Introduction Outline: Importance IT Governance COBIT as an IT control framework ITIL and ITSM SOX compliance COSO as a financial reporting framework
IT Governance Processes include: 4 objectives: IT portfolio management Service-level agreements Chargeback mechanisms IT demand management 4 objectives: Accountability Risk management Performance measurement IT value and alignment
IT Governance Definition: Decisions made around IT investments IT extends company’s strategy Used to align business with IT Pushes company to compliance
COBIT COBIT: Control Objectives for Information and related Technology Set of best practices for IT Control framework for IT Contains 34 control objectives
ITIL ITIL: Information Technology Infrastructure Library Developed in UK by OGC Best practices on managing IT services Complements COBIT Library consists of 8 books
SOX SOX: Sarbanes-Oxley Act enacted in 2002 Framework of internal controls Section 302 and 404 Relevant to financial reports
COSO COSO: Committee of Sponsoring Organizations Control framework that combats fraudulent financial reporting Organizations include: AICPA (American Institute of Certified Public Accountants) IIA (Institute of Internal Auditors) FEI (Financial Executives International) IMA (Institute of Management Accountants) AAA (American Accounting Association)
Conclusion IT Governance has grown more important Control frameworks help support governance IT Governance helps align business and IT Aims to apply a value to IT business functions