© ITGI not for commercial use. 1 A High-level Overview of the C OBI T Principles, Structure, and Framework John R. Robles Reliable Financial Services C OBI T Framework “This information is copyrighted by the IT Governance Institute and Information Systems Audit and Control Association. Any commercial use is strictly forbidden. It may, however, be used for educational or promotional purposes by ISACA members and chapters on a not- for-profit basis.”
© ITGI not for commercial use. 2 C OBI T Introduction Why does IT need an IT control framework? Who needs an IT control framework? How and why is C OBI T used?
© ITGI not for commercial use. 3 Why does IT need a control framework? Do any of these conditions sound familiar? Increasing pressure to leverage technology in business strategies Growing complexity of IT environments Fragmented IT infrastructures Communication gap between business and IT managers IT service levels that are disappointing from internal IT functions and from increasingly outsourced IT providers IT costs perceived to be out of control Marginal ROI/productivity gains on technology investments Impaired organisational flexibility and nimbleness to change User frustration leading to ad hoc solutions
© ITGI not for commercial use. 4 Increasing dependence on information and the systems that deliver this information Increasing vulnerabilities and a wide spectrum of threats, such as cyberthreats and information warfare Scale and cost of the current and future investments in information and information systems The need to comply with regulations The potential for technologies to dramatically change organisations and business practices, create new opportunities and reduce costs Recognition by many organisations of the potential benefits that technology can yield Successful organisations understand and manage the risks associated with implementing new technologies. Why does IT need a control framework?
© ITGI not for commercial use. 5 IT provides value Cost, time and functionality are as expected IT does not provide surprises Risks are mitigated IT pushes the envelope New opportunities and innovations for process, product and services Why does IT need a control framework? To ensure that management needs to get IT under control.
© ITGI not for commercial use. 6 Board and Executive To ensure management follows and implements the strategic direction for IT Management To make IT investment decisions To balance risk and control investment To benchmark existing and future IT environment Users To obtain assurance on security and control of products and services they acquire internally or externally Auditors To substantiate opinions to management on internal controls To advise on what minimum controls are necessary Who needs a control framework?
© ITGI not for commercial use. 7 Incorporates major international standards Has become the de facto standard for overall control over IT Starts from business requirements Is process-oriented IT Processes IT Management Processes IT Governance Processes CobiT best practices repository for IT Processes IT Management Processes IT Governance Processes C OBI T best practices repository for C OBI T as a response to the needs Why and how is C OBI T used?
© ITGI not for commercial use. 8 Helps substantially increase acceptance and reduce time to implement IT governance program Provides a guide for formal audits/reviews Helps use results of audits as an opportunity to plan improvements Is a strong factor in achieving primary goals for IT governance: transform organisational practices and pursue improved processes Provides economical continuous improvement framework Provides a credible source for management's decision on controls Impresses and helps IT operations managers with its ability to assist in understanding what auditors want Is ideal for business management to communicate requirements and concerns Is recognised as a reliable source reference that ensures identification of all major risk areas Improves communications and relations with IT management Testimonials from Case Studies Why and how is C OBI T used?
© ITGI not for commercial use. 9 To improve audit approach/programmes To support audit work with detailed audit guidelines To provide guidance for IT governance As a valuable benchmark for IS/IT control To improve IS/IT controls To standardise audit approach/programmes Results from Surveys Why and how is C OBI T used?
© ITGI not for commercial use. 10 The C OBI T Framework The C OBI T framework explained: Business focus Process orientation IT resources
© ITGI not for commercial use. 11 Generally applicable and accepted international standard for good practice for IT controls For application to enterprisewide information systems Technology-independent Starting from business requirements for information Management- and business process owner-oriented Based on ISACA's Control Objectives yAligned with de jure and de facto standards and regulations yBased on critical review of tasks and activities or process focus Includes existing standards and regulations yISO, EDIFACT and others yCodes of Conduct issued by Council of Europe yProfessional standards in auditing: COSO, IFAC, IIA, ISACA, AICPA, etc. First published in April 1996, second edition in 1998, third in July 2000 Has become the de facto standard for control over IT Fundamental in achieving IT governance Generally applicable and accepted international standard for good practice for IT controls For application to enterprisewide information systems Technology-independent Starting from business requirements for information Management- and business process owner-oriented Based on ISACA's Control Objectives yAligned with de jure and de facto standards and regulations yBased on critical review of tasks and activities or process focus Includes existing standards and regulations yISO, EDIFACT and others yCodes of Conduct issued by Council of Europe yProfessional standards in auditing: COSO, IFAC, IIA, ISACA, AICPA, etc. First published in April 1996, second edition in 1998, third in July 2000 Has become the de facto standard for control over IT Fundamental in achieving IT governance C OBI T: An IT Control Framework Principles
© ITGI not for commercial use. 12 Starts from the premise that IT needs to deliver the information that the enterprise needs to achieve its objectives Promotes process focus and process ownership Divides IT into 34 processes belonging to four domains and provides a high-level control objective for each Considers fiduciary, quality and security needs of enterprises, providing seven information criteria that can be used to generically define what the business requires from IT Is supported by a set of over 300 detailed control objectives Effectiveness Efficiency Availability Integrity Confidentiality Reliability Compliance Plan and Organise Acquire and Implement Deliver and Support Monitor and Evaluate C OBI T: An IT Control Framework Concepts
© ITGI not for commercial use. 13ITDomains Processes IT Control Objectives Critical Success Factors Outcome Measures Key Performance Indicators Maturity Model IT Control Practices IT is an important element of corporate governance and management accountability. Ensure business-oriented solutions. Framework for risk assessment As a means to communicate with all stakeholders Authoritative basis (internationally accepted, exhaustive, evolving) Why should an organisation adopt C OBI T? C OBI T: An IT Control Framework
© ITGI not for commercial use. 14 “In order to provide the information that the organisation needs to achieve its objectives, IT resources need to be managed by a set of naturally grouped processes.” Relates to business requirements (expressed as information criteria) Links to business processes Empowers business owners Decomposes IT into four domains and 34 processes Domains: (plan-build-run) + monitor Control, audit, implementation and performance management knowledge structured by process Business Process Business Orientation and Process Focus
© ITGI not for commercial use. 15 C OBI T Framework Definition “To provide the information that the organisation needs to achieve its objectives, IT resources need to be managed by a set of naturally grouped processes.” A process orientation is a proven management approach to efficiently exercise responsibilities, achieve set goals and reasonably manage risks. WHY
© ITGI not for commercial use. 16 Quality Requirements Quality Requirements: Quality Delivery Cost Security Requirements Confidentiality Integrity Availability Fiduciary Requirements (COSO Report) Effectiveness and efficiency of operations Compliance with laws and regulations Reliability of financial reporting Effectiveness Efficiency Confidentiality Integrity Availability Compliance Reliability of information Business Requirements
© ITGI not for commercial use. 17 Effectiveness –Deals with information being relevant and pertinent to the business process as well as being delivered in a timely, correct, consistent and usable manner Efficiency –Concerns the provision of information through the optimal (most productive and economical) usage of resources Confidentiality –Concerns protection of sensitive information from unauthorised disclosure Integrity –Relates to the accuracy and completeness of information as well as to its validity in accordance with the business‘s set of values and expectations Availability –Relates to information being available when required by the business process, and hence also concerns the safeguarding of resources Compliance –Deals with complying with those laws, regulations and contractual arrangements to which the business process is subject, i.e., externally imposed business criteria Reliability of information–Relates to systems providing management with appropriate information for it to use in operating the entity, providing financial reporting to users of the financial information, and providing information to report to regulatory bodies with regard to compliance with laws and regulations Business Requirements
© ITGI not for commercial use. 18 Processes A series of joined activities with natural control breaks Activities or Tasks Actions needed to achieve a measurable result. Activities have a life cycle, whereas tasks are discrete. Domains Natural grouping of processes, often matching an organisational domain of responsibility Process Orientation
© ITGI not for commercial use. 19 IT Domains Plan and Organise Acquire and Implement Deliver and Support Monitor and Evaluate IT Processes IT strategy Computer operations Incident handling Acceptance testing Change management Contingency planning Problem management Activities Record new problem Analyse Propose solution Monitor solution Record known problem Etc. Natural grouping of processes, often matching an organisational domain of responsibility A series of joined activities with natural (control) breaks Actions needed to achieve a measurable result. Activities have a life cycle, whereas tasks are discrete. Process Orientation
© ITGI not for commercial use. 20 Description This domain covers strategy and tactics, and concerns the identification of how IT can best contribute to the achievement of the business objectives. Furthermore, the realisation of the strategic vision needs to be planned, communicated and managed for different perspectives. Finally, a proper organisation as well as technological infrastructure must be put in place. Topics Strategy and tactics Vision planned Organisation and infrastructure Questions Are IT and the business strategy aligned? Is the enterprise achieving optimum use of its resources? Does everyone in the organisation understand the IT objectives? Are IT risks understood and being managed? Is the quality of IT systems appropriate for business needs? Domains Process Orientation Plan and Organise Plan and Organise
© ITGI not for commercial use. 21. Process Orientation Plan and Organise Plan and Organise PO 1 Define a Strategic Information Technology Plan PO 2 Define the Information Architecture PO 3 Determine the Technological Direction PO 4 Define the IT Organisation and Relationships PO 5 Manage the Investment in Information Technology PO 6 Communicate Management Aims and Direction PO 7 Manage IT Human Resources PO 8 Manage Quality PO 9 Assess and Manage IT Risks PO 10 Manage Projects
© ITGI not for commercial use. 22 Acquire and Implement Description To realise the IT strategy, IT solutions need to be identified, developed or acquired, as well as implemented and integrated into the business process. In addition, changes in and maintenance of existing systems are covered by this domain to make sure that the life cycle is continued for these systems. Topics IT solutions Changes and maintenance Questions Are new projects likely to deliver solutions that meet business needs? Are new projects likely to deliver on time and within budget? Will the new systems work properly when implemented? Will changes be made without upsetting current business operations? Domains Process Orientation
© ITGI not for commercial use. 23 Process Orientation Acquire and Implement AI 1 Identify Automated Solutions AI 2 Acquire and Maintain Application Software AI 3 Acquire and Maintain Technology Infrastructure AI 4 Enable Operation and Use AI 5 Procure IT Resources AI 6 Manage Changes AI 7 Install and Accredit Solutions and Changes
© ITGI not for commercial use. 24 Description This domain is concerned with the actual delivery of required services, which range from traditional operations over security and continuity aspects to training. To deliver services, the necessary support processes must be set up. This domain includes the actual processing of data by application systems, often classified under application controls. Topics Delivery of required services Setup of support processes Processing by application systems Questions Are IT services being delivered in line with business priorities? Are IT costs optimised? Is the work force able to use the IT systems productively and safely? Are adequate security, integrity and availability in place? Domains Process Orientation Deliver and Support Deliver and Support
© ITGI not for commercial use. 25 Process Orientation Deliver and Support DS 1 Define and Manage Service Levels DS 2 Manage Third-party Services DS 3 Manage Performance and Capacity DS 4 Ensure Continuous Service DS 5 Ensure Systems Security DS 6 Identify and Allocate Costs DS 7 Educate and Train Users DS 8 Manage service desk and incidents DS 9 Manage the Configuration DS 10 Manage Problems DS 11 Manage Data DS 12 Manage the physical environment DS 13 Manage Operations
© ITGI not for commercial use. 26 Description All IT processes need to be regularly assessed over time for their quality and compliance with control requirements. This domain thus addresses management’s oversight of the organisation’s control process and independent assurance provided by internal and external audit or obtained from alternative sources. Topics Assessment over time, delivering assurance Management’s oversight of the control system Performance measurement Questions Can IT’s performance be measured and can problems be detected before it is too late? Is independent assurance needed to ensure critical areas are operating as intended? Domains Process Orientation Monitor and Evaluate Monitor and Evaluate
© ITGI not for commercial use. 27 Process Orientation Monitor and Evaluate zME1 Monitor and evaluate IT performance zME2 Monitor and evaluate internal control zME3 Ensure compliance with external requirements zME4 Provide IT Governance
© ITGI not for commercial use. 28 Data : Data objects in their widest sense, i.e., external and internal, structured and nonstructured, graphics, sound, etc. Application Systems : Understood to be the sum of manual and programmed procedures Technology : Covers hardware, operating systems, database management systems, networking, multimedia, etc. Facilities : Resources to house and support information systems People : Staff skills, awareness and productivity to plan, organise, acquire, deliver, support, monitor and evaluate information systems and services IT Resources
© ITGI not for commercial use. 29 IT Processes IT Resources Business Requirements Data Application systems Technology Facilities People Plan and Organise Aquire and Implement Deliver and Support Monitor and Evaluate Effectiveness Efficiency Confidentiality Integrity Availability Compliance Information reliability How do they relate?
© ITGI not for commercial use. 30 IT Processes IT Resources Business Requirements Data Application systems Technology Facilities People Plan and Organise Aquire and Implement Deliver and Support Monitor and Evaluate Effectiveness Efficiency Confidentiality Integrity Availability Compliance Information reliability How IT is organised to respond to the requirements What the stakeholders expect from IT The resources made available to—and built up by—IT
© ITGI not for commercial use. 31 PO1 Define a strategic IT plan PO2 Define the information architecture PO3 Determine the technological direction PO4 Define the IT organisation and relationships PO5 Manage the IT investment PO6 Communicate management aims and direction PO7 Manage IT human resources PO8 Manage quality PO9 Assess and manage IT risks PO10 Manage projects A I 1 Identify automated solutions A I 2 Acquire and maintain application software A I 3 Acquire and maintain technology infrastructure A I 4 Enable operation and use A I 5 Procure IT resources A I 6 Manage changes AI7 Install and accredit solutions and changes M1 Monitor and evaluate It performance M2 Monitor and evaluate internal control M3 Ensure compliance with external requirements M4 Provide IT governance DS1 Define service levels DS2 Manage third-party services DS3 Manage performance and capacity DS4 Ensure continuous service DS5 Ensure systems security DS6 Identify and attribute costs DS7 Educate and train users DS8 Manage service desk and incidents DS9 Manage the configuration DS10 Manage problems DS11 Manage data DS12 Manage the physical environment DS13 Manage operations IT RESOURCES IT RESOURCES Data Application systems Technology Facilities People Data Application systems Technology Facilities People PLAN AND ORGANISE PLAN AND ORGANISE ACQUIRE AND IMPLEMENT ACQUIRE AND IMPLEMENT DELIVER AND SUPPORT MONITOR AND EVALUATE MONITOR AND EVALUATE Effectiveness Efficiency Confidentiality Integrity Availability Compliance Reliability Effectiveness Efficiency Confidentiality Integrity Availability Compliance Reliability Criteria Business Objectives C OBI T Framework
© ITGI not for commercial use. 32 COBIT Framework IT Governance Focus Areas
© ITGI not for commercial use. 33 C OBI T Framework
© ITGI not for commercial use. 34 IT Governance Focus Areas
© ITGI not for commercial use. 35 Summarising up to now IT is indispensable for the survival and growth of enterprises. Management is responsible for control. That responsibility needs a framework: Business requirements can be expressed as information criteria. IT is generally organised in a set of processes. IT needs a set of resources. C OBI T is an internationally accepted standard. To provide the information that the organisation needs to achieve its objectives, IT resources need to be managed by a set of naturally grouped processes. C OBI T Framework
© ITGI not for commercial use. 36 The C OBI T Cube
© ITGI not for commercial use. 37 Navigational Aids
© ITGI not for commercial use. 38Summary Processes, Criteria and Resources
© ITGI not for commercial use. 39 Effectiveness Efficiency Confidentiality Integrity Availability Compliance Reliability People Applications Technology Facilities Data DomainProcess Acquire and Implement AI1 Identify automated solutions PS AI2 Acquire and maintain application software PPSSS AI3 Acquire and maintain technology infrastructure PPS AI4 Develop and maintain procedures PPSSS AI5 Install and accredit systems PSS AI6 Manage changes PPPPS C OBI T Summary of Processes, Criteria and Resources AI6
© ITGI not for commercial use. 40 Assignment The most important C OBI T processes “For a business with which you are familiar, what would be the most important IT processes? Why?”
© ITGI not for commercial use. 41 PO1 Define a strategic IT plan PO3 Determine the technological direction PO5 Manage the IT investment PO9 Assess and manage IT risks PO10 Manage projects AI1Identify solutions AI2 Acquire and maintain applications s/w AI7 Install and accredit solutions and changes AI6 Manage changes DS1 Define service levels DS4 Ensure continuous service DS5 Ensure system security DS10 Manage problems DS11 Manage data ME1 Monitor and evaluate IT performance The Most Important IT Processes Survey
© ITGI not for commercial use. 42 Control and Control Objective Definitions The policies, procedures, practices and organisational structures designed to provide reasonable assurance that business objectives will be achieved and undesired events will be prevented or detected and corrected Definition of Control Definition of IT Control Objective A statement of the desired result or purpose to be achieved by implementing control practices in a particular IT activity
© ITGI not for commercial use. 43 High-level control objective One per process Detailed control objectives Three to 30 per process Control practices Five to seven per control objective Control Objectives and Control Practices
© ITGI not for commercial use. 44 The control of IT Processes which satisfy is enabled by Control Statements considering Control Practices C OBI T Framework Waterfall Model 4 Domains - 34 Processes Control Objectives Business Requirements
© ITGI not for commercial use. 45 AI6 Manage changes Managing changes to computer programs is required to ensure processing integrity between versions, and for consistency of results period to period. Change must be formally managed via change control request, impact assessment, documentation, authorisation, release, and distribution policies and procedures. High-level Control Objective
© ITGI not for commercial use. 46 AI6 High-level Control Objective
© ITGI not for commercial use. 47 Based on the 41 primary references Developed following a rigorous research process Three to 30 detailed control objectives for each of the 34 processes Directed to IT management, IT staff, control and audit functions and business process owners For each process, detailed control objectives are identified as « good practice » that need to be in place, and that will be assessed for sufficiency by the controls professional. Control objectives provide a working document, a place to start, from which selections need to be made based on the enterprise value and risk drivers. C OBI T Control Objectives
© ITGI not for commercial use. 48 AI6 Manage Changes 6.1 Change request initiation and control IT management should ensure that all requests for changes, system maintenance and supplier maintenance are standardised and are subject to formal change management procedures. Changes should be categorised and prioritised, and specific procedures should be in place to handle urgent matters. Change requesters should be kept informed about the status of their request. 6.2 Impact assessment A procedure should be in place to ensure that all requests for change are assessed in a structured way for all possible impacts on the operational system and its functionality. 6.3 Control of changes IT management should ensure that change management and software control and distribution are properly integrated with a comprehensive configuration management system. The system used to monitor changes to application systems should be automated to support the recording and tracking of changes made to large, complex information systems. 6.4 Emergency changes IT management should establish parameters defining emergency changes and procedures to control these changes when they circumvent the normal process of technical, operational and management assessment prior to implementation. The emergency changes should be recorded and authorised by IT management prior to implementation. Detailed Control Objectives
© ITGI not for commercial use. 49 Detailed Control Objectives AI6 Manage Changes (continued) 6.5 Documentation and procedures The change process should ensure that, whenever system changes are implemented, the associated documentation and procedures are updated accordingly. 6.6 Authorised maintenance IT management should ensure that maintenance personnel have specific assignments and their work is properly monitored. In addition, their system access rights should be controlled to avoid risks of unauthorised access to automated systems. 6.7 Software release policy IT management should ensure that the release of software is governed by formal procedures—ensuring sign-off, packaging, regression testing, handover, etc. 6.8 Distribution of software Specific internal control measures should be established to ensure distribution of the correct software element to the right place, with integrity, in a timely manner and with adequate audit trails.
© ITGI not for commercial use. 50 C OBI T AI6 Detailed Control Objectives
© ITGI not for commercial use. 51 Control practices are key control mechanisms that support the: Achievement of control objectives Prevention, detection and correction of undesired events Control practices achieve that through: Responsible use of resources Appropriate management of risk Alignment of IT with business Translate C OBI T’s control objectives into detailed, implementable practices and provide the business argumentation for implementation, from a value and a risk perspective Control Practices
© ITGI not for commercial use Management defines parameters, characteristics and procedures that identify and declare emergencies. 2.All emergency changes are documented, if not before, then after, implementation. 3.All emergency changes are tested, if not before, then after, implementation. 4.All emergency changes are formally authorised by the system owner and management before implementation. 5.Before and after images as well as intervention logs are retained for subsequent review. Controlling emergency changes by implementing the control practices will : Ensure that emergency procedures are used in declared emergencies only Ensure that urgent changes can be implemented without compromising integrity, availability, reliability, security, confidentiality or accuracy AI6 Manage change AI6.4 Emergency changes IT management should establish parameters defining emergency changes and procedures to control these changes when they circumvent the normal process of technical, operational and management assessment prior to implementation. The emergency changes should be recorded and authorised by IT management prior to implementation. Control PracticesWhy do it? Control Practices
© ITGI not for commercial use. 53 C OBI T IT Control Practices
© ITGI not for commercial use. 54 Important C OBI T Products Control Objectives— “Minimum controls are...” Management Guidelines – “Here is how you measure…” Audit Guidelines— “Here is how you audit...”
© ITGI not for commercial use. 55 IT Governance Model IT governance helps ascertain how automated systems: Simplify operations Cut costs Increase revenue Needs an IT control framework
© ITGI not for commercial use. 56 How Does C OBI T Link to IT Governance? Goals Responsibilities Control Objectives Requirements BusinessIT Governance Information the Business Needs to Achieve Its Objectives Information Executives and Board Need to Exercise Their Responsibilities Direction and Resourcing
© ITGI not for commercial use. 57 IT Governance Goals Responsibilities Control Objectives Requirements Business IT Governance Information the Business Needs to Achieve Its Objectives Direction (IT Strategy and Policy) Information (IT Control, Risk and Assurance) How Does C OBI T Link to IT Governance?
© ITGI not for commercial use. 58 However, management has questions that go beyond a control framework: How do responsible managers "keep the ship on course"? DASHBOARD How to achieve results that are satisfactory for the largest possible segment of our stakeholders ? SCORECARDS How to adapt the organisation in a timely manner to trends and developments in the enterprise's environment ? BENCHMARKING Indicators? Indicators? Measures? Measures? Scales? Scales? Management Guidelines
© ITGI not for commercial use. 59 Process Description Critical Success Factors Key Goal Indicators Key Performance Indicators Information Criteria Resources Management processes are not applied at all Processes are ad hoc and disorganised Processes follow a regular pattern Processes are documented and communicated Processes are monitored and measured Best practices are followed and automated. Maturity Model Management Guidelines Framework
© ITGI not for commercial use. 60 Describe the outcome of the process (i.e., measurable after the fact); are measures of “what,” and may describe the impact of not reaching the process goal Are indicators of the success of the process and its business contribution Focus on the customer and financial dimensions of the balanced scorecard Key Goal Indicators Definitions
© ITGI not for commercial use. 61 Increased level of service delivery Number of customers and cost per customer served Availability of systems and services Absence of integrity and confidentiality risks Cost-efficiency of processes and operations Confirmation of reliability and effectiveness Adherence to development cost and schedule Cost-efficiency of the process Staff productivity and morale Number of timely changes to processes and systems Improved productivity (e.g., delivery of value per employee) Key Goal Indicators Examples
© ITGI not for commercial use. 62 Are measures of “how well” the process is performing Predict the probability of success or failure Focus on the process and learning dimensions of the balanced scorecard Are expressed in precise, measurable terms Should help in improving the IT process Key Performance Indicators Definitions
© ITGI not for commercial use. 63 Number of IT customers Cost per IT customer Cost-efficiency of IT processes up Delivery of IT value per employee Information Availability of systems and services Developments on schedule and budget Throughput and response times Amount of errors and rework Level of service delivery Satisfaction of existing customers Number of new customers reached Number of new service delivery channels F Financial C Customer Staff productivity and morale Number of staff trained in new techno/services Value delivery per employee Increased availability knowledge systems L Learning P Process Key Performance Indicators Examples
© ITGI not for commercial use. 64 Are the most important things to do to increase the probability of success of the process Are observable—usually measurable—characteristics of the organisation and process Focus on obtaining, maintaining and leveraging capability, skills and behaviour Critical Success Factors Definitions
© ITGI not for commercial use. 65 The IT strategic plan clearly states a risk position such as leading-edge or road-tested, innovator or follower, and the required balance between time-to- market, cost of ownership and service quality. If you are not ready to enforce the policy, do not issue the policy. A building permit programme for building IT systems and a “driver’s licence” programme for those doing the building A good security plan takes time to evolve. Strategy Policy Compliance Security Examples Critical Success Factors
© ITGI not for commercial use. 66 Refer to business requirements (KGIs) and the enabling aspects (KPIs) at the different levels Are a scale that lend themselves to pragmatic comparison, where the difference can be made measurable in an easy manner Are recognisable as a profile of the enterprise in relation to IT governance and control Assist in determining as-is and to-be positions relative to IT governance and control maturity and analyse the gap Are not industry-specific nor generally applicable. The nature of the business determines what is an appropriate level. Maturity Models Definitions
© ITGI not for commercial use Nonexistent InitialRepeatableDefinedManagedOptimised Enterprise current status International standard guidelines Industry best practice Enterprise strategy Legend for Symbols UsedLegend for Rankings Used 0 - Management processes are not applied at all. 1 - Processes are ad hoc and disorganised. 2 - Processes follow a regular pattern. 3 - Processes are documented and communicated. 4 - Processes are monitored and measured. 5 - Best practices are followed and automated. Maturity Models Usage
© ITGI not for commercial use. 68 AI6 Management Guideline
© ITGI not for commercial use. 69 AI6 Management Guideline
© ITGI not for commercial use. 70 Provide management with reasonable assurance that control objectives are being met Where there are significant control weaknesses, substantiate the resulting risks Advise management on corrective actions Objectives of Auditing “Am I all right? And, if not, how do I fix it? ”
© ITGI not for commercial use. 71 Structure of the Audit Process Identification and Documentation Evaluation Compliance Testing Substantive Testing
© ITGI not for commercial use. 72 An IT process is audited by: Obtaining an understanding Obtaining an understanding of business requirements-related risks, and relevant control measures Evaluating the appropriateness Evaluating the appropriateness of stated controls Assessing compliance Assessing compliance by testing whether the stated controls are working as prescribed, consistently and continuously Substantiating the risk Substantiating the risk of the control objectives not being met by using analytical techniques and/or consulting alternative sources
© ITGI not for commercial use. 73 One Generic Guideline and 34 Process-oriented Guidelines A generic guideline identifies various tasks to be performed in assessing any control objective within a process. This generic guideline is a model for all control objectives. Others are specific, process-oriented task suggestions to provide management assurance that a control exists and has a reasonable level of effectiveness. C OBI T Audit Guidelines
© ITGI not for commercial use. 74 O btaining an U nderstanding The audit steps to be performed to document the activities underlying the control objectives as well as to identify the control measures/procedures put in place Interview appropriate management and staff to obtain and gain an understanding of: Business requirements and associated risks Organisation structure Roles and responsibilities Policies and procedures Laws and regulations Control measures in place Management reporting (status, performance, actions) Document the process-related IT resources particularly affected by the process under review. Confirm the understanding of the process under review, the control implications, e.g., by a process walkthrough. Generic Audit Guideline (1 of 4)
© ITGI not for commercial use. 75 Evaluating the Controls The audit steps to be performed, in light of assessing the effectiveness of control measures in place or the degree to which the control objective is achieved Evaluate the appropriateness of control measures for the process under review by considering identified criteria and industry standard practices and applying professional judgement. Determine whether: Documented processes exist. Appropriate deliverables exist. Responsibility and accountability are clear and effective. Compensating controls exist, where necessary. Conclude the degree to which the control objective is met. Generic Audit Guideline (2 of 4)
© ITGI not for commercial use. 76 Assessing Compliance The audit steps to be performed to ensure that the control measures established are working as prescribed, consistently and continuously Obtain direct or indirect evidence for selected items/periods to ensure that the procedures have been complied with for the period under review, using both direct and indirect evidence. Perform a limited review of the adequacy of the process deliverables. Determine the level of substantive testing and additional work needed to provide assurance that the IT process is adequate. Generic Audit Guideline (3 of 4)
© ITGI not for commercial use. 77 Substantiating the Risk The audit steps to be performed to substantiate the risk of the control objective not being met by using analytical techniques and/or consulting alternative sources Document the control weaknesses and resulting threats and vulnerabilities. Identify and document the actual and potential impact. Generic Audit Guideline (4 of 4)
© ITGI not for commercial use. 78 AI6 Audit Guideline
© ITGI not for commercial use. 79 AI6 Audit Guideline
© ITGI not for commercial use. 80 AI6 Audit Guideline
© ITGI not for commercial use. 81 How Audit Guidelines and Control Objectives Are Linked Obtaining an understanding Evaluating the appropriateness Assessing compliance Substantiating the risk Control objectives translated to verify whether they are addressed and take into account the appropriateness for the enterprise and management claims about their presence Control objectives translated to test and/or measure whether controls in support of the control objectives are present as claimed and whether they operate satisfactorily Collect background information referencing business drivers, risks, infrastructure, etc. Illustrate missed business objectives, losses, etc., due to absence of adequate control.
© ITGI not for commercial use. 82 Business IT Processes Audit Guidelines Control Objectives Control Practices Critical Success Factors Key Performance Indicators Key Goal Indicators Maturity Models requirements information measured by controlled by implemented with audited by for performance for outcome for maturity made effective and efficient with translated into = takes into consideration How Audit Guidelines and All Other C OBI T Elements Are Linked
© ITGI not for commercial use. 83 To improve audit approach/programs y To support audit work with detailed audit guidelines y To provide guidance for IT governance y As a valuable benchmark for IS/IT control y To improve IS/IT controls y To standardise audit approach/programs How Is C OBI T Used? ( Results from Surveys) The C OBI T Framework
© ITGI not for commercial use. 84 C OBI T—Benefits What Comfort about: Dependence on IT IT risks are mitigated IT delivers value Assurance of: Cost down and revenue up Business operations improved Service levels maintainedWho Executive Business manager IT manager Project manager Developer Operations staff User Security officer Auditor
© ITGI not for commercial use. 85 y Helps substantially increase acceptance and reduce time needed to implement IT governance program y Provides a guide for formal audits/reviews y Helps use results of audits as an opportunity to plan improvements y Strong factor in achieving primary goals for IT governance—transform organisational practices and pursue improved processes y Provides economical continuous improvement framework y Management's decision on controls needed was based on a credible source (C OBI T) y IT operations manager impressed with C OBI T's ability to help him understand what auditors want y Ideal for business management y Reliable source reference that ensures identification of all major risk areas y Improves communications and relations with IT management Why Is C OBI T Used? ( Testimonials from Case Studies) The C OBI T Framework
© ITGI not for commercial use. 86 C OBI T Products Management Guidelines Provide management direction for: Getting the enterprise's information and related processes under control Monitoring achievement of organisational goals Monitoring and improving performance within each IT process Benchmarking organisational achievement Action-oriented and generic Provide answers to typical management questions: How far should we go in controlling IT, and is the cost justified by the benefit? What are the indicators of good performance? What are the critical success factors? What are the risks of not achieving our objectives? What do others do? How do we measure and compare?
© ITGI not for commercial use. 87 Biggest Challenge = Sustainable Solutions l Establish policy, objectives and targets l Implement policy, responsibilities, processes and procedures l Measure performance against policy and external best practice l Take corrective and preventive action and continuously improve l Measure success of the change projects l Provide feedback into other improvement projects Identify needs Identify needs Envision the solution Envision the solution Plan the solution Plan the solution Implement the solution Implement the solution Road MapApproach l Business value and risk analysis l As-is and to-be positions l Gap analysis l Project identification and initiation IT Governance Implementation Guide
© ITGI not for commercial use. 88 Raise awareness & make decision Analyse values and risks Select processes Identify needs Define projects Develop & implement change plan Plan the solution Integrate into day-to- day practices Integrate measures into ITBSC Implement the solution Define where you are Define where you want to be Analyse gaps Envision the solution Implementation Road Map Post- implement. review Feedback IT Governance Implementation Guide
© ITGI not for commercial use. 89 ImplementationManual IT Governance Implementation Guide
© ITGI not for commercial use. 90 Conclusion —C OBI T Values Sharing knowledge and leveraging expert volunteers Internationally accepted good practices Continually evolves Maintained by reputable not-for-profit organisation Maps strongly onto all major related standards Is management-oriented Is supported by tools and training Maps completely to ISO17799 and COSO Provide action-oriented solutionsFUTURE PRESENT
© ITGI not for commercial use. 91 IT Governance Institute 3701 Algonquin Road, Suite 1010 Rolling Meadows, IL USA John R. Robles and Associates The C OBI T Framework