SlideShare una empresa de Scribd logo
1 de 18
Policy Development
& The 4 COBIT
Domain Processes
Policy Development based on COBIT
Implementation
Craig R. Gray, Director of IS&T
cgray@leeuniversity.edu
Agenda
 Policy Development: Basis & Application
 The Mechanics of Control
 COBIT-What?
 COBIT-4 Domains
 High Level Control Examples?
Traditional Tools of the Trade
Control
Statements
Control
Practices
is enabled by
and considers
IT Processes
The control of
Business
Requirements
which satisfy
Policy Development Flow
Control Cycle
Adjust
as
Necessary
Standards
Measurement
System
Measure
Control
Focus
Identify Key Controls
What is COBIT?
 COBIT (Control Objectives for Information and Related Technology) is
globally accepted as being the most comprehensive work for IT
governance, organization, as well as IT process and risk management
 COBIT provides good practices for the management of IT processes in
a manageable and logical structure, meeting the multiple needs of
enterprise management by bridging the gaps between business
risks, technical issues, control needs and performance
measurement requirements.
 The COBIT mission is to research, develop, publicize and promote an
authoritative, up-to-date, international set of generally accepted
information technology control objectives for day-to-day use by
business managers and auditors.
Starts from the premise that IT needs to deliver the
information that the enterprise needs to achieve its
objectives.
Promotes process focus and process ownership
Divides IT into 34 processes belonging to four domains
and provides a high level control objective for each
Looks at fiduciary, quality and security needs of
enterprises,providing seven information criteria that can
be used to generically define what the business requires
from IT
Is supported by a set of 318 detailed control objectives
Effectiveness
Efficiency
Availability
Integrity
Confidentiality
Reliability
Compliance
Planning
Acquiring & Implementing
Delivery & Support
Monitoring
EFFECTIVENESS
Deals with information being
relevant and pertinent to the
business process as well as being
delivered in a timely, correct,
consistent and usable manner
EFFICIENCY
Concerns the provision of the
information through the optimal
use of resources
CONFIDENTIALITY
Concerns the protection of
sensitive information from
unauthorized disclosure
INTEGRITY
Relates to the accuracy and
completeness of information as
well as to its validity in accordance
with business values and
expectations
AVAILABILITY
Relates to the information being
available when required by the
business process now and in the
future
COMPLIANCE
Deals with complying with laws,
regulations and contractual
arrangements.
RELIABILITY OF
INFORMATION
Relates to the provision of
appropriate information for the
workforce of the organization
EVENTS
 Business Operations
 Business Opportunities
 External Requirements
 Regulations
PROCESS
TECHNOLOGY
ORGANIZATION
DATA
RISK
CRITERIA
Effectiveness
Efficiency
Confidentiality
Integrity
Availability
Compliance
Reliability
MESSAGE INPUT SERVICE OUTPUT
Events can be defined in terms of the processes, technology (systems) and organization
(people) that compose them
Information Risk Criteria
The 4 COBIT Domains
 Planning & Organization
 Acquisition & Implementation
 Delivery & Support
 Monitoring
Planning and Organization
 This domain covers strategy and tactics, and concerns
the identification of the way IT can best contribute to the
achievement of the business objectives.
 Furthermore, the realization of the strategic vision needs
to be planned, communicated and managed for different
perspectives.
 Finally, a proper organization as well as technological
infrastructure must be put in place.
Acquisition and Implementation
 To realize the IT strategy, IT solutions need to be
identified, developed or acquired, as well as
implemented and integrated into the business process.
 In addition, changes in and maintenance of existing
systems are covered by this domain to make sure that
the life cycle is continued for these systems.
Delivery and Support
 This domain is concerned with the actual delivery of
required services, which range from traditional
operations over security and continuity aspects to
training.
 In order to deliver services, the necessary support
processes must be set up.
 This domain includes the actual processing of data by
application systems, often classified under application
controls.
Monitoring
 All IT processes need to be regularly assessed
over time for their quality and compliance with
control requirements.
 This domain thus addresses management’s
oversight of the organization's control process
and independent assurance provided by internal
and external audit or obtained from alternative
sources.
Executive Summary There is a method…
Framework The method is…
Control Objectives Minimum controls are…
Audit Guidelines Here is how you audit…
Implementation
Toolset
Here is how you implement…
Management
Guidelines
Here is how you measure…
COBIT Components
COBIT History
 Technical Standards
 ISO, EDIFACT
 Codes of Conduct
 Council of Europe, ISACA, OECD
 Qualification Criteria for IT Systems and Processes
 ITSEC, TCSEC, ISO 9000, SPICE, TICKIT, Common Criteria
 Professional Standards
 COSO, IFAC, AICPA, CICA, ISACA, IIA, PCIE, GAO
 Industry Practices and Requirements
 Industry forums (ESF, 14), Government-sponsored platforms (IBAG,
NIST, DTI, BS7799)
Thanks!
Questions?
cgray@leeuniversity.edu

Más contenido relacionado

Similar a gray_audit_presentation.ppt

It governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yungIt governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yungnorsaidatul_akmar
 
02. cobit 41 dan iso 17799
02. cobit 41 dan iso 1779902. cobit 41 dan iso 17799
02. cobit 41 dan iso 17799Mulyadi Yusuf
 
Governance and management of IT.pptx
Governance and management of IT.pptxGovernance and management of IT.pptx
Governance and management of IT.pptxPrashant Singh
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachMohammad Reda Katby
 
Msp It Goverance And Service Delivery Process
Msp It Goverance And Service Delivery ProcessMsp It Goverance And Service Delivery Process
Msp It Goverance And Service Delivery Processkadhar_masthan
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfSALES97
 
Frameworks For Predictability
Frameworks For PredictabilityFrameworks For Predictability
Frameworks For Predictabilitytlknecht
 
ISO 27001 ISMS MEASUREMENT
ISO 27001 ISMS MEASUREMENTISO 27001 ISMS MEASUREMENT
ISO 27001 ISMS MEASUREMENTGaffri Johnson
 
IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...GrapesTech Solutions
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and TrendsMaclear LLC
 
CISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of ITCISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of ITShivamSharma909
 
Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811faau09
 
CoBIT 5 (A brief Description)
CoBIT 5 (A brief Description)CoBIT 5 (A brief Description)
CoBIT 5 (A brief Description)Sam Mandebvu
 
Data Management Strategies
Data Management StrategiesData Management Strategies
Data Management StrategiesMicheal Axelsen
 
ISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptxISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptxjojo82637
 

Similar a gray_audit_presentation.ppt (20)

It governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yungIt governance in_higher_education_by_james_yung
It governance in_higher_education_by_james_yung
 
02. cobit 41 dan iso 17799
02. cobit 41 dan iso 1779902. cobit 41 dan iso 17799
02. cobit 41 dan iso 17799
 
Risk - IT Services
Risk - IT ServicesRisk - IT Services
Risk - IT Services
 
Governance and management of IT.pptx
Governance and management of IT.pptxGovernance and management of IT.pptx
Governance and management of IT.pptx
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic Approach
 
Msp It Goverance And Service Delivery Process
Msp It Goverance And Service Delivery ProcessMsp It Goverance And Service Delivery Process
Msp It Goverance And Service Delivery Process
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdf
 
Frameworks For Predictability
Frameworks For PredictabilityFrameworks For Predictability
Frameworks For Predictability
 
ISO 27001 ISMS MEASUREMENT
ISO 27001 ISMS MEASUREMENTISO 27001 ISMS MEASUREMENT
ISO 27001 ISMS MEASUREMENT
 
IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...IT Governance and Compliance: Its Importance and the Best Practices to Follow...
IT Governance and Compliance: Its Importance and the Best Practices to Follow...
 
Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
CISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of ITCISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of IT
 
Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811Marcos cobi t -e-itil-v040811
Marcos cobi t -e-itil-v040811
 
Process
ProcessProcess
Process
 
An IT Governance program
An IT Governance programAn IT Governance program
An IT Governance program
 
01 intro-cobit
01 intro-cobit01 intro-cobit
01 intro-cobit
 
CoBIT 5 (A brief Description)
CoBIT 5 (A brief Description)CoBIT 5 (A brief Description)
CoBIT 5 (A brief Description)
 
Data Management Strategies
Data Management StrategiesData Management Strategies
Data Management Strategies
 
ISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptxISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptx
 

Último

5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdfWave PLM
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsJhone kinadey
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...MyIntelliSource, Inc.
 
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...MyIntelliSource, Inc.
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxComplianceQuest1
 
Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxbodapatigopi8531
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...harshavardhanraghave
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...kellynguyen01
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsAndolasoft Inc
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AIABDERRAOUF MEHENNI
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️Delhi Call girls
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionSolGuruz
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsArshad QA
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerThousandEyes
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfkalichargn70th171
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsAlberto González Trastoy
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️anilsa9823
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comFatema Valibhai
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVshikhaohhpro
 

Último (20)

5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial Goals
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
 
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docx
 
Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptx
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.js
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with Precision
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview Questions
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.com
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 

gray_audit_presentation.ppt

  • 1. Policy Development & The 4 COBIT Domain Processes Policy Development based on COBIT Implementation Craig R. Gray, Director of IS&T cgray@leeuniversity.edu
  • 2. Agenda  Policy Development: Basis & Application  The Mechanics of Control  COBIT-What?  COBIT-4 Domains  High Level Control Examples?
  • 3.
  • 5. Control Statements Control Practices is enabled by and considers IT Processes The control of Business Requirements which satisfy Policy Development Flow
  • 7. What is COBIT?  COBIT (Control Objectives for Information and Related Technology) is globally accepted as being the most comprehensive work for IT governance, organization, as well as IT process and risk management  COBIT provides good practices for the management of IT processes in a manageable and logical structure, meeting the multiple needs of enterprise management by bridging the gaps between business risks, technical issues, control needs and performance measurement requirements.  The COBIT mission is to research, develop, publicize and promote an authoritative, up-to-date, international set of generally accepted information technology control objectives for day-to-day use by business managers and auditors.
  • 8. Starts from the premise that IT needs to deliver the information that the enterprise needs to achieve its objectives. Promotes process focus and process ownership Divides IT into 34 processes belonging to four domains and provides a high level control objective for each Looks at fiduciary, quality and security needs of enterprises,providing seven information criteria that can be used to generically define what the business requires from IT Is supported by a set of 318 detailed control objectives Effectiveness Efficiency Availability Integrity Confidentiality Reliability Compliance Planning Acquiring & Implementing Delivery & Support Monitoring
  • 9. EFFECTIVENESS Deals with information being relevant and pertinent to the business process as well as being delivered in a timely, correct, consistent and usable manner EFFICIENCY Concerns the provision of the information through the optimal use of resources CONFIDENTIALITY Concerns the protection of sensitive information from unauthorized disclosure INTEGRITY Relates to the accuracy and completeness of information as well as to its validity in accordance with business values and expectations AVAILABILITY Relates to the information being available when required by the business process now and in the future COMPLIANCE Deals with complying with laws, regulations and contractual arrangements. RELIABILITY OF INFORMATION Relates to the provision of appropriate information for the workforce of the organization
  • 10. EVENTS  Business Operations  Business Opportunities  External Requirements  Regulations PROCESS TECHNOLOGY ORGANIZATION DATA RISK CRITERIA Effectiveness Efficiency Confidentiality Integrity Availability Compliance Reliability MESSAGE INPUT SERVICE OUTPUT Events can be defined in terms of the processes, technology (systems) and organization (people) that compose them Information Risk Criteria
  • 11. The 4 COBIT Domains  Planning & Organization  Acquisition & Implementation  Delivery & Support  Monitoring
  • 12. Planning and Organization  This domain covers strategy and tactics, and concerns the identification of the way IT can best contribute to the achievement of the business objectives.  Furthermore, the realization of the strategic vision needs to be planned, communicated and managed for different perspectives.  Finally, a proper organization as well as technological infrastructure must be put in place.
  • 13. Acquisition and Implementation  To realize the IT strategy, IT solutions need to be identified, developed or acquired, as well as implemented and integrated into the business process.  In addition, changes in and maintenance of existing systems are covered by this domain to make sure that the life cycle is continued for these systems.
  • 14. Delivery and Support  This domain is concerned with the actual delivery of required services, which range from traditional operations over security and continuity aspects to training.  In order to deliver services, the necessary support processes must be set up.  This domain includes the actual processing of data by application systems, often classified under application controls.
  • 15. Monitoring  All IT processes need to be regularly assessed over time for their quality and compliance with control requirements.  This domain thus addresses management’s oversight of the organization's control process and independent assurance provided by internal and external audit or obtained from alternative sources.
  • 16. Executive Summary There is a method… Framework The method is… Control Objectives Minimum controls are… Audit Guidelines Here is how you audit… Implementation Toolset Here is how you implement… Management Guidelines Here is how you measure… COBIT Components
  • 17. COBIT History  Technical Standards  ISO, EDIFACT  Codes of Conduct  Council of Europe, ISACA, OECD  Qualification Criteria for IT Systems and Processes  ITSEC, TCSEC, ISO 9000, SPICE, TICKIT, Common Criteria  Professional Standards  COSO, IFAC, AICPA, CICA, ISACA, IIA, PCIE, GAO  Industry Practices and Requirements  Industry forums (ESF, 14), Government-sponsored platforms (IBAG, NIST, DTI, BS7799)