus Areas ,[object Object],[object Object]
IT Governance Focus Areas ,[object Object],[object Object]
IT Governance Focus Areas ,[object Object]
What Should Management Do? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
To Manage and Control IT,  C OBI T Recommends : ,[object Object],[object Object],[object Object],[object Object],[object Object]
Agencies Need Assurance ,[object Object],[object Object],[object Object],[object Object],[object Object]
CobiT is an Authoritative Source ,[object Object],[object Object],[object Object],[object Object]
C OBI T’s View of the Definition of Control Why Control Information Systems? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
C OBI T’s View of the Definition of Control ,[object Object],[object Object]
Control (as defined by COBIT) ,[object Object]
To Achieve Business Objectives To Avoid Risks, Threats and Exposures Control (as defined by COBIT) The policies, procedures, practices and organizational  structures designed to provide reasonable assurance that  business objectives  will be achieved and that  undesired events   will be prevented or detected and corrected. Source: COBIT  Control Objectives. P. 12.
CobiT promotes a healthy understanding about “reasonable assurance” and “residual risk” Knowing the acceptable levels for reasonable assurance and residual risk is a critical success factor for designing and managing an adequate framework of control
Assurance Level 100% Residual Risk 0% Reasonable Assurance
Relation to Other Control Models ,[object Object],[object Object],[object Object],[object Object],[object Object]
Organizations will consider and use a variety of IT models, standards and best practices. They must be understood to consider how they can be used together, with COBIT acting as the consolidator (‘umbrella’). C OBI T ISO 9000 ISO 17799 ITIL COSO WHAT HOW ,[object Object],SCOPE OF COVERAGE
C OBI T Cube The COBIT framework describes how IT processes deliver the information that the business needs to achieve its objectives.  For controlling this delivery, COBIT provides three key components, each forming a dimension of the COBIT cube. Business Requirements for Information Criteria IT Resources IT Processes
C OBI T: Premise ,[object Object],[object Object],i IT Resources and Processes Information Business  Processes Business  Objectives provide to for achieving
IT Resource Management ,[object Object]
C OBI T C OBI T  is a valuable IT governance tool that helps in the understanding and management of risks and benefits associated with information integrity, security, and availability, and the management of related technology.
 
[object Object],[object Object],[object Object],CobiT
Where is C OBI T Today?
How is CobiT Focused? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
What are the key COBIT Documents? ,[object Object],[object Object],[object Object]
C OBI T and Related Products Provides guidance on how COBIT can be used to support a variety of assurance activities together with suggested testing steps for all the IT processes and control objectives IT Assurance Guide Provide guidance on why the control objectives are worth implementing and how to implement them Control Practices Provides a generic road map for implementing IT governance using the COBIT and Val IT resources IT Governance Implementation Guide COBIT is an IT governance framework and supporting tool set that allows managers to bridge the gap between control requirements, technical issues and business risks. C OBI T 4.1 To help overcome these barriers by explaining information security in business terms. It comes complete with tools and techniques to help managers uncover security-related problems Information Security Governance To help executives understand why IT governance is important, what its issues are and what their responsibility is for managing it Board Briefing on IT Governance
C OBI T and Related Products To overview and various mappings of COBIT to other international guidance have been published by ITGI, such as CMM, ISO17799. COBIT Mapping Series To explain to business users and senior management the value of IT best practices and how harmonization, implementation and integration of best practices (COBIT, ITIL and ISO/IEC 17799) may be made easier. Aligning COBIT, ITIL and ISO 17799 To provides guidance on how to ensure compliance for the IT environment based on the COBIT control objectives related to financial reporting. IT Control Objectives for Sarbanes-Oxley To summarized version of the COBIT resources, focusing on the most crucial IT processes, control objectives and metrics, all presented in an easy-to-follow format to help users gain the benefits of COBIT quickly. COBIT Quickstart To provides guidance for managing an organization’s portfolio of IT-enabled business investments and for maximizing the quality of business cases for IT-enabled business investments. Val IT To focuses on IT security risk in a way that is simple to follow and implement for everyone, from the home user or small- to medium-sized enterprise to executives and board members of larger organizations. COBIT Security Baseline  (available 3rd quarter 2007)
C OBI T and Related Products
 
Control Objectives Framework Control Objectives Management Guidelines Maturity Models
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
 
Concise Control Objectives CobiT 4.1 CobiT 4.0 PO5.1 Financial Management Framework Establish a financial framework for IT that drives budgeting and cost/benefit analysis, based on investment, service and asset portfolios. Maintain the portfolios of IT-enabled investment programmers, IT services and IT assets, which form the basis for the current IT budget. Provide input to business cases for new investments, taking into account current IT asset and service portfolios. New investments and maintenance to service and asset portfolios will influence the future IT budget. Communicate the cost and benefit aspects of these portfolios to the budget prioritization, cost management and benefit management processes. PO5.1 Financial Management Framework Establish and maintain a financial framework to manage the investment and cost of IT assets and services through portfolios of IT enabled investments, business cases and IT budgets. PO1.2 Business-IT Alignment Educate executives on current technology capabilities and future directions, the opportunities that IT provides, and what the business has to do to capitalize on those opportunities. Make sure the business direction to which IT is aligned is understood. The business and IT strategies should be integrated, clearly linking enterprise goals and IT goals and recognizing opportunities as well as current capability limitations, and broadly communicated. Identify where the business (strategy) is critically dependent on IT and mediate between imperatives of the business and the technology, so agreed priorities can be established. PO1.2 Business-IT Alignment Establish processes of bi-directional education and reciprocal involvement in strategic planning to achieve business and IT alignment and integration. Mediate between business and IT imperatives so priorities can be mutually agreed.
 
 
Framework Update
C OBI T Framework ,[object Object],[object Object],[object Object],[object Object]
Information Criteria -- The 1st Component ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
IT Resources -- The 2nd Component ,[object Object],[object Object],[object Object],[object Object]
IT Process Domains -- The 3rd Component ,[object Object],[object Object],[object Object],[object Object]
C OBI T Process Model ,[object Object],[object Object],[object Object],[object Object]
What Are the Main Changes?
C OBI T Domains :  Information Processes (3rd Component) Feedback Feedback Feedback Plan and Organize Acquire and Implement Deliver and Support Monitor and Evaluate
C OBI T Framework   ,[object Object],Basic COBIT Principle
CobiT Framework ,[object Object],[object Object],[object Object],[object Object]
 
CobiT is Business-focused ,[object Object],[object Object]
Business Orientation of C OBI T ,[object Object],[object Object],[object Object]
Business Goals ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Business Goals ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
IT Goals ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
IT Goals ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
IT Goals ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
 
Linking Business Goals to IT Goals ,[object Object],[object Object],[object Object],[object Object]
 
Linking IT Goals to IT Processes ,[object Object],[object Object]
 
The WATERFALL Navigation Aid -- High Level Control Objectives for Each Process High-Level Control Objective Users satisfaction Is measured by The control of which satisfy is focusing on Is achieved by IT Processes Business Requirements Control Statements Control Practices
 
“ RACI” Chart ,[object Object],[object Object],[object Object],[object Object],[object Object]
Primary Inputs and Outputs ,[object Object],[object Object],[object Object],[object Object]
 
Metrics ,[object Object],[object Object]
Metrics ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
 
 
 
Use of Maturity Models ,[object Object],[object Object],[object Object]
 
Control Practices Control Practices Control Objectives Value Drivers Risk Drivers
Control Design ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
IT Control Practices ,[object Object],[object Object],[object Object],[object Object]
IT Control Practices ,[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
IT Assurance Guide Need for IT Governance and Assurance The CobiT Framework IT Assurance Approaches How CobiT Supports IT Assurance Activities
Approach ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],IT Assurance Steps
Approach ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],IT Assurance Steps
 
 
 
1 Using CobiT
[object Object],CobiT Links business goals to IT Goals CobiT Framework provides a common understanding of IT’s role CobiT IT Processes and Maturity Models focus on IT capability CobiT KGIs and KPIs enable measurement Provide  Direction Compare Measure Performance IT Activities ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],Set Objectives
Using CobiT ,[object Object]
Strong Basis for Policy Development ,[object Object],[object Object],[object Object]
Using CobiT Matrices to Focus on: ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
CobiT’s Evaluation Focus ,[object Object],[object Object],[object Object],[object Object],[object Object]
Risks to the Entity? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
C OBI T Focuses on Risk-Based Approach ,[object Object],[object Object],[object Object],[object Object]
To Address Outsourced Services ,[object Object],[object Object],[object Object],[object Object]
Recap: CobiT Recognizes ,[object Object],[object Object],[object Object],[object Object],[object Object]
 
Interrelationships of CobiT Components
C OBI T Content Diagram CobiT and Val IT  frameworks Control Objectives Key Management  Pratices IT Governance  Implementation Guide,  2 nd  Edition CobiT Control Practices  2 nd  Edition IT Assurance Guide
CobiT Update ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

Mais conteúdo relacionado

Mais procurados

Introduction to COBIT 2019 and IT management
Introduction to COBIT 2019 and IT managementIntroduction to COBIT 2019 and IT management
Introduction to COBIT 2019 and IT managementChristian F. Nissen
 
An Introduction to IT Management with COBIT 2019
An Introduction to IT Management with COBIT 2019An Introduction to IT Management with COBIT 2019
An Introduction to IT Management with COBIT 2019Gregor Polančič
 
IT Governance Made Easy
IT Governance Made EasyIT Governance Made Easy
IT Governance Made EasyJerry Bishop
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500Ramiro Cid
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance FrameworkSherri Booher
 
COBIT 5 Basic Concepts
COBIT 5 Basic ConceptsCOBIT 5 Basic Concepts
COBIT 5 Basic ConceptsSpyros Ktenas
 
Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Managementjiricejka
 
COBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdfCOBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdfMartinPatrici
 
IT frameworks
IT frameworksIT frameworks
IT frameworkscyouss
 
COBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an IntroductionCOBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an Introductionaqel aqel
 
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon Nam
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon NamCOBIT 5 as an IT Management Best Practices Framework - by Goh Boon Nam
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon NamNUS-ISS
 
Gartner's IT Score Wallchart
Gartner's IT Score WallchartGartner's IT Score Wallchart
Gartner's IT Score WallchartPaul Sullivan
 
IT Governance – The missing compass in a technology changing world
 IT Governance – The missing compass in a technology changing world IT Governance – The missing compass in a technology changing world
IT Governance – The missing compass in a technology changing worldPECB
 

Mais procurados (20)

Introduction to COBIT 2019 and IT management
Introduction to COBIT 2019 and IT managementIntroduction to COBIT 2019 and IT management
Introduction to COBIT 2019 and IT management
 
It governance
It governanceIt governance
It governance
 
An Introduction to IT Management with COBIT 2019
An Introduction to IT Management with COBIT 2019An Introduction to IT Management with COBIT 2019
An Introduction to IT Management with COBIT 2019
 
IT Governance Made Easy
IT Governance Made EasyIT Governance Made Easy
IT Governance Made Easy
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance Framework
 
COBIT 5 Basic Concepts
COBIT 5 Basic ConceptsCOBIT 5 Basic Concepts
COBIT 5 Basic Concepts
 
Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
 
COBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdfCOBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdf
 
What is Cobit
What is CobitWhat is Cobit
What is Cobit
 
IT frameworks
IT frameworksIT frameworks
IT frameworks
 
COBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an IntroductionCOBIT 5 IT Governance Model: an Introduction
COBIT 5 IT Governance Model: an Introduction
 
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon Nam
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon NamCOBIT 5 as an IT Management Best Practices Framework - by Goh Boon Nam
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon Nam
 
It governance
It governanceIt governance
It governance
 
Gartner's IT Score Wallchart
Gartner's IT Score WallchartGartner's IT Score Wallchart
Gartner's IT Score Wallchart
 
It governance & cobit 5
It governance & cobit 5It governance & cobit 5
It governance & cobit 5
 
ISO 27001 How to accelerate the implementation.pdf
ISO 27001 How to accelerate the implementation.pdfISO 27001 How to accelerate the implementation.pdf
ISO 27001 How to accelerate the implementation.pdf
 
IT Governance – The missing compass in a technology changing world
 IT Governance – The missing compass in a technology changing world IT Governance – The missing compass in a technology changing world
IT Governance – The missing compass in a technology changing world
 
COBIT5 Introduction
COBIT5 IntroductionCOBIT5 Introduction
COBIT5 Introduction
 
Sosialisasi sni iso iec 20000 - sistem manajemen layanan
Sosialisasi sni iso iec 20000 - sistem manajemen layananSosialisasi sni iso iec 20000 - sistem manajemen layanan
Sosialisasi sni iso iec 20000 - sistem manajemen layanan
 

Destaque (9)

Gobierno Corporativo y de TI, ¿compatibles? (Spanish)
Gobierno Corporativo y de TI, ¿compatibles? (Spanish)Gobierno Corporativo y de TI, ¿compatibles? (Spanish)
Gobierno Corporativo y de TI, ¿compatibles? (Spanish)
 
COBIT 5 Lo Nuevo
COBIT 5 Lo NuevoCOBIT 5 Lo Nuevo
COBIT 5 Lo Nuevo
 
From Value Governance To Benefits Realization In A Controlled Environment
From Value Governance To Benefits Realization In A Controlled EnvironmentFrom Value Governance To Benefits Realization In A Controlled Environment
From Value Governance To Benefits Realization In A Controlled Environment
 
Cobit(R) 5 Fundamentos
Cobit(R) 5 FundamentosCobit(R) 5 Fundamentos
Cobit(R) 5 Fundamentos
 
CobiT Foundation Free Training
CobiT Foundation Free TrainingCobiT Foundation Free Training
CobiT Foundation Free Training
 
Cobit 5 Business Framework -Governance and Management of Enterprise IT
Cobit 5  Business Framework -Governance and Management of Enterprise ITCobit 5  Business Framework -Governance and Management of Enterprise IT
Cobit 5 Business Framework -Governance and Management of Enterprise IT
 
COBIT®5 - Foundation
COBIT®5 - FoundationCOBIT®5 - Foundation
COBIT®5 - Foundation
 
Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 Framework
 
Implementing Enterprise Risk Management with ISO 31000:2009
Implementing Enterprise Risk Management with ISO 31000:2009Implementing Enterprise Risk Management with ISO 31000:2009
Implementing Enterprise Risk Management with ISO 31000:2009
 

Semelhante a COBIT 4.0

It governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yungIt governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yungnorsaidatul_akmar
 
Chap2 2007 Cisa Review Course
Chap2 2007 Cisa Review CourseChap2 2007 Cisa Review Course
Chap2 2007 Cisa Review CourseDesmond Devendran
 
IT Governance.pptx
IT Governance.pptxIT Governance.pptx
IT Governance.pptxFaith Shimba
 
MAKING SENSE OF IT GOVERNANCE
MAKING SENSE OF IT GOVERNANCEMAKING SENSE OF IT GOVERNANCE
MAKING SENSE OF IT GOVERNANCERudy Shoushany
 
Cobit Training course
Cobit Training courseCobit Training course
Cobit Training courseIman Baradari
 
What Every Executive Needs To Know About IT Governance
What Every Executive Needs To Know About IT GovernanceWhat Every Executive Needs To Know About IT Governance
What Every Executive Needs To Know About IT GovernanceBill Lisse
 
IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...GrapesTech Solutions
 
IT Governance in Banks, May, 2014
IT Governance in Banks, May, 2014IT Governance in Banks, May, 2014
IT Governance in Banks, May, 2014ArmeniaFED
 
Ict Vision And Strategy Development
Ict Vision And Strategy DevelopmentIct Vision And Strategy Development
Ict Vision And Strategy DevelopmentAlan McSweeney
 
rethinking marketing
rethinking marketingrethinking marketing
rethinking marketingNavneet Singh
 
Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3Dam Frank
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfSALES97
 
CISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of ITCISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of ITShivamSharma909
 

Semelhante a COBIT 4.0 (20)

It governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yungIt governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yung
 
Accountability Corbit Overview 06262007
Accountability Corbit Overview 06262007Accountability Corbit Overview 06262007
Accountability Corbit Overview 06262007
 
Gtag 1 information risk and control
Gtag 1 information risk and controlGtag 1 information risk and control
Gtag 1 information risk and control
 
Chap2 2007 Cisa Review Course
Chap2 2007 Cisa Review CourseChap2 2007 Cisa Review Course
Chap2 2007 Cisa Review Course
 
IT Governance.pptx
IT Governance.pptxIT Governance.pptx
IT Governance.pptx
 
MAKING SENSE OF IT GOVERNANCE
MAKING SENSE OF IT GOVERNANCEMAKING SENSE OF IT GOVERNANCE
MAKING SENSE OF IT GOVERNANCE
 
IT Governances
IT GovernancesIT Governances
IT Governances
 
It Governance Methodology Cox
It Governance Methodology CoxIt Governance Methodology Cox
It Governance Methodology Cox
 
Cobit Training course
Cobit Training courseCobit Training course
Cobit Training course
 
What Every Executive Needs To Know About IT Governance
What Every Executive Needs To Know About IT GovernanceWhat Every Executive Needs To Know About IT Governance
What Every Executive Needs To Know About IT Governance
 
IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...
 
Cobit 41 framework
Cobit 41 frameworkCobit 41 framework
Cobit 41 framework
 
Understanding co bit 4.1
Understanding co bit 4.1Understanding co bit 4.1
Understanding co bit 4.1
 
IT Governance in Banks, May, 2014
IT Governance in Banks, May, 2014IT Governance in Banks, May, 2014
IT Governance in Banks, May, 2014
 
Ict Vision And Strategy Development
Ict Vision And Strategy DevelopmentIct Vision And Strategy Development
Ict Vision And Strategy Development
 
rethinking marketing
rethinking marketingrethinking marketing
rethinking marketing
 
Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3
 
Task 2
Task 2Task 2
Task 2
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdf
 
CISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of ITCISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of IT
 

Mais de bluekiu

Tecnicas SEO
Tecnicas SEOTecnicas SEO
Tecnicas SEObluekiu
 
Idea de Proyecto
Idea de ProyectoIdea de Proyecto
Idea de Proyectobluekiu
 
Familia BMS
Familia BMSFamilia BMS
Familia BMSbluekiu
 
Familia Bms
Familia BmsFamilia Bms
Familia Bmsbluekiu
 
Analisis Del Dominio Nestle
Analisis Del Dominio NestleAnalisis Del Dominio Nestle
Analisis Del Dominio Nestlebluekiu
 
Flickr & SlideShare
Flickr & SlideShareFlickr & SlideShare
Flickr & SlideSharebluekiu
 

Mais de bluekiu (6)

Tecnicas SEO
Tecnicas SEOTecnicas SEO
Tecnicas SEO
 
Idea de Proyecto
Idea de ProyectoIdea de Proyecto
Idea de Proyecto
 
Familia BMS
Familia BMSFamilia BMS
Familia BMS
 
Familia Bms
Familia BmsFamilia Bms
Familia Bms
 
Analisis Del Dominio Nestle
Analisis Del Dominio NestleAnalisis Del Dominio Nestle
Analisis Del Dominio Nestle
 
Flickr & SlideShare
Flickr & SlideShareFlickr & SlideShare
Flickr & SlideShare
 

Último

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Bhuvaneswari Subramani
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontologyjohnbeverley2021
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxRemote DBA Services
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 

Último (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 

COBIT 4.0

  • 1. CobiT Update NSAA IT Conference Richmond, VA John W. Beveridge September 27, 2007
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12.
  • 13.
  • 14.
  • 15.
  • 16.
  • 17.
  • 18.
  • 19.
  • 20.
  • 21.
  • 22.
  • 23.
  • 24.
  • 25.
  • 26.
  • 27.
  • 28.
  • 29.
  • 30.
  • 31.
  • 32.
  • 33.
  • 34.
  • 35.
  • 36.
  • 37.
  • 38. To Achieve Business Objectives To Avoid Risks, Threats and Exposures Control (as defined by COBIT) The policies, procedures, practices and organizational structures designed to provide reasonable assurance that business objectives will be achieved and that undesired events will be prevented or detected and corrected. Source: COBIT Control Objectives. P. 12.
  • 39. CobiT promotes a healthy understanding about “reasonable assurance” and “residual risk” Knowing the acceptable levels for reasonable assurance and residual risk is a critical success factor for designing and managing an adequate framework of control
  • 40. Assurance Level 100% Residual Risk 0% Reasonable Assurance
  • 41.
  • 42.
  • 43. C OBI T Cube The COBIT framework describes how IT processes deliver the information that the business needs to achieve its objectives. For controlling this delivery, COBIT provides three key components, each forming a dimension of the COBIT cube. Business Requirements for Information Criteria IT Resources IT Processes
  • 44.
  • 45.
  • 46. C OBI T C OBI T is a valuable IT governance tool that helps in the understanding and management of risks and benefits associated with information integrity, security, and availability, and the management of related technology.
  • 47.  
  • 48.
  • 49. Where is C OBI T Today?
  • 50.
  • 51.
  • 52. C OBI T and Related Products Provides guidance on how COBIT can be used to support a variety of assurance activities together with suggested testing steps for all the IT processes and control objectives IT Assurance Guide Provide guidance on why the control objectives are worth implementing and how to implement them Control Practices Provides a generic road map for implementing IT governance using the COBIT and Val IT resources IT Governance Implementation Guide COBIT is an IT governance framework and supporting tool set that allows managers to bridge the gap between control requirements, technical issues and business risks. C OBI T 4.1 To help overcome these barriers by explaining information security in business terms. It comes complete with tools and techniques to help managers uncover security-related problems Information Security Governance To help executives understand why IT governance is important, what its issues are and what their responsibility is for managing it Board Briefing on IT Governance
  • 53. C OBI T and Related Products To overview and various mappings of COBIT to other international guidance have been published by ITGI, such as CMM, ISO17799. COBIT Mapping Series To explain to business users and senior management the value of IT best practices and how harmonization, implementation and integration of best practices (COBIT, ITIL and ISO/IEC 17799) may be made easier. Aligning COBIT, ITIL and ISO 17799 To provides guidance on how to ensure compliance for the IT environment based on the COBIT control objectives related to financial reporting. IT Control Objectives for Sarbanes-Oxley To summarized version of the COBIT resources, focusing on the most crucial IT processes, control objectives and metrics, all presented in an easy-to-follow format to help users gain the benefits of COBIT quickly. COBIT Quickstart To provides guidance for managing an organization’s portfolio of IT-enabled business investments and for maximizing the quality of business cases for IT-enabled business investments. Val IT To focuses on IT security risk in a way that is simple to follow and implement for everyone, from the home user or small- to medium-sized enterprise to executives and board members of larger organizations. COBIT Security Baseline (available 3rd quarter 2007)
  • 54. C OBI T and Related Products
  • 55.  
  • 56. Control Objectives Framework Control Objectives Management Guidelines Maturity Models
  • 57.
  • 58.  
  • 59. Concise Control Objectives CobiT 4.1 CobiT 4.0 PO5.1 Financial Management Framework Establish a financial framework for IT that drives budgeting and cost/benefit analysis, based on investment, service and asset portfolios. Maintain the portfolios of IT-enabled investment programmers, IT services and IT assets, which form the basis for the current IT budget. Provide input to business cases for new investments, taking into account current IT asset and service portfolios. New investments and maintenance to service and asset portfolios will influence the future IT budget. Communicate the cost and benefit aspects of these portfolios to the budget prioritization, cost management and benefit management processes. PO5.1 Financial Management Framework Establish and maintain a financial framework to manage the investment and cost of IT assets and services through portfolios of IT enabled investments, business cases and IT budgets. PO1.2 Business-IT Alignment Educate executives on current technology capabilities and future directions, the opportunities that IT provides, and what the business has to do to capitalize on those opportunities. Make sure the business direction to which IT is aligned is understood. The business and IT strategies should be integrated, clearly linking enterprise goals and IT goals and recognizing opportunities as well as current capability limitations, and broadly communicated. Identify where the business (strategy) is critically dependent on IT and mediate between imperatives of the business and the technology, so agreed priorities can be established. PO1.2 Business-IT Alignment Establish processes of bi-directional education and reciprocal involvement in strategic planning to achieve business and IT alignment and integration. Mediate between business and IT imperatives so priorities can be mutually agreed.
  • 60.  
  • 61.  
  • 63.
  • 64.
  • 65.
  • 66.
  • 67.
  • 68. What Are the Main Changes?
  • 69. C OBI T Domains : Information Processes (3rd Component) Feedback Feedback Feedback Plan and Organize Acquire and Implement Deliver and Support Monitor and Evaluate
  • 70.
  • 71.
  • 72.  
  • 73.
  • 74.
  • 75.
  • 76.
  • 77.
  • 78.
  • 79.
  • 80.  
  • 81.
  • 82.  
  • 83.
  • 84.  
  • 85. The WATERFALL Navigation Aid -- High Level Control Objectives for Each Process High-Level Control Objective Users satisfaction Is measured by The control of which satisfy is focusing on Is achieved by IT Processes Business Requirements Control Statements Control Practices
  • 86.  
  • 87.
  • 88.
  • 89.  
  • 90.
  • 91.
  • 92.  
  • 93.  
  • 94.  
  • 95.
  • 96.  
  • 97. Control Practices Control Practices Control Objectives Value Drivers Risk Drivers
  • 98.
  • 99.
  • 100.
  • 101.
  • 102. IT Assurance Guide Need for IT Governance and Assurance The CobiT Framework IT Assurance Approaches How CobiT Supports IT Assurance Activities
  • 103.
  • 104.
  • 105.  
  • 106.  
  • 107.  
  • 109.
  • 110.
  • 111.
  • 112.
  • 113.
  • 114.
  • 115.
  • 116.
  • 117.
  • 118.  
  • 120. C OBI T Content Diagram CobiT and Val IT frameworks Control Objectives Key Management Pratices IT Governance Implementation Guide, 2 nd Edition CobiT Control Practices 2 nd Edition IT Assurance Guide
  • 121.

Notas do Editor

  1. This summarises the different types of audience
  2. Explain that there are many management challenges relating to the use of IT. The slide identifies some examples (the same as in the C OBI T ® Foundation Course). To manage this range of issues, a sound management approach is needed. The goals include agreed and aligned objectives for IT, effective controls, and effective tracking of performance. These are the main drivers for IT governance.
  3. This slide summarises the main attributes of the C OBI T framework.
  4. Strategic alignment focuses on ensuring the linkage of business and IT plans; on defining, maintaining and validating the IT value proposition; and on aligning IT operations with enterprise operations. • Value delivery is about executing the value proposition throughout the delivery cycle, ensuring that IT delivers the promised benefits against the strategy, concentrating on optimising costs and proving the intrinsic value of IT. • Resource management is about the optimal investment in, and the proper management of, critical IT resources: applications, information, infrastructure and people. Key issues relate to the optimisation of knowledge and infrastructure. • Risk management requires risk awareness by senior corporate officers, a clear understanding of the enterprise’s appetite for risk, understanding of compliance requirements, transparency about the significant risks to the enterprise, and embedding of risk management responsibilities into the organisation. • Performance measurement tracks and monitors strategy implementation, project completion, resource usage, process performance and service delivery, using, for example, balanced scorecards that translate strategy into action to achieve goals measurable beyond conventional accounting.
  5. It is normal for C OBI T to be used in conjunction with other good practices, standards and in-house developed guidance. C OBI T can act like an umbrella providing the framework for everything else.
  6. CobiT focuses on 5 key areas which we will see during this course are the main elements of IT Governance as well as the issues all commentators and analysts agree are key to IT success Read through each bullet to reinforce each one, saying these will be come clearer as we progress through the two days
  7. Control Practices go to the next level down and are a guide for implementation, explaining how to address each objective providing practical considerations. But they are not specific solutions and are therefore generic. Note that during 2003 not all of these are available as they are under development
  8. This diagram which is taken from the Management Guidelines book, describes one of the basic principles of IT Governance. Objectives have to be clear and well understood. Management should direct activities to meet these objectives and regularly measure and compare to detect variances that can then be corrected. The diagram shows how the various elements of CobiT support these stages The working of a central heating thermostat as an example