Introduction
It is clear that all organizations, especially Padgett-Beale, depend on their
information technology resources for survival and growth in the highly
competitive international market. But, information technology comes with
significant risks to information systems and vital resources due to its nature.
Therefore, the security of information requires to be managed and
controlled properly. For effective management of information security in a
company, Information Security Management Systems (ISMs) are created.
ISMs manage and operate information security systems in hardware,
technology, and management to attain confidentiality, integrity, and
availability. The application of ISMs follows the idea of the plan-Do-Check-
Act (PDCA) cycle. Some of the best practices like COBIT can be used as a
foundation for creating a strong information security process (Sheikhpour &
Modiri, 2012).
COBIT Framework
COBIT (Control Objectives for Information and related Technology) is an IT
governance framework and supporting toolset that enables administrators
to create a gap between control needs, technical issues, and business risks.
COBIT provides administrators, auditors, and IT users with a set of
generally accepted indicators, processes, measures, and best practices to
help them in maximizing the benefits derived through the use of
information technology and create appropriate IT governance and control in
the company. In addition, COBIT will help Padgett-Beale managers
understand their IT systems and decide the level of security and authority
necessary to safeguard our company's assets by creating an IT governance
model (Harvath, 2020). c
Explanation of the guidance and content of the COBIT
From COBIT's point of view, Enterprise governance, which is the system by
which companies are controlled and governed, and IT governance, which is
the system by which company IT is directed, are highly related. Enterprise
governance is not enough without IT governance, and the reverse is true. IT
can develop and affect a company's performance, but it must be subjected
to enough governance. Consequently, business processes need information
from the IT processes, and this association has to be appropriately
governed (Mohr, 2019).
In this subject Plan-Do-Check-Act (PDCA) cycle becomes applicable. The
idea of the PDCA cycle is usually used in structured problem solving and
continuous improvement processes. Both information requirements
(Enterprise governance) and information provision (IT governance) are
planned with measurable and constructive pointers (plan). The information
and the information systems must be implemented, delivered, and used (do).
The information provided and utilized results are gauged against the
pointers defined in the planning level (check). The deviation is investigated,
and corrective actions are taken (act). Considering these associations, it is
clear that the IT processes are not an end. They are a means to an end that
is highly integrated with the management of business processes
(Sheikhpour & Modiri, 2012).
Characteristics of COBIT
1. Business-oriented: It is designed to be used by IT service providers,
users, and auditors and provides comprehensive guidance for
management and business process owners.
2. Process-Oriented: COBIT subdivides IT governance into 34 processes
grouped into four domains at offers a high-level control objective for
each of the thirty-four processes. The four domains are:
▪ Plan and organize
▪ Acquire and Implement
▪ Deliver and Support
▪ Monitor and Evaluate.
3. Control-based: COBIT defines control aims for all the thirty-four
processes and overarching processes and application controls.
4. Measurement-Driven: Enterprises need to gauge where and where
improvements are required and apply a management toolkit to
monitor this improvement.
Principles of COBIT
1. Attaining stakeholders' requirements
2. Covering the company end-to-end
3. Application of a single integrated framework
4. Allowing a holistic approach
5. Separating governance from management.
These five principles enable the company to develop an all-inclusive
framework for the governance and management of IT that is built on seven
enablers
1. Policies, People, and Frameworks
2. Processes
3. Business structure
4. Culture, behavior, and ethics
5. Information
6. Services, infrastructure, and applications
7. People, skills, and competencies.
The principles and the enablers allow the company to align its IT investment
with its goal to realize the value of those investments (IT governance, n.d).
c c c c c c Conclusion
For Padgett-Beal to realize the benefit of IT, it must implement a framework
that enables all the departments to work together for the company's
common goal. Therefore, the COBIT framework suits Padgett-Beale's need
to implement policies and guidelines to ensure client information's security
and privacy. I have explained the COBIT framework, its characteristics,
principles, and enablers. This paper will provide the IT Governance Board
with an overview of COBIT and enable them to determine its importance in
the company.
c References
Harvath. (2020). Benefits of COBIT 5 That Help Achieve Digital
Transformation. Retrieved from:
https://www.invensislearning.com/blog/benefits-of-cobit-5/
IT governance (n.d). What is COBIT 5? Definition & Explanation. Rtrieeved
from https://www.itgovernance.co.uk/cobit
Mohr (2019). IT Frameworks Standards, and Models: A Recipe or Value.
Retrieved from
https://www.thinkhdi.com/library/supportworld/2011/frameworks-
standards-models.aspx
Sheikhpour, R., & Modiri, N. (2012). An approach to map COBIT processes
to ISO/IEC 27001 information security management controls.
International
Journal of Security and Its Applications
,
6
(2), 13-28.