ITIL & COBIT O6PLM Kevin Lisay – Rendy Winarta –

Slides:



Advertisements
Similar presentations
Program Management Office (PMO) Design
Advertisements

Enterprise Architecture Rapid Assessment
Developing a Successful Integrated Audit Approach September 14, 2010.
Global Congress Global Leadership Vision for Project Management.
Achieve Benefit from IT Projects. Aim This presentation is prepared to support and give a general overview of the ‘How to Achieve Benefits from IT Projects’
Course: e-Governance Project Lifecycle Day 1
Test Automation Success: Choosing the Right People & Process
© Sigma (Bookham) Ltd British Computer Society 19 March 2007 'Embedding Benefit Realisation Management – Friends Provident’s experiences Ann Watts – Head.
Chapter 10 Accounting Information Systems and Internal Controls
Strategy 2022: A Holistic View Tony Hayes International President ISACA © 2012, ISACA. All rights reserved.
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
Dr. Julian Lo Consulting Director ITIL v3 Expert
IT Infrastructure Library ITIL vs COBIT. ANDRIAN EDUARD BANGGA IKHSAN BASKARA JOOVANNY PASUHUK RANGGA FAJARULLAH TEAM.
1 LBNL Enterprise Computing (EC) January 2003 LBNL Enterprise Computing.
Sarbanes-Oxley Compliance Process Automation
Program Management Overview (An Introduction)
By Collin Smith COBIT Introduction By Collin Smith
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
Training.
project management office(PMO)
A District Perspective Thomas Purwin, Jersey City Public Schools
How can projects be controlled?
Chicagoland IASA Spring Conference
Internal Auditing and Outsourcing
Project Management An Overview John Mulhall MIICM; LIB International Credit & Process Management Professional.
Project Human Resource Management
Chapter : Software Process
Mission Assurance SI International’s Quality Management System John Wheeler Director, Mission Assurance 16, April 2008.
COBIT®. COBIT - Control Objectives for Information and related Technology C OBI T was initially created by the Information Systems Audit & Control Foundation.
A NASSCOM ® Initiative Security and Quality Kamlesh Bajaj CEO, DSCI May 23, 2009 NASSCOM Quality Summit Hyderabad 1.
Challenges Faced in Developing Audit Plans and Programs 21 st March, 2013.
QAD's Customer Engagement Dan Blake Consultancy Development Director, QAD QAD Explore 2012.
© Loyalist Certification Services, 2009 Certified Process Design Engineer (CPDE) ®
The Evergreen, Background, Methodology and IT Service Management Model
PMP® Exam Preparation Course
Copyright © 2002 Open Applications Group, Inc. All rights reserved Project Definition Project name - RiskML Project Leader name – ? Date – 9/12/03.
Test Organization and Management
Chapter 3 Internal Controls.
THE REGIONAL MUNICIPALITY OF YORK Information Technology Strategy & 5 Year Plan.
-Nikhil Bhatia 28 th October What is RUP? Central Elements of RUP Project Lifecycle Phases Six Engineering Disciplines Three Supporting Disciplines.
Demystifying the Business Analysis Body of Knowledge Central Iowa IIBA Chapter December 7, 2005.
The Challenge of IT-Business Alignment
Deakin Richard Tan Head, Information Technology Services Division DEAKIN UNIVERSITY 14 th October 2003.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
BPK Strategic Planning: Briefing for Denpasar Regional Office Leadership Team Craig Anderson Ahmed Fajarprana August 11-12, 2005.
IT Requirements Management Balancing Needs and Expectations.
ITIL Framework. What is ITIL ? ITIL stands for the Information Technology Infrastructure Library. ITIL is the international de facto management framework.
Project Plan. Project Plan Components Project Overview – Description and Strategy Business Case Summary Key Deliverables and Scope Critical Success Factors.
1 Chapter Nine Conducting the IT Audit Lecture Outline Audit Standards IT Audit Life Cycle Four Main Types of IT Audits Using COBIT to Perform an Audit.
Practical Investment Assurance Framework PIAF Copyright © 2009 Group Joy Pty. Ltd. All rights reserved. Recommended for C- Level Executives.
Samantha Schreiner University of Illinois at Urbana- Champaign BA 559 – Professor Michael Shaw December 15 th, 2008 A Survey of IT Governance Through COBIT,
Institute of Internal Auditors COBIT Presentation October 9, 2001.
COBIT®. COBIT® - Control Objectives for Information and related Technology. C OBI T was initially created by the Information Systems Audit & Control Foundation.
Enterprise Service Management (ESM) An Approach for Adopting and Adapting Best Practice Programs to Manage, Secure and Improve an Organizations Information.
Company: Cincinnati Insurance Company Position: IT Governance Risk & Compliance Service Manager Location: Fairfield, OH About the Company : The Cincinnati.
ITIL VS COBIT 06 PLM - Group 9
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
1Third Party Assurance Optimization and Control RationalizationCopyright © 2016 Deloitte Development LLC. All rights reserved. Third-Party Assurance (TPA)
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
CMMI Certification - By Global Certification Consultancy.
International Standards of Supreme Audit Institutions (ISSAIs) Jennifer Thomson Director OPSPF & Chief Financial Management Officer World Bank.
BIL 424 NETWORK ARCHITECTURE AND SERVICE PROVIDING.
Service Organization Control (SOC)
Description of Revision
By Jeff Burklo, Director
What is IT audit? An examination of how IT systems where implemented to ensure that they meet the organization’s business needs without compromising.
KEY INITIATIVE Shared Services Function Management
KEY INITIATIVE Internal Control and Technical Accounting
{Project Name} Organizational Chart, Roles and Responsibilities
Presentation transcript:

ITIL & COBIT O6PLM Kevin Lisay – 1501147113 Rendy Winarta – 1501149226 Steven Ekaputranto - 1501148362 Stefani Trifosa – 1501158893 Gladys Natalia – 1501165476

Background Information Technology is a thing that can’t be missed in this modern world. Effectiveness and efficiency that IT offers are great and gives so much benefit. Any company especially the big one can’t endure to use IT nowadays. In order to make the structure of IT operates really well, many of company use ITIL (Information Technology Infrastructure Library), which is a set of document a set of documents which defines best practices and accepted techniques in Information Technology community. Also COBIT (Control objectives for information and related technology) that helps top tier user (managers, IT professionals and assurance professionals) develop IT itself.

Scope Implementation of Information Technology Infrastructure Library. Implementation of Control Objective for Information and Related Technology. Differences between Information Technology Infrastructure Library and Control Objective for Information and Related Technology.

What is ITIL (Information Technology Infrastructure Library) ITIL is the most widely adopted approach for IT Service Management in the world. It provides a practical, no-nonsense framework for identifying, planning, delivering and supporting IT services to the business.

COBIT? (Control objectives for information and related technology) A model designed to control the IT function. This model was originally developed by the Information System Audit and control foundation (ISACF). COBIT support IT governance by providing a comprehensive description of the control objectives for IT processes and by offering the possibility of examining the maturity of these processes.

Implementation of Information Technology Infrastructure Library.

1.Process Implementation Objective The objective of this document is to provide a template for developing process implementation plans that will be usable across a wide range of diverse organizations Program Management

2. Process Implementation Projects Process, People And Technology (The Integrated Project Plan) Project Timelines Expected Project Deliverables Implementation Roles Process Owner Core Process Team Stakeholder Groups And Subject Matter Experts Internal and External Process Advisors Pink Elephant Consulting Roles High Level Process Model Development

3. Process Embedding Strategy Process Workshops / Training Develop Lesson Plans Schedule Workshop And Process Embedding Date Coaching Period Initial Process Review And Adjustment Detailed Activities (Project Check List) People Involved Awareness Campaign Systems Implementation Activities Support Tools Post Implementation and Audit Other Considerations

4. Evaluationof The Project Post Project Review Auditing Using Quality Parameters Generic Quality Parameters for IT Service Management Process Specific Quality Parameters for IT Service Management

Implementation of Control Objective for Information and Related Technology.

1. Background The bank in the given case is a global conglomerate with operations in more than 50 countries and with more than 125,000 employees across the globe. The bank’s technology teams are located throughout the world to support global lines of business. The IT teams include development centers that are part of the bank and others that are outsourced to vendors, as well as technology back offices that support IT infrastructure and services. The bank had a history of multiple governance and assurance templates and processes followed by different teams, regions and locations. Hence, the key challenge was to create a common governance and assurance process across technology teams.

2. Use of COBIT Defining a framework to use—Control objective framework (COF) Identifying a standard definition of ‘entities’ against which risks and controls were to be evaluated—Key entity management model Identifying a risk management process— Risk and control assessment (RCA)

Defining COF It should act as a tool to facilitate the effective assessment of risks and controls within technology. It should act as a reporting framework to demonstrate how technology satisfies reporting regulatory requirements, including those of Sarbanes- Oxley. It should act as an aid to drive management assurance. The steps in implementing COF using COBIT included: Identify principal risks Identify level II risks Identify control objectives

Benefit of Defining COF Prior to implementing this framework, each entity, organization and location had its own set of controls. COBIT helped in developing and managing a single list of controls for each type of risk through the mapping of needed controls to COBIT. In turn, this assisted with the attestation of each type of risk, which provided confidence to senior executives on the reporting and attestation process. Subsequently, a risk assessment process was developed to define risks and controls. This helped in ensuring that adequate controls were deployed to cover the principal risks and level II risks.

Identifying Entities for Managing Risks and Controls Process entities Supporting services entities Technology entities Project entities

Defining and Implementing the RCA Process

Training Key Stakeholders One of the main challenges was to explain the entire process to all of the stakeholders with different backgrounds and understanding of risks and controls and at various locations. The challenge was managed by creating additional training programs at various levels.

Differences Between ITIL and COBIT

- ITIL - COBIT Control Focused Uses IT Metrics Used by auditors in SOX Critical Success Factors Includes a discussion of quality Includes a discussion of process maturity Strong concentration on processes Security is a very important component Focused on service delivery Has a broad base of adopting organizations with lessons learned Has an organization certification schema

Here is a table explaining COBIT, ITIL, and one other framework (CMMi) for SOX :

Another table describing COBIT, ITIL, another framework (CMMi) for non-SOX Objectives