Information Assurance Audit (Due 20 May) (5 Pages) (5 References)

profileBeeye
Chapter5-COBITandtheITGovernanceInstitute.pdf

67

5 C H A P T E R F I V E COBIT and the IT

Governance Institute

EN T E R P R I S E P R O F E S S I O N A L S A N D C E R TA I N LY S E N I O R M A N A G E R S require the use of a set of standards or a framework to govern their IT governance practices and general internal control procedures. Adherence to such a framework allows senior managers as well as enterprise professionals in their area of expertise to be recognized as specialists in their fi eld of operations. The Committee of Sponsoring Organi- zations (COSO) internal control framework, as introduced and discussed in Chapter 4, has become an important IT governance tool for evaluating and improving IT governance processes for a wide span of systems and IT processes as well as the internal accounting controls rules under the Sarbanes-Oxley Act (SOx) introduced in Chapter 2. However, some senior managers and their information technology (IT) professionals, in particular, have expressed concerns with using the COSO internal control framework in today’s IT- oriented world. The concern had been that the published COSO internal control guidance just does not give enough emphasis on IT tools and processes. For example, the original, 1992-published COSO internal control guidance materials (see Chapter 4) primarily look at IT application internal controls at a very high level, even though there is much more of a need for additional IT-specifi c internal control guidance in today’s world.

A more IT-oriented internal control assessment and guidance framework, called COBIT (Control Objectives for Information and related Technology), has actually been in place long before SOx, with COBIT fi rst released in 1996. The COBIT framework was initially developed for the internal and external auditors who reviewed computer sys- tems and technology controls (often called IT auditors), but COBIT also has become a preferred tool in many enterprises for complying with SOx Section 404 internal control procedures and related IT governance support. COBIT provides guidance for evaluat- ing and understanding internal controls, with an emphasis on enterprise IT resources. COBIT is not a replacement for the COSO internal control framework but is a different and sometimes preferable way to look at internal controls in today’s IT-centric world.

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

68 ◾ COBIT and the IT Governance Institute

Although originally launched as guidance to help internal and external IT auditor professionals who reviewed IT-related internal controls, COBIT today has evolved into a helpful tool for assessing IT governance and evaluating all internal controls across an enterprise. It provides emphasis and guidance on the linkage of IT with other business resources to deliver overall values to an enterprise today. It is an important tool to help the senior enterprise executive establish effective IT governance practices.

This chapter will provide an executive-level overview of the COBIT framework and many of its key components. The chapter will introduce the newest version, 5.0, which has just been released at the time of our publication. We will introduce other elements of COBIT, such as its board governance guidance and the COBIT-related Val IT framework, an approach to better recognize the value of all IT assets in the enter- prise. Val IT addresses assumptions, costs, risks, and outcomes related to a balanced portfolio of IT-enabled business investments. The importance of Val IT will be discussed in Chapter 22. In addition, this chapter will describe the relationship between COBIT objectives and the COSO internal control framework, as discussed in Chapter 4.

Although COBIT had its origins as an IT audit guidance tool, it is much broader today. Today’s executives should have a high-level knowledge of the function and pur- poses of the COBIT framework and should be in a position to question both their IT functions and general fi nancial management operations about an enterprise’s use of COBIT in IT governance activities. In addition to the COSO internal control framework, knowledge of COBIT will help a senior manager to better understand the role of IT con- trols, governance processes, and risks in many enterprise environments.

AN EXECUTIVE’S INTRODUCTION TO COBIT

An unusual or strange-sounding word for many, COBIT is an acronym that is becoming increasingly recognized by auditors, IT professionals, and many enterprise managers. Although it is now abbreviated as COBIT, it was originally written and for many years described as CobiT; in either case the acronym stands for Control Objectives for Information and related Technology. Because of the framework’s emphasis on controls and technology, the fi rst and last letters had been capitalized. COBIT is an IT governance internal control frame- work that is an important support tool for documenting and understanding COSO internal controls and SOx requirements, and for recognizing the value of and risks associated with IT assets in an enterprise. Many members of the internal audit staff may have had at least a gen- eral or working knowledge of COBIT, and senior managers throughout the enterprise should also have a general knowledge of COBIT and its importance as an IT governance support tool.

The COBIT standards and framework are issued and regularly updated by the IT Governance Institute (ITGI),1 and the closely affi liated professional organization, the Information Systems Audit and Control Association (ISACA). ISACA is more focused on IT auditing, while ITGI’s emphasis is on research and governance processes. ISACA also manages the Certifi ed IT Auditor (CISA) examination and professional designation as well as other certifi cations such as the Certifi ed Information Systems Manager (CISM) and the Certifi ed in the Governance of Enterprise IT (CGEIT) designation certifi cation and examination. The Certifi ed Information Security Manager (CISM) certifi cation

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

An Executive’s Introduction to COBIT ◾ 69

targets IT security managers and promotes the advancement of professionals who wish to be recognized for their IT governance–related experience and knowledge.

Many IT and regular internal audit staff members in a typical enterprise are mem- bers of ISACA. For nostalgia purposes, ISACA was originally known as the EDP Auditors Association (EDPAA), a professional group that was started in 1967 by internal auditors who felt that their then-professional organization, the Institute of Internal Auditors (IIA), was not giving sufficient attention to the importance of IT systems and technol- ogy controls as part of internal audit activities. We have almost forgotten that EDP once stood for electronic data processing, today an almost archaic term for IT. Over time, this professional enterprise broadened its focus and became ISACA.

The EDPAA, originally an upstart IT audit professional organization, began to develop IT audit professional guidance materials shortly after its formation. Just as the EDPAA evolved into the well-respected ISACA and now the ITGI, its original IT audit standards became an excellent set of internal control objectives that evolved into COBIT, now in its 2011 version 5.0 edition.2 This new edition of the framework was not officially released at the time of our publication, but our comments are based on the final draft releases of this version and the assumption that it will soon become official. With virtually all enterprise processes today tied to IT-related facilities, an understanding of the overall area of IT governance is critical.

The COBIT framework consists of what are called five principles, broad and intercon- nected areas of governance and internal controls, as illustrated in Exhibit 5.1. COBIT’s principles are five major areas of emphasis arranged around the important core concept of IT governance:

COBIT Principle 1: An integrated IT framework. COBIT calls for efforts to align IT operations and activities with all other enterprise operations. These include establishing linkages between enterprise business operations and IT plans as well as processes for defining, maintaining, and validating quality and value relationships. COBIT Principle 2: Stakeholder value drivers. Processes should be in place to ensure that IT and other enterprise operating units deliver promised benefits throughout a delivery cycle and with a strategy that optimizes costs while empha- sizing the intrinsic enterprise values of IT and related activities. COBIT Principle 3: Resources focus on a business context. With an emphasis on IT, there should be optimal investments in, and the proper management of, criti- cal IT resources, applications, information, infrastructure, and people. Effective IT governance depends on this optimization of knowledge and infrastructure. COBIT Principle 4: Risk management. Management, at all levels, should have a clear understanding of an enterprise’s appetite for risk, its compliance require- ments, and the impact of significant risks. Both IT and other operations have their own and joint risk management responsibilities that may individually or jointly impact the entire enterprise. COBIT Principle 5: Performance measurement. Processes should be in place to track and monitor strategy implementation, project completions, resource usage, process performance, and service delivery. IT governance mechanisms should translate implementation strategies into actions and measurements to achieve these goals.

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

70 ◾ COBIT and the IT Governance Institute

These fi ve COBIT principles or areas of emphasis defi ne the COBIT framework’s elements and provide a defi nition for the key elements of IT governance. The COBIT framework is an effective tool for documenting IT and all other internal controls, and this chapter looks at the framework in the broader perspective of using COBIT to assist in the IT governance processes of management, enterprise, and internal auditing.

The following sections provide an overall description of the COBIT framework, in its current version 5.0 fi nal draft format, and COBIT’s key elements that link business with IT goals through key controls and effective measurement metrics. In addition, the chapter will describe the mapping of COBIT standards with the COSO internal control framework, discussed in Chapter 4, the Information Technology Infrastructure Library best practices introduced in Chapter 6, and for overall IT and corporate governance. Elements and key components of IT governance will be discussed as well. The COBIT framework is an effective mechanism for documenting and understanding internal con- trols and managing IT governance processes at all levels. Although COBIT fi rst started primarily as a set of “IT audit” guidance materials, it is a much more powerful tool today.

THE COBIT FRAMEWORK AND ITS DRIVERS

IT processes and their supporting software applications and hardware devices are key components in any enterprise today. Whether a small retail business, with pri- mary needs to keep track of inventory and pay employees, or a very large “Fortune 50”

5. Governance & Management

Structures 1. Need for an Integrated IT Framework

4. Coabler- based

Processes 2. Stakeholder Value

Drivers

3. Focus on Business Context

COBIT IT Governance

Principles

EXHIBIT 5.1 COBIT IT Governance Principles

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

The COBIT Framework and Its Drivers ◾ 71

corporation, all need a wide set of interconnected and often complex IT processes that are closely tied to their business operations. That is, enterprise business processes and their supporting IT resources should work in a close information-sharing relationship. IT cannot and certainly should not tell business operations what types of IT processes and systems they should consider implementing, but IT provides information to help influence these business decisions. In the very early days of computer systems, IT man- agers sometimes felt they had lots of answers and promoted systems solutions for their businesses, sometimes with very counterproductive results. However, this relation- ship has long since changed; IT and business operations generally should have a close mutual relationship of shared requirements and information. An enterprise manager should understand the needs and information-sharing requirements on both sides. IT has responsibilities over a series of other related process areas that are audited by or through established audit guidelines, are measured by a series of performance indica- tor measures and activities, and are made effective through activity goals. All of these become part of COBIT, an IT governance and control framework defining best practices, governance, and internal control objectives for both IT and business processes.

In addition to the COSO internal control framework and SOx internal controls requirements, this chapter introduces COBIT’s new 5.0 version. An enterprise execu- tive might ask, “I think I understand some of the key SOx rules and my enterprise uses COSO internal controls; why should I be concerned about this thing called COBIT, yet another framework?” Our answer here is that COBIT provides an alternative and some- times preferable approach to both define and describe processes that have more of an IT governance emphasis than the pure COSO internal control framework. Information and supporting IT processes often are the most valuable assets for virtually all enterprises today, and management has a major responsibility to safeguard its supporting IT assets, including automated systems. An enterprise executive today needs to understand these information-related processes and the controls that support them. This combination is concerned about the effectiveness and efficiency of their IT resources, processes, and overall business requirements.

The COBIT framework recognizes that information should be considered a key resource for all enterprises, and throughout the whole life cycle of information there is a huge dependency on technology. IT and its related technologies are pervasive in enter- prises and they need to be governed and managed in a holistic manner, taking in the full end-to-end business and IT functional areas of responsibility. Through the effective implementation of COBIT framework guidance, an enterprise should achieve increased:

▪ Value creation through enterprise IT. ▪ Business user satisfaction with IT engagement and services. ▪ Compliance with relevant laws, regulations, and policies.

As discussed, the COBIT framework has continued to evolve and improve over the years. Our comments in this chapter are primarily based on COBIT’s new 5.0 version, which was still in final draft form as this book was being developed. We will also include some references to the previous and well-recognized 4.1 version of COBIT. The new COBIT 5.0 version is a major improvement and provides excellent support and guidance

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

72 ◾ COBIT and the IT Governance Institute

for enhancing IT governance processes. Although there may be some fi nal tweaks when the 5.0 version is offi cially released, many of our descriptions of COBIT will reference this soon-to-be-released fi nal new version. Based on the COBIT IT governance principles shown in Exhibit 5.1, the sections following provide a high-level, executive overview of COBIT and why it is an important IT governance tool.

COBIT PRINCIPLE 1: ESTABLISH AN INTEGRATED IT ARCHITECTURE FRAMEWORK

Architecture describes how we build or the style of our offi ce headquarters, but today it also often refers to an enterprise’s IT architecture technology selections. For example, when IT functions moved away from the centralized legacy mainframe computer sys- tems, now many years ago, to networks of smaller server systems, an enterprise IT function would state that it had adopted or implemented “client–server architecture.” Systems architecture is a term IT functions use to refer to the major hardware or software confi gurations of their IT resources. COBIT has its own architecture; however, a copy of the current published COBIT 5.0 architecture may scare off non-IT specialists because of the diagram’s complexity in its current draft form. Exhibit 5.2 is a simplifi ed diagram of COBIT’s version 5.0 architecture components.

Referencing this COBIT architecture and going back to its beginning steps, an important concept here is that COBIT and other IT governance concern processes are driven by their stakeholder needs, ranging from senior management wishing to improve IT governance processes through perhaps IT local management seeking to improve specifi c application processes. Stakeholders usually are large and differing groups who all have some common as well as sometimes differing interests and concerns with an enterprise’s IT governance processes. These needs are presented or delivered to estab- lished COBIT processes, with an emphasis on IT governance and value objectives. In addition, since COBIT does not just stand by itself, these needs must be coordinated with other existing enterprise standards, frameworks, and processes.

As illustrated in Exhibit 5.2, these needs fl ow through what COBIT calls enablers, a series of separate but interconnected processes discussed later in this chapter. The pur- pose of these enablers is—as the name suggests—to implement and perform governance and management systems processes for enterprise IT. Enablers are broadly defi ned as specifi c processes, mechanisms, or anything that can help to achieve the enterprise governance objectives. This includes resources, such as information and people. The COBIT 5.0 framework defi nes seven categories of enablers:

1. Processes 2. Principles and policies 3. Organizational structures 4. Skills and competences 5. Culture and behavior 6. Service capabilities 7. Information

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

COBIT Principle 1: Establish an Integrated IT Architecture Framework ◾ 73

These enablers interact in a systemic way, meaning that a governance and man- agement system cannot succeed unless all enablers are addressed, dealt with, and their major interactions understood. We will further discuss these COBIT enablers later in this chapter.

The established enablers then provide support to a COBIT knowledge database, including both current guidance materials and structures for future activities. These then provide support for the overall implementation of COBIT processes that also are supported by a series of product and reference guides. The concept or benefi t behind the COBIT architecture is to support the framework’s goals by providing to all stakehold- ers the most complete and up-to-date guidance on the governance and management of enterprise IT. To achieve this benefi t, the COBIT architecture includes a wide range of automated and data-related components such as the guidance materials discussed in our other chapters. The purpose and function of these enablers will be discussed in greater detail below.

EXHIBIT 5.2 COBIT 5 Simpli� ed General Architecture

Stakeholder Needs

COBIT Enablers

(see Exhibit 5.6)

COBIT Knowledge Database Current & Future Guidance

COBIT Framework • Practice Guides • Val IT & Security • Enabler Guides

Knowledge Base Content Filter

Governance Objectives:

Benefits, Risks & Resources

Existing COBIT

& Other

Guidance

Other Standards

& Frameworks

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

74 ◾ COBIT and the IT Governance Institute

COBIT is a set guidance materials that supports major elements of IT governance guidance, incorporating many concepts and topics in enterprise governance and man- agement techniques. Enterprises of all sizes around the world have implemented COBIT in its previous 4.1 version. The new COBIT version 5.0 introduces enhancements to reduce IT-related risks and increase confi dence in the information provided by IT, to enable clear policy development and good practice for IT management, and to increase the value attained from IT and manage compliance.

COBIT PRINCIPLE 2: STAKEHOLDER VALUE DRIVERS

The business focus of COBIT is achieved through identifying all stakeholders and their needs and determining how they link to governance and management decisions and activities. Perhaps it is best to think of these IT process and operations stakeholders in two groups: internal and external. IT operations and processes are very pervasive, and COBIT’s identifi ed internal stakeholders include members of the board of directors, the CEO, chief fi nancial offi cer (CFO), chief information offi cer (CIO), business executives, business pro- cess owners, business managers, risk managers, security managers, service managers, human resources (HR) managers, internal auditors IT users, IT operations managers, and many others. Each of these will have different expectations and exposures to IT gover- nance issues, but Exhibit 5.3 summarizes some typical COBIT internal stakeholder needs.

This list of stakeholder needs represents some but certainly not all of the many concerns of internal users of IT resources. For example, Exhibit 5.3 contains the need, “How can we use IT resources in the most effective and effi cient manner?” A supervisor working in IT operations may think of things in terms of specifi c network processes, while more senior management will often have much more of a big-picture concern around the same question.

EXHIBIT 5.3 Typical COBIT Internal Stakeholder Needs

▪ Given IT security, privacy concerns, and other issues, did we address all IT‐related risks? ▪ Are we running an ef� cient and resilient IT operation? ▪ How can we better control the cost of IT? ▪ How can we use IT resources in the most effective and ef� cient manner? ▪ What are our most effective and ef� cient IT equipment sourcing options? ▪ Do I have enough people to operate and manage IT, and how do I develop and maintain their

skills and manage their performance? ▪ How do we get assurance over the results and performance of IT processes? ▪ Is the information we are processing well secured? ▪ How can we improve business agility through a more � exible IT environment? ▪ Are all levels of management and operations clear on what IT is doing? ▪ How often do IT projects fail to deliver what they promised? ▪ How critical is IT to sustaining the enterprise? ▪ How do we know our business partner’s IT and related operations are secure and reliable? ▪ How do I know the enterprise is compliant with applicable rules and regulations? ▪ How do we know if the enterprise is maintaining an effective system of internal control?

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

COBIT Principle 3: Focus on Business Context ◾ 75

External stakeholders include business partners, suppliers, shareholders, regula- tors/government, external users, customers, standardization organizations, external auditors, consultants, and many others concerned with enterprise IT operations and resources. External stakeholder needs include such questions as:

▪ How do I know if my business partner’s operations are secure and reliable? ▪ How do I know if this enterprise and its organizational units are compliant with

applicable rules and regulations? ▪ How do I know if the enterprise is maintaining an effective system of internal control?

Stakeholder needs are infl uenced by a number of drivers, including strategy changes, a changing business and regulatory environment, and the evolution of tech- nology. These stakeholder needs materialize in a series of potential expectations, con- cerns, or requirements; all of these issues relate to one or more of COBIT’s three generic governance objectives: benefi ts realization, risk balancing, and cost optimization.

Enterprises exist to create value for their stakeholders, so the governance objec- tive for any enterprise—commercial or not—is value creation, realizing benefi ts at an optimal resource cost while optimizing risk. Enterprises have many internal and exter- nal stakeholders, and “creating value” means different—and sometimes confl icting— things to each of them. Governance is about negotiating and deciding solutions among different stakeholders’ value interests. In consequence, an IT governance system must consider all of these stakeholders when making benefi t, resource, and risk assessments and decisions. For each of these value creation components, the question can and should be asked: For whom are the benefi ts and risks, and which IT resources are required?

COBIT PRINCIPLE 3: FOCUS ON BUSINESS CONTEXT

As mentioned in our earlier comments, COBIT got its start as essentially an IT audit tool, an improved set of recommended processes to review and assess IT internal control procedures. How things have changed over the years! Today, the COBIT framework pro- vides a strong set of guidance materials to help an enterprise improve its IT governance processes, and a core principle of COBIT is its focus on a business context.

COBIT’s third key principle emphasizes that business enterprises exist to create value for their stakeholders. There are three COBIT-defi ned governance value objectives here:

1. Benefi ts realization 2. Risk optimization 3. Resource optimization

COBIT links each of these three objectives to fi nancial, customer-related, and enter- prise-internal enterprise goals. COBIT also defi nes a set of enterprise fi nancial goals, separated in terms of fi nancial, customer, internal, and learning and growth enter- prise goal categories. Exhibit 5.4 shows a summary of these COBIT governance objec- tives goals mapped to enterprise fi nancial goals in terms of where there is a primary or

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

76 ◾ COBIT and the IT Governance Institute

EXHIBIT 5.4 COBIT Summary Governance Objectives Mapped to Enterprise Goals

GOVERNANCE OBJECTIVES

ENTERPRISE GOALS BENEFITS

REALIZATION RISK

OPTIMIZATION RESOURCE

OPTIMIZATION

F IN

A N

C IA

L

1. STAKEHOLDER VALUE OF BUSINESS INVESTMENTS

P

2. PORTFOLIO OF COMPETITIVE PRODUCTS AND SERVICES

P S

3. MANAGED BUSINESS RISKS (SAFEGUARDING OF ASSETS)

P S

4. COMPLIANCE WITH EXTERNAL LAWS AND REGULATIONS

P

5. FINANCIAL TRANSPARENCY

P S S

C U

S T O

M E

R

6. CUSTOMER‐ORIENTED SERVICE CULTURE

P S

7. BUSINESS SERVICE CONTINUITY AND AVAILABILITY

P

8. AGILE RESPONSES TO A CHANGING BUSINESS ENVIRONMENT

P S

9. INFORMATION‐BASED STRATEGIC DECISION MAKING

P P P

10. OPTIMIZATION OF SERVICE DELIVERY COSTS

P

IN T

E R

N A

L

11. OPTIMIZATION OF BUSINESS PROCESS FUNCTIONALITY

P P

12. OPTIMIZATION OF BUSINESS PROCESS COSTS

P P P

13. MANAGED BUSINESS CHANGE PROGRAMS

P S

14. OPERATIONAL AND STAFF PRODUCTIVITY

P P

15. COMPLIANCE WITH INTERNAL POLICIES

S S

GROWTH

16. SKILLED AND MOTIVATED PEOPLE

P P

17. PRODUCT AND BUSINESS INNOVATION CULTURE

P

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

COBIT Principle 3: Focus on Business Context ◾ 77

secondary relationship to the COBIT-defi ned governance value objective. Exhibit 5.5 is a more detailed document for just the fi nancial goal objective. The published COBIT source materials show more detailed relationships for each of the three governance objectives, each mapped to enterprise goals.

This detailed mapping helps to describe COBIT’s Principle 3, its focus on a business context. These relationships should help management at all levels and staff members to better understand the relationships and connections between IT processes and both internal and external business activities.

EXHIBIT 5.5 COBIT Detailed Financial Governance Objectives Mapped to Enterprise Goals

ENTERPRISE IT GOALS

Enterprise Financial Goals

C o

m p

lia n

ce w

it h e

xt e

rn al

la

w s

an d

r e

g u

la ti

o n

s

M an

ag e

d b

u si

n e

ss r

is ks

(S

af e

g u

ar d

in g

o f

as se

ts )

P o

rf o

lio o

f co

m p

e ti

tv e

p ro

d u

ct s

an d

s e

rv ic

e s

S ta

ke h

o ld

e r

va lu

e o

f b

u si

n e

ss in

ve st

m e

n ts

F in

an ci

al t

ra n

sp ar

e n

cy

1 2 3 4 5

F IN

A N

C IA

L

1. STAKEHOLDER VALUE OF BUSINESS INVESTMENTS

S P P

2. PORTFOLIO OF COMPETITIVE PRODUCTS AND SERVICES

P S S

3. MANAGED BUSINESS RISKS (SAFEGUARDING OF ASSETS)

S S P

4. COMPLIANCE WITH EXTERNAL LAWS AND REGULATIONS

S P

5. FINANCIAL TRANSPARENCY P P

C U

S T O

M E

R

6. CUSTOMER‐ORIENTED SERVICE CULTURE S S 7. BUSINESS SERVICE CONTINUITY AND

AVAILABILITY S S P P P

8. AGILE RESPONSES TO A CHANGING BUSINESS ENVIRONMENT

S S S

9. INFORMATION‐BASED STRATEGIC DECISION MAKING

S P S

10. OPTIMIZATION OF SERVICE DELIVERY COSTS P P

IN T

E R

N A

L

11. OPTIMIZATION OF BUSINESS PROCESS FUNCTIONALITY

P P

12. OPTIMIZATION OF BUSINESS PROCESS COSTS S S S 13. MANAGED BUSINESS CHANGE PROGRAMS S S P 14. OPERATIONAL AND STAFF PRODUCTIVITY S S P S 15. COMPLIANCE WITH INTERNAL POLICIES S S

GROWTH 16. SKILLED AND MOTIVATED PEOPLE P S S 17. PRODUCT AND BUSINESS INNOVATION

CULTURE P S

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

78 ◾ COBIT and the IT Governance Institute

COBIT PRINCIPLE 4: GOVERNANCE AND RISK MANAGEMENT ENABLERS

As outlined in our summary description of COBIT’s architecture, enablers are key ele- ments in the COBIT governance process. They are the tangible and intangible elements that make something work—in this case, governance and management over enterprise IT. The COBIT 5.0 simplifi ed general architecture in Exhibit 5.2 shows a function called enablers in the center of the overall process. These enablers should be adopted by an enterprise for the governance of IT.

COBIT has defi ned seven different classes or types of these enablers, as separately illustrated in Exhibit 5.6. To achieve its main objectives, an enterprise must always recognize that it has and manages an interconnected set of these enablers. The general architecture diagram shows seven categories of interconnected enablers. The COBIT- designated enablers are:

1. Processes. These are organized sets of practices and activities that achieve certain objectives and produce a set of outputs in support of achieving overall IT-related goals.

2. Culture, ethics, behavior. A strong enterprise culture with an emphasis on busi- ness ethics and stakeholder behaviors to support those values are often underesti- mated but important enabler success factors.

3. Organizational structures. Activities, policies, and organizational arrange- ments represent key decision-making vehicles in an organization.

4. Information. Critical as a pervasive element throughout any organization, infor- mation is required for keeping the organization running and well governed, but at the operational level, information is very often the key product of the enterprise itself.

5. Principles and policies. These enabler factors are a vehicle to translate desired behavior into practical guidance for day-to-day management.

6. Skills and competences. These attributes are linked to people and are required for the successful completion of all activities and for making correct decisions.

7. Service capabilities. This enabler includes the infrastructure, technology, and applications that provide the enterprise with information processing and services.

None of these enabler categories exists separately but all need the input of other COBIT-defi ned enablers to be fully effective. For example, processes need the informa- tion enabler, organizational structures need people enablers, and people need skills and behavior. The enablers deliver output to the benefi t of other enablers (e.g., processes deliver information, skills, and behavior). Each of these seven COBIT-defi ned enablers shown in Exhibit 5.6 has its own fi ve specifi c components:

1. Enabler stakeholders. Although we have discussed the importance of stakehold- ers as drivers of the overall COBIT process, each of the seven enablers here will have its own internal and external stakeholders.

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

COBIT Principle 4: Governance and Risk Management Enablers ◾ 79

Processes have internal and external stakeholders, each with its own roles; stake- holders and their responsibility levels should be documented in a manner that rep- resents attributes of the process.

2. Goals and metrics. Enabler goals should be defi ned as a statement describing the desired outcome of a process. An outcome can be an artifact, a signifi cant change of a state, or a signifi cant capability improvement of other processes. They are part of the process goals that support IT-related goals, which in turn support enterprise goals. At each level, metrics should defi ne and measure the extent to which these goals are achieved. Metrics can be defi ned as a quantifi able entity and should be specifi c, measurable, actionable, relevant, and timely.

Goals can be classifi ed in various ways, ranging from economic goals, which are more effi ciency-oriented, to quality goals, which are more effectiveness-oriented.

Processes & Information

Culture, Ethics & Behavior

Organizational Structures

Service Capabilities

Skills & Competencies

Principles & Policies

EXHIBIT 5.6 COBIT Classes or Types of Enablers

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

80 ◾ COBIT and the IT Governance Institute

Likewise, there are two types of process metrics: performance metrics, which have a predictive character, indicating the extent to which the process is performing in terms of activities, and outcome metrics, which indicate the extent to which the process really has achieved its goals and purpose.

3. Enabler life cycles. Each of these should be supported by plans to establish them and then build, acquire, create, and implement. After their use or operation, the enabler should be periodically monitored and evaluated with an objective update or disposed as required.

4. Good practices. Internal and external practices should be installed using tools such as the COBIT framework as well. Good practices enablers have internal and external elements. Both of these include people-skill good practices, includ- ing the need for objective skill requirements for each role played by the various stakeholders. This can be described through defi ned job descriptions for different skill levels in different skill categories. The skill categories correspond with IT- related activities such as telecommunications network management or business analysis.

5. Enabler attributes. Each of these will have some unique components that set them apart from other enterprise enablers.

Enabler is a term or concept that was not that common in business operations and processes all that many years ago. The expression fi rst became more common in aca- demic papers on IT issues. We should remember that an enabler is a tool or process that provides measurable capabilities and competencies that enhance, rather than just auto- mate, business processes. They are capabilities, forces, and resources that contribute to the success of an entity, activity, or project. They are worthwhile concepts to add to one’s business vocabulary.

COBIT PRINCIPLE 5: GOVERNANCE AND MANAGEMENT PERFORMANCE MEASUREMENT STRUCTURES

COBIT’s last key principle focuses on the importance of separate but related concepts of management and governance in an IT-oriented enterprise. The COBIT 5.0 framework makes a clear distinction between governance and management. The two disciplines include different types of activities, require different organizational structures, and serve different purposes. This distinction is a key to COBIT’s view of governance and management.

We often forget that governance, a popular term in business today, is derived from the Greek verb meaning “to steer.” A governance system refers to all the means and mechanisms that enable multiple stakeholders in an enterprise to have an organized say in evaluating conditions and options; setting direction; and monitoring compli- ance, performance, and progress against plans, to satisfy specifi c enterprise objectives. This all refers to a major set of steering activities. Means and mechanisms here include frameworks, principles, policies, sponsorship, structures, and decision mechanisms, as well as roles and responsibilities, processes, and practices to set direction and monitor

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

Putting It Together: Matching COBIT Processes and IT Goals ◾ 81

compliance and performance aligned with the overall objectives. This is a rather large and extensive defi nition of IT governance, but the chapters following will discuss other issues that support this defi nition. We should always remember that in most enterprises, governance is the responsibility of the board of directors under the leadership of the CEO and chairperson.

Often differentiated from governance, management entails the judicious use of resources, people, processes, practices, and so on to achieve an identifi ed end. It is the means or instrument by which the governance body achieves a result or objective. Man- agement is responsible for execution within the direction set by the guiding body or unit. Management is about planning, building, organizing, and controlling operational activities to align with the direction set by the governance body.

The COBIT guidance emphasizes that governance and management are dif- ferent types of activities, with different responsibilities. However, given the role of governance—to evaluate, direct, and monitor—a set of interactions is required between governance and management to result in an effi cient and effective governance system. These interactions, using the enabler structure, are then tied to specifi c internal control review processes, the real strength of the COBIT framework.

PUTTING IT TOGETHER: MATCHING COBIT PROCESSES AND IT GOALS

The published COBIT framework and its supporting materials defi ne a high-level group of processes that set the direction for enterprise business goals and IT resources. Tailored for virtually all types and sizes of enterprises, these are classifi ed in two groups, fi rst as processes for the governance of enterprise IT, and then a second, separate group of processes providing guidance for the management of enterprise IT. Each of these two includes a series of more detailed process categories. For the management of enterprise IT, there are process groups to:

▪ Align, plan, and organize. ▪ Build, acquire, and implement. ▪ Deliver, service, and support. ▪ Evaluate, direct, and monitor.

Each of these groups then contains more specifi c COBIT processes. For the build, acquire, and implement group, COBIT guidance is organized in categories of internal control objectives, using the following COBIT-defi ned coding names:

BAI1—Manage programs and projects BAI2—Defi ne requirements BAI3—Identify and build solutions BAI4—Manage availability and capacity BAI5—Enable organizational change BAI6—Manage changes

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

82 ◾ COBIT and the IT Governance Institute

BAI7—Accept and transition changes BAI8—Manage knowledge

Similar sets of control objective process categories have been defined for each of the listed process categories. The purpose of the detailed but fairly specific control processes is to help make a business case for the implementation and improvement of the gover- nance and management of IT. Their objective is to recognize both their typical pain points and trigger events, with an overall objective of creating the right environment for IT operations and implementations.

COBIT has defined a set of 17 IT-related goals that can be mapped to each of these processes. These goals also are divided into categories labeled “Corporate,” “Customer,” “Internal,” and “Learning and Growth.” These names may change as COBIT moves from its current final draft version, and a category such as “Corporate” does not mean that the guidance applies just to public corporations but rather to the overall enterprise.

Exhibit 5.7 shows the mapping of COBIT’s IT-related goals to the factors for two COBIT processes: EDM (evaluate, direct, and monitor) and DSS (deliver, service, and support). This mapping shows how each IT-related goal is supported by a COBIT-related process and is illustrated in Exhibit 5.7 and expressed using a scale where:

▪ P stands for a primary connection between the IT-related goal and the connected COBIT-related process, when there is an important relationship where the des- ignated COBIT process is a primary support for the achievement of an IT-related goal.

▪ S stands for secondary, when there is still a less important relationship, and the COBIT process is a secondary support for the IT-related goal.

▪ Blank when there is no strong relationship here.

For example, the DSS7 COBIT process to “Manage security” has a strong or primary relationship with the IT-related goal IT called or designated as compliance and support for business-related laws and regulations. That same DSS7 process also has secondary relationships with several other IT goals, such as number 7, the delivery of IT services in line with business requirements.

The COBIT guidance emphasizes that governance and management are different types of activities, each with different responsibilities. However, given governance’s steering role—to evaluate, direct, and monitor—a set of interactions is required between governance and management to result in an efficient and effective governance system. These interactions, using the enabler structure, are then tied to specific COBIT internal control review processes, the real strength of the framework.

For many more senior managers, the COBIT framework may seem almost too detailed, with far too complex sets of objectives and goals. Optimal value can be real- ized from leveraging COBIT only if it is effectively adopted and adapted to suit each enterprise’s unique environment. Each implementation approach will also need to address specific challenges, including managing changes to culture and behavior. This chapter has merely touched on the overall structure of COBIT and its current version 5.0.

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

EXHIBIT 5.7 COBIT Goal and IT Objective Mapping Example

IT-related Goals A

lig n

m e

n t

o f

IT &

b u

si n

e ss

s tr

at e

g y

IT c

o m

p lia

n ce

& s

u p

p o

rt f

o r

b u

si n

e ss

co

m p

lia n

ce w

it h la

w s

& r

e g

u la

ti o

n s

C o

m m

it m

e n

t o

f e

xe cu

ti ve

m

an ag

e m

e n

t fo

r m

ak in

g I T-

re la

te d

d

e ci

si o

n s

M an

ag e

d I T-

re la

te d

b u

si n

e ss

r is

ks

R e

al iz

e d

b e

n e

� ts

f ro

m I T-

re la

te d

in

ve st

m e

n ts

& s

e rv

ic e

s p

o rt

fo lio

Tr an

sp ar

e n

cy o

f IT

c o

st s,

b e

n e

� ts

&

ta sk

s D

e liv

e ry

o f

IT s

e rv

ic e

s in

li n

e w

it h

b u

si n

e ss

r e

q u

ir e

m e

n ts

A d

e q

u at

e u

se o

f ap

p lic

at io

n s,

in

fo rm

at io

n &

t e

ch n

o lo

g y

so lu

ti o

n s

IT a

g ili

ty S

e cu

ri ty

o f

in fo

rm at

io n , IT

p ro

ce ss

in g

in

fr as

tr u

ct u

re &

a p

p lic

at io

n s

O p

ti m

iz at

io n o

f IT

a ss

e ts

, re

so u

rc e

s &

ca

p ab

ili ti

e s

E n

ab le

m e

n t

& s

u p

p o

rt o

f in

te g

ra ti

n g

ap

p lic

at io

n s

& t

e ch

n o

lo g

y in

to

b u

si n

e ss

p ro

ce ss

e s

O p

ti m

iz at

io n o

f IT

r e

so u

rc e

s &

ca

p ab

ili ti

e s

A va

ila b

ili ty

o f

re lia

b le

& u

se fu

l in

fo rm

at io

n

IT c

o m

p lia

n ce

w it

h in

te rn

al p

o lic

ie s

C o

m p

e te

n t

& m

o ti

va te

d I T

p e

rs o

n n

e l

K n

o w

le d

g e,

e xp

e rt

is e &

in it

ia ti

ve s

fo r

b u

si n

e ss

in n

o va

ti o

n

COBIT Processes

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17

Corporate Customer Internal Learning & Growth

E va

lu at

e, D

ir e

ct

& M

o n

it o

r

EDM1 Set and maintain the governance framework

P S P S S S P S S S S S S S S S

EDM2 Ensure value optimization P S P P P S S S S S S P

EDM3 Ensure risk optimization S S S P P S S P S S P S S

EDM4 Ensure resource optimization S S S S S S P P S P S

EDM5 Ensure stakeholder transparency S S P P P S S S S

D e

liv e

r, S

e rv

ic e

& S

u p

p o

rt

DSS1 Manage operations S P S S S S S P S S DSS2 Manage processes S P S S S P S S S S DSS3 Manage con� guration S S S S S S S DSS4 Manage service requests & incidents P S S S S DSS5 Manage problems S P S S S S P P P P S S DSS6 Manage continuity S S P S P S S S S P S S S DSS7 Manage security S P P S S P S S DSS8 Manage business process controls S P P S S S S S S S

83 Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

84 ◾ COBIT and the IT Governance Institute

USING COBIT IN A SOX ENVIRONMENT

When SOx fi rst became effective in the United States, there was little guidance on how to implement and manage SOx Section 404 internal control reviews. The Public Company Accounting Oversight Board, introduced in Chapter 2, indicated that it was going to establish some specifi c standards but initially left enterprises and their external audi- tors on their own. With its heavy emphasis on high-level IT-oriented internal controls, many enterprises have adopted COBIT as the internal control framework of choice to help achieve SOx compliance.

The SOx Section 404 internal control assessment requirements have highlighted risk-based approaches for evaluating internal controls with an emphasis on the COSO internal control framework, discussed in Chapter 4. COBIT is a powerful alternative internal control assessment framework, particularly in environments with a heavy concentration of IT processes and resources. Both COSO internal controls and COBIT can be described as multidimensional frameworks to describe their internal control environments. Each is similar but with slight differences in classifi cations and terminol- ogy. Exhibit 5.8 shows how the COBIT framework maps to the COSO internal control

EXHIBIT 5.8 Relationship between COSO Components and COBIT Objectives

Control Environment

S e

c ti

o n

3 0

2

Risk Assessments

Control Activities

Information and Communication

Monitoring

IT P

ro ce

ss es

Bu si

ne ss

R eq

ui re

m en

ts

Co nt

ro l

St at

em en

t s

Co nt

ro l

Pr oc

ed ur

es

S e

c ti

o n

4 0

4

COBIT Objectives

C O

S O

I n

te rn

a l

C o

n tr

o l

C o

m p

o n

e n

ts

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

COBIT in Perspective ◾ 85

model. COBIT’s objectives, from planning and enterprise to monitoring and evaluation, can be used to understand and evaluate internal controls through COSO’s fi ve internal control components. Whether considering COSO internal controls in general or using COBIT, an analysis of these two that moves through a series of processes from planning to performing risk assessments and on to identifying, documenting, and evaluating key internal controls all will help an enterprise to achieve SOx Section 404 compliance. In addition, with its support of the ITGI professional organization and its widespread international acceptance, COBIT is a living document that is updated from time to time.

With SOx, the increased emphasis on IT governance, and the recognition of the criticality of IT in most internal control decisions, COBIT has gone through multiple revisions up through its current soon-to-be-released 5.0 edition. COBIT’s sponsoring IT Governance Institute has been doing an excellent job releasing publications that map the COBIT framework to these other standards.

The full set of COBIT control objectives materials will provide strong support for a management team performing a SOx Section 404 internal control assessment review. While the concepts can be used in any internal control area, the emphasis is on IT appli- cations and processes. For many enterprises, an understanding and assessment of those IT-associated internal controls is a key to achieving SOx compliance. COBIT has been around for some years now, but for too long, many had viewed it as just a specialized IT audit tool and not a more general help for other internal audit and internal controls assessment work. Although COBIT’s emphasis continues to be on IT, senior managers should explore this framework as an excellent tool for helping with current and evolving SOx compliance requirements.

COBIT IN PERSPECTIVE

Whether operational, fi nancial, or IT specialists, all enterprise senior managers should have at least a high-level understanding of the COBIT framework. It is a particularly use- ful and important tool for assessing internal fi nancial controls and overall governance processes in a more IT-oriented environment—the type of environment that we almost always encounter today. The decision to use COBIT in IT governance processes should not be a onetime or individual senior manager’s decision. Rather, senior managers as well as their enterprise internal control specialists and internal auditors should develop objectives and take steps to implement the COBIT framework.

COBIT is an elegant—sometimes too elegant—internal control framework and evaluation tool for establishing IT governance processes and assessing internal controls. Perhaps the largest more senior management impediment to its overall use is that COBIT was originally constructed as primarily an IT audit tool. Although the move from ISACA to the ITGI sponsorship has broadened its appeal and focus, there is a very heavy IT focus in many of the published COBIT guidance materials. This certainly scares away some.

The real strength of COBIT is its IT governance focus as described in Exhibit 5.1. That exhibit illustrates the importance of the strategic alliance of business and IT resources with value delivery, resource management, risk management, and performance mea- surement processes. These allow an enterprise to establish effective IT governance, and

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.

86 ◾ COBIT and the IT Governance Institute

COBIT should help in managing and understanding these concepts. We can expect COBIT published standards and practices to continue to broaden and go beyond just its original “IT audit” special concepts.

NOTES

1. IT Governance Institute (ITGI) and the Information Systems Audit and Control Association (ISACA), both at Rolling Meadows, IL.

2. COBIT 5: The Framework Exposure Draft (Rolling Meadows, IL: IT Governance Institute, 2011).

Moeller, Robert R.. Executive's Guide to IT Governance : Improving Systems Processes with Service Management, COBIT, and ITIL, John Wiley & Sons, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/trident/detail.action?docID=1119800. Created from trident on 2021-05-14 09:54:12.

C op

yr ig

ht ©

2 01

3. J

oh n

W ile

y &

S on

s, In

co rp

or at

ed . A

ll rig

ht s

re se

rv ed

.