SlideShare una empresa de Scribd logo
1 de 27
Introduction-BenefitsIntroduction-Benefits
COBIT FrameworkCOBIT Framework
With ExampleWith Example
Sanjiv Arora, CISA, CISM, CGEIT
Principal Consultant
TECHNOLOGICS
& CONTROLS
Protecting the ABCs of your business.
AgendaAgenda
 IT Governance
 COBIT framework
 Example - Cost Management Controls in IT Operations using
COBIT
 About Technologics and Controls
IT Governance – Need?IT Governance – Need?
What is driving today’s businesses?
Assertive Stakeholders
Aggressive Competition
Emerging Regulations
Recessionary trends direct / indirect
Extremely high IT Dependence
Impacts
Enterprise GovernanceEnterprise Governance
IT Governance - AlignmentIT Governance - Alignment
Value Delivery
•Secure
•On Time
•Within Budgets
•Good Quality
•Reduce Expense
•Proven best
practices
Business Benefits
•Customer satisfaction
•Brand Loyalty
•Competitive advantage
•Profitability
Crux - Fill what's empty. Empty what's full. And scratch where
it itches. – Murphy’s law
Why COBIT?Why COBIT?
 Better alignment based on business focus
 Demonstrates management viewpoint and expectations
 Clear ownerships and responsibilities based on
processes
 Increasing acceptability with third parties and regulators
 Eases IT Governance communication between
stakeholders and other parties
 Fulfillment of the COSO requirements for IT control
environment
Lack of IT Governance makes it....Lack of IT Governance makes it....
 Difficult to make a link to the business requirements
 Complex to measure performance against the
requirements
 Cumbersome to control activities using a generally
accepted process model
 Difficult to identify the resources to be leveraged
 A problem to define management control objectives
Use of COBIT – Practical ScenarioUse of COBIT – Practical Scenario
 Uses are
 Implement and Manage IT governance
 Risk Assessment and Management
 Defining KPI and KGI
 Mapping to other standards
 Customize controls
 Provides direction and recommendations for weak
controls
 Aid to implement ERP, BCP, BPR and other IT
projects
 Implement Cost Savings on IT spend (Capex and
Opex)
 Assessment of IT governance maturity
 Demonstrate IT alignment (using Balance Score card)
COBIT – It is ImplementableCOBIT – It is Implementable

Based on self assessment

Very comprehensive yet flexible

Does not enforce COMPLETE implementation

Customizable

Easy to understand (Subject Matter Experts are
available)

Implementation maybe fast track, with help of tools
COBIT – Importance Vs Other standardsCOBIT – Importance Vs Other standards
 Comprehensive for business requirements
 Business operations completely dependent on IT
 Business applications (ERP), workflows, resource sharing,
communication (chat, email,video conferencing) controls are all
logical controls
 Approval and authorization – financial or non-financial is mostly
handled by logical controls
 Confidentiality is primarily managed within technology
 COBIT encompasses all aspects of IT Governance
 Other standards where COBIT is useful
 ITIL
 SOX compliance
 PCI-DSS
 NIST
 HIPAA
 ISO27001
 Others
COBITCOBIT – Other Standards– Other Standards
http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=31702
Common misunderstanding: We already have xyz standard, so we do
not need COBIT.
COBIT FrameworkCOBIT Framework
Source – ITGI presentation materials
The following slides explain an example
of COBIT framework implementation.
The slides are prepared using the Meycor COBIT suite software tools.
Actual tool may also be demonstrated as necessary,
time and audience permitting.
Thanks.
COBIT FrameworkCOBIT Framework
COBIT – Key Objectives and ControlsCOBIT – Key Objectives and Controls
COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach
4 Domains
34 Processes
(select applicable processes)
210 Control Objectives
(select from applicable objectives)
Controls
(Select / add / modify controls to
Suit your IT Governance needs)
* Equals =
4 Domains
22 processes
145 controls objectives
N Controls
* An example
COBIT – Processes and Controls – Tangible Cost ManagementCOBIT – Processes and Controls – Tangible Cost Management
Source - http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=47399
Cost Management Controls = Selected 10 processes
COBIT – Processes and Controls – Excess Labour ManagementCOBIT – Processes and Controls – Excess Labour Management
Too many cooks….!
COBIT – Assessment and gaps – Tangible Cost ManagementCOBIT – Assessment and gaps – Tangible Cost Management
COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving
Cont’d
COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving
COBIT – Tangible Cost Management – Recommendation – DS2COBIT – Tangible Cost Management – Recommendation – DS2
Customize recommendations
according to business objectives.
COBIT – Tangible Cost Management–Tasks/linked RecommendationCOBIT – Tangible Cost Management–Tasks/linked Recommendation
COBIT – Tangible Cost Management–Tasks Manage / ComplyCOBIT – Tangible Cost Management–Tasks Manage / Comply
Verify and validate to ensure
compliance and success.
COBIT – Tangible Cost Management– Communicate ResultsCOBIT – Tangible Cost Management– Communicate Results
 Proactive IT initiatives and operational improvements
 Enhance credibility of the IT organization
 Benefits
 Tangibles
 Current period vs previous period
 % saving from alternate options
 Forecast reduction in expense / ROI
 Intangibles
 Efficiency of operations
 Reduced incidents
 High uptime
 Link to business objectives
 Faster product launch
 Timely service delivery
 Increase in customers / revenue
COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach
4 Domains
34 Processes
(select applicable processes)
210 Control Objectives
(select from applicable objectives)
Controls
(Select / add / modify controls to
Suit your IT Governance needs)
* Equals =
4 Domains
22 processes
145 controls objectives
N Controls
* An example
The funnel model can be used for
implementation of ERP, Other IT Projects,
Project Monitoring and controls,
Compliance checklists
Introduction : Technologics & ControlsIntroduction : Technologics & Controls
 Founded in 2001
 Based in New Delhi, India
 Services: IT Audits, Risk Management consulting, Information
security assessment and management, IT Governance services,
compliance and related services.
 Products: Sole reseller in India of DataSec S.R.L providing software
solutions based on COBIT / ISO27001 / COSO and other standards
COBIT – BenefitsCOBIT – Benefits
We offer our rich experience to meet your Business Requirements and Objectives in the IT
Audits, IT Governance, Risk, Security Awareness, CISA, CISM Training and IT Strategy
consulting areas.
Our specializations includes reviews of ERP, CBS, Information Architecture, IT Efficiency
and Effectiveness to deliver value amongst other things.
We have worked with Al Rajhi Takaful in KSA, Qatar Steel, WFP, WHO, UNOPS, Govt of
India and many other reputed companies across the world.
We shall be happy to discuss your requirements,
Look forward.
Sanjiv Arora
Contact us on +91 98102 93733 or email sa@tech-controls.com
www.tech-controls.com

Más contenido relacionado

La actualidad más candente

IT Audit For Non-IT Auditors
IT Audit For Non-IT AuditorsIT Audit For Non-IT Auditors
IT Audit For Non-IT AuditorsEd Tobias
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500Ramiro Cid
 
La mise en œuvre de la gouvernance du SI au Ministère des Affaires Étrangères
La mise en œuvre de la gouvernance du SI au Ministère des Affaires ÉtrangèresLa mise en œuvre de la gouvernance du SI au Ministère des Affaires Étrangères
La mise en œuvre de la gouvernance du SI au Ministère des Affaires Étrangèrespeguet
 
Etude de cas audit cobit 4.1
Etude de cas audit cobit 4.1Etude de cas audit cobit 4.1
Etude de cas audit cobit 4.1saqrjareh
 
IT Control Objectives Framework, A Relationship Between COSO Cobit and ITIL
IT Control Objectives Framework, A Relationship Between COSO Cobit and ITILIT Control Objectives Framework, A Relationship Between COSO Cobit and ITIL
IT Control Objectives Framework, A Relationship Between COSO Cobit and ITILAlfid Ardyanto
 
Audit of IT Governance (Reference documents to be audited)
Audit of IT Governance (Reference documents to be audited)Audit of IT Governance (Reference documents to be audited)
Audit of IT Governance (Reference documents to be audited)Ammar Sassi
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewNaresh Rao
 
How To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckHow To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckSlideTeam
 
NIST Cybersecurity Framework - Mindmap
NIST Cybersecurity Framework - MindmapNIST Cybersecurity Framework - Mindmap
NIST Cybersecurity Framework - MindmapWAJAHAT IQBAL
 
Risk management ISO 27001 Standard
Risk management ISO 27001 StandardRisk management ISO 27001 Standard
Risk management ISO 27001 StandardTharindunuwan9
 
Improve Cybersecurity posture by using ISO/IEC 27032
Improve Cybersecurity posture by using ISO/IEC 27032Improve Cybersecurity posture by using ISO/IEC 27032
Improve Cybersecurity posture by using ISO/IEC 27032PECB
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEryk Budi Pratama
 

La actualidad más candente (20)

ISO 27001:2022 Introduction
ISO 27001:2022 IntroductionISO 27001:2022 Introduction
ISO 27001:2022 Introduction
 
IT Audit For Non-IT Auditors
IT Audit For Non-IT AuditorsIT Audit For Non-IT Auditors
IT Audit For Non-IT Auditors
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500
 
La mise en œuvre de la gouvernance du SI au Ministère des Affaires Étrangères
La mise en œuvre de la gouvernance du SI au Ministère des Affaires ÉtrangèresLa mise en œuvre de la gouvernance du SI au Ministère des Affaires Étrangères
La mise en œuvre de la gouvernance du SI au Ministère des Affaires Étrangères
 
Etude de cas audit cobit 4.1
Etude de cas audit cobit 4.1Etude de cas audit cobit 4.1
Etude de cas audit cobit 4.1
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Using the Threat Agent Library to improve threat modeling
Using the Threat Agent Library to improve threat modelingUsing the Threat Agent Library to improve threat modeling
Using the Threat Agent Library to improve threat modeling
 
IT Control Objectives Framework, A Relationship Between COSO Cobit and ITIL
IT Control Objectives Framework, A Relationship Between COSO Cobit and ITILIT Control Objectives Framework, A Relationship Between COSO Cobit and ITIL
IT Control Objectives Framework, A Relationship Between COSO Cobit and ITIL
 
Iso 20000 presentation
Iso 20000 presentationIso 20000 presentation
Iso 20000 presentation
 
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdfISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
 
Audit of IT Governance (Reference documents to be audited)
Audit of IT Governance (Reference documents to be audited)Audit of IT Governance (Reference documents to be audited)
Audit of IT Governance (Reference documents to be audited)
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
 
How To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckHow To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete Deck
 
NIST Cybersecurity Framework - Mindmap
NIST Cybersecurity Framework - MindmapNIST Cybersecurity Framework - Mindmap
NIST Cybersecurity Framework - Mindmap
 
Risk management ISO 27001 Standard
Risk management ISO 27001 StandardRisk management ISO 27001 Standard
Risk management ISO 27001 Standard
 
L'audit et la gestion des incidents
L'audit et la gestion des incidentsL'audit et la gestion des incidents
L'audit et la gestion des incidents
 
Cobit 5 - An Overview
Cobit 5 - An OverviewCobit 5 - An Overview
Cobit 5 - An Overview
 
Improve Cybersecurity posture by using ISO/IEC 27032
Improve Cybersecurity posture by using ISO/IEC 27032Improve Cybersecurity posture by using ISO/IEC 27032
Improve Cybersecurity posture by using ISO/IEC 27032
 
It governance
It governanceIt governance
It governance
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating Model
 

Destacado

Russain Optical Core Switch Market
Russain Optical Core Switch MarketRussain Optical Core Switch Market
Russain Optical Core Switch Marketguestba6d0cd
 
【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書env25
 
Wellspiration 6 - Fighting Heart Disease Naturally
Wellspiration 6  - Fighting Heart Disease NaturallyWellspiration 6  - Fighting Heart Disease Naturally
Wellspiration 6 - Fighting Heart Disease NaturallyYafa Sakkejha
 
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàngFacebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàngHoàng Nguyễn
 
Tdd pecha kucha_v2
Tdd pecha kucha_v2Tdd pecha kucha_v2
Tdd pecha kucha_v2Paul Boos
 
Supermods Enter Rehab
Supermods Enter RehabSupermods Enter Rehab
Supermods Enter Rehabguestda81b6
 
Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010Marko Gargenta
 
Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)Yuriy Silvestrov
 
Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009Bonnier
 
100道素菜(心經版)
100道素菜(心經版)100道素菜(心經版)
100道素菜(心經版)Richja
 
BMES @ SJSU
BMES @ SJSUBMES @ SJSU
BMES @ SJSUSheena
 
Social Media Legal Issues & Best Practices
Social Media Legal Issues & Best PracticesSocial Media Legal Issues & Best Practices
Social Media Legal Issues & Best Practicesskmarcus
 
Lezione Ed Ambientale
Lezione Ed AmbientaleLezione Ed Ambientale
Lezione Ed AmbientaleTeresa Fresu
 
Meeting Change Game
Meeting Change GameMeeting Change Game
Meeting Change GamePaul Boos
 

Destacado (20)

Russain Optical Core Switch Market
Russain Optical Core Switch MarketRussain Optical Core Switch Market
Russain Optical Core Switch Market
 
【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書
 
Wellspiration 6 - Fighting Heart Disease Naturally
Wellspiration 6  - Fighting Heart Disease NaturallyWellspiration 6  - Fighting Heart Disease Naturally
Wellspiration 6 - Fighting Heart Disease Naturally
 
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàngFacebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
 
Tdd pecha kucha_v2
Tdd pecha kucha_v2Tdd pecha kucha_v2
Tdd pecha kucha_v2
 
Email Marketing & Landing Pages
Email Marketing & Landing PagesEmail Marketing & Landing Pages
Email Marketing & Landing Pages
 
Supermods Enter Rehab
Supermods Enter RehabSupermods Enter Rehab
Supermods Enter Rehab
 
Android Internals
Android InternalsAndroid Internals
Android Internals
 
Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010
 
Resursele Regenerabile (2)
Resursele Regenerabile  (2)Resursele Regenerabile  (2)
Resursele Regenerabile (2)
 
Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)
 
Linda
LindaLinda
Linda
 
Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009
 
Pertussis en niños Lima
Pertussis en niños LimaPertussis en niños Lima
Pertussis en niños Lima
 
Hispaania
HispaaniaHispaania
Hispaania
 
100道素菜(心經版)
100道素菜(心經版)100道素菜(心經版)
100道素菜(心經版)
 
BMES @ SJSU
BMES @ SJSUBMES @ SJSU
BMES @ SJSU
 
Social Media Legal Issues & Best Practices
Social Media Legal Issues & Best PracticesSocial Media Legal Issues & Best Practices
Social Media Legal Issues & Best Practices
 
Lezione Ed Ambientale
Lezione Ed AmbientaleLezione Ed Ambientale
Lezione Ed Ambientale
 
Meeting Change Game
Meeting Change GameMeeting Change Game
Meeting Change Game
 

Similar a Use COBIT for IT SAVINGS

Cobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiCobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiIvo Oktavianti
 
CobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced ScorecardsCobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced ScorecardsMichael Sim
 
Frameworks For Predictability
Frameworks For PredictabilityFrameworks For Predictability
Frameworks For Predictabilitytlknecht
 
Frameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information TechnologyFrameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information TechnologyJohn Halliday
 
Pmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewPmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewAlan McSweeney
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Meghna Verma
 
IT frameworks
IT frameworksIT frameworks
IT frameworkscyouss
 
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practiceJohn Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practiceitSMF UK
 
Indus productization-brief
Indus productization-briefIndus productization-brief
Indus productization-briefindusaviation
 

Similar a Use COBIT for IT SAVINGS (20)

Cobit 4.1 indri
Cobit 4.1 indriCobit 4.1 indri
Cobit 4.1 indri
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
Cobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiCobit 4.1 ivooktavianti
Cobit 4.1 ivooktavianti
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
CobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced ScorecardsCobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced Scorecards
 
Frameworks For Predictability
Frameworks For PredictabilityFrameworks For Predictability
Frameworks For Predictability
 
Donna Febriani
Donna FebrianiDonna Febriani
Donna Febriani
 
Frameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information TechnologyFrameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information Technology
 
Uas dwi widiastuti
Uas dwi widiastutiUas dwi widiastuti
Uas dwi widiastuti
 
Pmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewPmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment Overview
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799
 
CobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast SeminarCobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast Seminar
 
IT frameworks
IT frameworksIT frameworks
IT frameworks
 
Darmin ritonga 11353205418
Darmin ritonga 11353205418Darmin ritonga 11353205418
Darmin ritonga 11353205418
 
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
 
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practiceJohn Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
 
IT Governance - COBIT Perspective
IT Governance - COBIT PerspectiveIT Governance - COBIT Perspective
IT Governance - COBIT Perspective
 
Audit rizkie hafizzah
Audit rizkie hafizzahAudit rizkie hafizzah
Audit rizkie hafizzah
 
Cobi t vs itil
Cobi t vs itilCobi t vs itil
Cobi t vs itil
 
Indus productization-brief
Indus productization-briefIndus productization-brief
Indus productization-brief
 

Último

How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Phases of negotiation .pptx
 Phases of negotiation .pptx Phases of negotiation .pptx
Phases of negotiation .pptxnandhinijagan9867
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangaloreamitlee9823
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noidadlhescort
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1kcpayne
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756dollysharma2066
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...allensay1
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperityhemanthkumar470700
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 

Último (20)

How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Phases of negotiation .pptx
 Phases of negotiation .pptx Phases of negotiation .pptx
Phases of negotiation .pptx
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 

Use COBIT for IT SAVINGS

  • 1. Introduction-BenefitsIntroduction-Benefits COBIT FrameworkCOBIT Framework With ExampleWith Example Sanjiv Arora, CISA, CISM, CGEIT Principal Consultant TECHNOLOGICS & CONTROLS Protecting the ABCs of your business.
  • 2. AgendaAgenda  IT Governance  COBIT framework  Example - Cost Management Controls in IT Operations using COBIT  About Technologics and Controls
  • 3. IT Governance – Need?IT Governance – Need? What is driving today’s businesses? Assertive Stakeholders Aggressive Competition Emerging Regulations Recessionary trends direct / indirect Extremely high IT Dependence Impacts Enterprise GovernanceEnterprise Governance
  • 4. IT Governance - AlignmentIT Governance - Alignment Value Delivery •Secure •On Time •Within Budgets •Good Quality •Reduce Expense •Proven best practices Business Benefits •Customer satisfaction •Brand Loyalty •Competitive advantage •Profitability Crux - Fill what's empty. Empty what's full. And scratch where it itches. – Murphy’s law
  • 5. Why COBIT?Why COBIT?  Better alignment based on business focus  Demonstrates management viewpoint and expectations  Clear ownerships and responsibilities based on processes  Increasing acceptability with third parties and regulators  Eases IT Governance communication between stakeholders and other parties  Fulfillment of the COSO requirements for IT control environment
  • 6. Lack of IT Governance makes it....Lack of IT Governance makes it....  Difficult to make a link to the business requirements  Complex to measure performance against the requirements  Cumbersome to control activities using a generally accepted process model  Difficult to identify the resources to be leveraged  A problem to define management control objectives
  • 7. Use of COBIT – Practical ScenarioUse of COBIT – Practical Scenario  Uses are  Implement and Manage IT governance  Risk Assessment and Management  Defining KPI and KGI  Mapping to other standards  Customize controls  Provides direction and recommendations for weak controls  Aid to implement ERP, BCP, BPR and other IT projects  Implement Cost Savings on IT spend (Capex and Opex)  Assessment of IT governance maturity  Demonstrate IT alignment (using Balance Score card)
  • 8. COBIT – It is ImplementableCOBIT – It is Implementable  Based on self assessment  Very comprehensive yet flexible  Does not enforce COMPLETE implementation  Customizable  Easy to understand (Subject Matter Experts are available)  Implementation maybe fast track, with help of tools
  • 9. COBIT – Importance Vs Other standardsCOBIT – Importance Vs Other standards  Comprehensive for business requirements  Business operations completely dependent on IT  Business applications (ERP), workflows, resource sharing, communication (chat, email,video conferencing) controls are all logical controls  Approval and authorization – financial or non-financial is mostly handled by logical controls  Confidentiality is primarily managed within technology  COBIT encompasses all aspects of IT Governance  Other standards where COBIT is useful  ITIL  SOX compliance  PCI-DSS  NIST  HIPAA  ISO27001  Others
  • 10. COBITCOBIT – Other Standards– Other Standards http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=31702 Common misunderstanding: We already have xyz standard, so we do not need COBIT.
  • 11. COBIT FrameworkCOBIT Framework Source – ITGI presentation materials
  • 12. The following slides explain an example of COBIT framework implementation. The slides are prepared using the Meycor COBIT suite software tools. Actual tool may also be demonstrated as necessary, time and audience permitting. Thanks.
  • 14. COBIT – Key Objectives and ControlsCOBIT – Key Objectives and Controls
  • 15. COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach 4 Domains 34 Processes (select applicable processes) 210 Control Objectives (select from applicable objectives) Controls (Select / add / modify controls to Suit your IT Governance needs) * Equals = 4 Domains 22 processes 145 controls objectives N Controls * An example
  • 16. COBIT – Processes and Controls – Tangible Cost ManagementCOBIT – Processes and Controls – Tangible Cost Management Source - http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=47399 Cost Management Controls = Selected 10 processes
  • 17. COBIT – Processes and Controls – Excess Labour ManagementCOBIT – Processes and Controls – Excess Labour Management Too many cooks….!
  • 18. COBIT – Assessment and gaps – Tangible Cost ManagementCOBIT – Assessment and gaps – Tangible Cost Management
  • 19. COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving Cont’d
  • 20. COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving
  • 21. COBIT – Tangible Cost Management – Recommendation – DS2COBIT – Tangible Cost Management – Recommendation – DS2 Customize recommendations according to business objectives.
  • 22. COBIT – Tangible Cost Management–Tasks/linked RecommendationCOBIT – Tangible Cost Management–Tasks/linked Recommendation
  • 23. COBIT – Tangible Cost Management–Tasks Manage / ComplyCOBIT – Tangible Cost Management–Tasks Manage / Comply Verify and validate to ensure compliance and success.
  • 24. COBIT – Tangible Cost Management– Communicate ResultsCOBIT – Tangible Cost Management– Communicate Results  Proactive IT initiatives and operational improvements  Enhance credibility of the IT organization  Benefits  Tangibles  Current period vs previous period  % saving from alternate options  Forecast reduction in expense / ROI  Intangibles  Efficiency of operations  Reduced incidents  High uptime  Link to business objectives  Faster product launch  Timely service delivery  Increase in customers / revenue
  • 25. COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach 4 Domains 34 Processes (select applicable processes) 210 Control Objectives (select from applicable objectives) Controls (Select / add / modify controls to Suit your IT Governance needs) * Equals = 4 Domains 22 processes 145 controls objectives N Controls * An example The funnel model can be used for implementation of ERP, Other IT Projects, Project Monitoring and controls, Compliance checklists
  • 26. Introduction : Technologics & ControlsIntroduction : Technologics & Controls  Founded in 2001  Based in New Delhi, India  Services: IT Audits, Risk Management consulting, Information security assessment and management, IT Governance services, compliance and related services.  Products: Sole reseller in India of DataSec S.R.L providing software solutions based on COBIT / ISO27001 / COSO and other standards
  • 27. COBIT – BenefitsCOBIT – Benefits We offer our rich experience to meet your Business Requirements and Objectives in the IT Audits, IT Governance, Risk, Security Awareness, CISA, CISM Training and IT Strategy consulting areas. Our specializations includes reviews of ERP, CBS, Information Architecture, IT Efficiency and Effectiveness to deliver value amongst other things. We have worked with Al Rajhi Takaful in KSA, Qatar Steel, WFP, WHO, UNOPS, Govt of India and many other reputed companies across the world. We shall be happy to discuss your requirements, Look forward. Sanjiv Arora Contact us on +91 98102 93733 or email sa@tech-controls.com www.tech-controls.com