2/20/2016 Leveraging IT Governance and COBIT Chip Council, PhD, CGEIT, CISM, CISA Matt Schmidt, MS, CISSP, CISA Adjunct Professors, University of Minnesota.

Slides:



Advertisements
Similar presentations
Connecting Phoenix to Information IT Governance in a Decentralized Organization Charles T. Thompson Chief Information Officer City of Phoenix.
Advertisements

IT Governance & Quality Management
Microsoft Operations Framework (MOF) 4.0
IT Governance Framework
Chapter 10 Accounting Information Systems and Internal Controls
IT Governance Infocom India Presentation December 6, 2006.
Agenda COBIT 5 Product Family Information Security COBIT 5 content
TI BISNIS ITG using COBIT &
Roger Southgate Past President of ISACA London Chapter Member of the BSI Committees for Service Management and IT Governance Leader.
By Collin Smith COBIT Introduction By Collin Smith
ISS IT Assessment Framework
IT Governance: Simultaneously Empowers and Controls Source: IT Governance, Chapter 1.
Information Security Governance and Risk Chapter 2 Part 1 Pages 21 to 69.
Aust. AM Collaborative Group (AAMCOG) An introduction to ISO “What to do” guide 20th October 2014.
COBIT Framework Introduction. Problems with IT? – Increasing pressure to leverage technology in business strategies – Growing complexity of IT environments.
Welcome to the Information Session on Leadership Competency Models
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
Internal Auditing and Outsourcing
Developing Enterprise Architecture
Reinventing with Outsourcing YES BANK Experience Balaji V Vice President, Business Services July 4, 2005.
COBIT®. COBIT - Control Objectives for Information and related Technology C OBI T was initially created by the Information Systems Audit & Control Foundation.
© ITGI, ISACA - not for commercial use. John R. Robles Guidance for Information.
QAD's Customer Engagement Dan Blake Consultancy Development Director, QAD QAD Explore 2012.
Continual Service Improvement Process
IT Governance
The Challenge of IT-Business Alignment
Chapter Three IT Risks and Controls.
Roles and Responsibilities
Challenges in Infosecurity Practices at IT Organizations
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
Introduction to the ISO series ISO – principles and vocabulary (in development) ISO – ISMS requirements (BS7799 – Part 2) ISO –
Overview of COBIT5 and Impact on Local Content for IT By Mrs Tokunbo Martins Director Banking Supervision (Central Bank of Nigeria)
ITIL Framework. What is ITIL ? ITIL stands for the Information Technology Infrastructure Library. ITIL is the international de facto management framework.
Security Standards and Threat Evaluation. Main Topic of Discussion  Methodologies  Standards  Frameworks  Measuring threats –Threat evaluation –Certification.
Environmental Management System Definitions
ITIL Drivers for Government Scott Spencer Vice President, Program Management, GTSI.
IT GOVERNANCE SIMULTANEOUSLY EMPOWERS AND CONTROLS Pertemuan ke-1 & 2 Matakuliah: Pengantar IT Governance Tahun: Feb
DISCUSSION OF EXPLORING DIFFERENCES BETWEEN LARGE AND MEDIUM ORGANIZATIONS’ CORPORATE GOVERNANCE OF INFORMATION TECHNOLOGY BY ANNE FORTIN, ESG UQAM University.
IT GOVERNANCE  Objective : The objective of this area is to ensure that the Certified Information Systems Auditor ( CISA ) candidate understands and can.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
Chapter 9: Introduction to Internal Control Systems
Samantha Schreiner University of Illinois at Urbana- Champaign BA 559 – Professor Michael Shaw December 15 th, 2008 A Survey of IT Governance Through COBIT,
COBIT®. COBIT® - Control Objectives for Information and related Technology. C OBI T was initially created by the Information Systems Audit & Control Foundation.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
Kathy Corbiere Service Delivery and Performance Commission
TMS - Cooperation partner of TÜV SÜD EFFECTIVE SERVICE MANAGEMENT based on ISO/IEC & ISO/IEC
C OBI T and slides © 2007 IT Governance Institute. Used with permission. An Overview of C OBI T ®
© | Hansan Global | All Rights Reserved 1 INTRODUCTION TO IT SERVICE MANAGEMENT Hansan Global Pte Ltd.
#325 - CobiT and Service Delivery Debra Mallette, CISA, CSSBB Kaiser Permanente IT.
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
CSC4003: Computer and Information Security Professor Mark Early, M.B.A., CISSP, CISM, PMP, ITILFv3, ISO/IEC 27002, CNSS/NSA 4011.
ForrTel: IT Governance Frameworks
COBIT 5 Update FEI/CFIT Meeting December 15, 2011
IT Governance Excerpts PM ROI/Case Study 3/12/
1 Using CobiT to Enhance IT Security Governance LHS © John Mitchell John Mitchell PhD, MBA, CEng, CITP, FBCS, MBCS, FIIA, CIA, CISA, QiCA, CFE LHS Business.
AFRICACS. ACCRA Developing and Implementing IT GRC Framework in a Post Merger Integration Phase Presented By Ivan Anya, MBA, CISA, CGEIT, CRISC MD/CEO,
Models of Security Management Matt Cupp. Overview What is Security Management? What is Security Management? ISO/IEC ISO/IEC NIST Special Publication.
ISACA Willamette Valley Chapter Luncheon Thursday, March 20, 2008 Practical Auditors Guide for CobiT Steve Balough, CISA.
Asset Management Accountability Framework
BIL 424 NETWORK ARCHITECTURE AND SERVICE PROVIDING.
JU September Stakeholder Engagement Conference Webinar #1
EITS Planning & Decision Support
IIASA Governance Review
Overview of the Information Security Guide: Leveraging the Knowledge and Skills of Your Colleagues Cedric Bennett, Emeritus Director, Information Security.
City of Vaughan | Corporate Asset Management Strategy
CIGFARO ANNUAL CONFERENCE – 11 OCTOBER 2017
COSO Internal Control s Framework
همسویی چارچوب‏هاو به‏روشهای حاکمیت و مدیریت فناوری اطلاعات
Alignment of COBIT to Botswana IT Audit Methodology
COBIT 5 and GRC Date.
Presentation transcript:

2/20/2016 Leveraging IT Governance and COBIT Chip Council, PhD, CGEIT, CISM, CISA Matt Schmidt, MS, CISSP, CISA Adjunct Professors, University of Minnesota

2/20/2016 Agenda  Introduction – 2:40 – 3:00  IT Governance – 3:00 – 3:45  The Problem  What Is IT Governance  How to evaluate it  How to Deploy it  Frameworks – 3:45 – 4:20  COBIT/ValIT (Chip)  ISO 2700x/ITIL (Matt)  Future Directions – 4:20 – 4:30  ISO/IEC DIS (Chip)

2/20/2016 The Problem – Current IT Issues  IT Strategy Not Aligned With the Business  Staffing Issues  High IT Cost – Low ROI  Service Delivery Problems

2/20/2016 What Is IT Governance Specifying the decision rights and accountability framework to encourage desirable behavior in the use of IT. Peter Weill and Jeanne W. Ross IT Governance: How Top Performers Manage IT Decision Rights for Superior Results (2004)

2/20/2016 Another Definition IT governance is the responsibility of the board of directors and consists of the leadership, organizational structures and processes that ensure that the enterprise’s IT sustains and extends the organization’s strategies and objectives. - IT Governance Institute

2/20/2016 IT Governance Focus Risk Management Value Delivery Strategic Alignment Resource Management Performance Measurement - IT Governance Institute

2/20/2016 How to evaluate it? Weill and Ross  Survey to quickly assess the effectiveness of an enterprise’s IT governance.  Recommended to have at least 10 senior managers take the survey. Four Objectives To Assess  Cost-effective use of IT  Effective use of IT for asset utilization  Effective use of IT for growth  Effective use of IT for business flexibility

2/20/2016 How to evaluate it? Question 1 – Outcomes How important are the following outcomes of your IT governance, on a scale from 1 (Not Important) to 5 (Very Important)

2/20/2016 How to evaluate it? Question 2 - Success What is the influence of the IT governance in your business on the following measures of success, on a scale from 1 (Not Successful) to 5 (Very Successful)

2/20/2016 How to evaluate it? Calculating Governance Performance Not all firms rank the outcomes with the same importance, so the answers to the first question are used to weight the answers to the second question.

2/20/2016 How to deploy it?  Ad Hoc Approach  Use a Standard or Framework  A Combination of the Two IMPORTANT: Any standard approach must be customized to meet the needs of the organization (Don’t be that guy or gal!)

2/20/2016 Benefits of the Standard Approach 1. The Wheel Exists 2. Structured 3. Best Practices 4. Knowledge Sharing 5. Auditable  -George Spafford

2/20/2016 COBIT

2/20/2016 COBIT Information Criteria  Efficiency  Effectiveness  Availability  Integrity  Confidentiality  Compliance  Reliability

2/20/2016 COBIT Framework

2/20/2016 Tools  COBIT 4.1 Control Objectives  COBIT 4.1 Assurance Guide  COBIT Implementation Guide  Worksheets  Sample Reports  Management Concerns Diagnostics  Risk Assessments

2/20/2016 ISO 2700x/ITIL  ISO/IEC 17799/27002 – Code of Practice for Information Security Management  Twelve main sections with specialized recommendations for risk assessment, security policy, governance, compliance, etc.  Based heavily on C-I-A Triad Principles  ITIL (IT Infrastructure Library)  IT Operations and Service Delivery Best Practices  Security recommendations based heavily on ISO/IEC 17799/27002

2/20/2016 Leveraging Multiple Frameworks  Typical driver for implementing multiple frameworks is regulatory compliance, however, that does not have to be the driver.  One size does not fit all.  Consider available mapping guidance to address overlap.  Underlying Themes  Understand your environment  Understand risks to your environment  Manage the risks to an acceptable level (acceptable level

2/20/2016 ISO/IEC Corporate Governance of Information Technology Standard  The ISO/IEC Corporate Governance of Information Technology Standard  An updated version of the Australian Standard AS8015, published in  This standard expresses six principles for good governance of IT use:  Responsibility  Strategy  Acquisition  Performance,  Conformance  Human Behavior  It is intended to guide the behavior of the organization,  Provides a lens or framework through which the behavior can be evaluated.  Describes the tasks that must be implemented in the governance system – at a much higher level than one finds in frameworks like ITIL and COBIT  Makes no reference to frameworks such as ITIL and COBIT but compliments many of them  It specifically acknowledges that organizations should select appropriate frameworks. -Mark Toomey Managing Director Infonomics Pty Ltd Melbourne, Australia MelbourneAustralia

2/20/2016 Acknowledgements -Bob Frelinger, CISA, CSSGB - Common Issues in Implementing IT Governance and How to Resolve Them (Presentation) -Peter Weill and Jeanne W. Ross IT Governance: How Top Performers Manage IT Decision Rights for Superior Results (2004) (Book) -IT Governance Institute, COBIT 4.1 Framework (2007) -George Spafford: The Benefits of Standard IT Governance Frameworks: Datamation (2003) -Mark Toomey Managing Director Infonomics Pty Ltd

2/20/2016 Discussion