您好,欢迎访问三七文档
SITC:Service&Security1COBITPart2–Framework&ManagementGuidelines2009年3月SITC:Service&Security2学习目标•COBIT是甚么•COBIT的框架•COBIT的組成•COBIT的瀏覽SITC:Service&Security3AgendaCOBITOverviewCOBITFrameworkBusiness-focusedProcess-orientedControls-basedMeasurement-drivenConclusionsSITC:Service&Security4COBITCOBIT®=ControlOBjectivesforInformationandRelatedTechnologyProcess-orientedframeworkforITGovernanceFocusedonbusinessgoalsandhowITsupportstheirachievementAtoolfor•Businessmanagement•ITmanagement•ITprocessmanagersFirstdevelopedin1992IssuedbyITGovernanceInstituteContentismanagedbytheCOBITSteeringCommitteeAcceptedgloballyasthedefactocontrolframeworkforITGovernanceDocumentscanbedownloadedfromwww.isaca.orgSITC:Service&Security5COBIT’sMissionToresearch,develop,publicizeandpromoteanauthoritative,up-to-date,internationallyacceptedITgovernancecontrolframeworkforadoptionbyenterprisesandday-to-dayusebybusinessmanagers,ITprofessionalsandassuranceprofessionalsCOBIT’sVisonTobethemodelforITgovernance!SITC:Service&Security6InformationSystemsAuditandControlAssociationTherecognizedgloballeadersinITgovernance,controlandassurance.Foundedin1969astheEDPAuditorsAssociationMorethan50,000membersinover140countriesMorethan170chaptersinover70countriesworldwideProvidesServiceandProgramsDesignedtoPromoteandEstablishExcellenceonITGovernanceandAuditResearchconductedthroughFoundationProjectsareselectedtohelpMembersandtheProfessionkeeppacewithever-changingITandbusinessenvironmentSITC:Service&Security7CISAintheWorkplaceMorethan1,100arenowemployedinorganizationsastheCEO,CFOorequivalentexecutivepositionMorethan2,300serveaschiefauditexecutives,auditpartnersorauditheadsMorethan2,800serveasCIOs,CISOs,securitydirectors,securitymanagersorconsultantsMorethan4,200serveasauditdirectors,managersorconsultantsNearly8,300areemployedinmanagerialorconsultingpositionsinIToperationsorcomplianceSITC:Service&Security8ITGovernanceInstitute(ITGI)FoundedbyISACAin1998.TheITGovernanceInstitute(ITGI)existstoassistenterpriseleadersintheirresponsibilitytoensurethatITgoalsalignwiththoseofthebusiness,itdeliversvalue,itsperformanceismeasured,itsresourcesproperlyallocatedanditsrisksmitigated.Throughoriginalresearch,symposiaandelectronicresources,theITGIhelpsensurethatboardsandexecutivemanagementhavethetoolsandinformationtheyneedforITtodeliveragainstexpectations.SITC:Service&Security9CobithistoryCOBIThasevolvedfromanauditor‘stooltoanITgovernanceframework,usedincreasinglybyITmanagementGovernanceCOBIT42005COBIT3Management2000COBIT2Control1998COBIT1Audit1996EvolutionSITC:Service&Security10HowCOBIT4.1ChangedFrom4.0EnhancedexecutiveoverviewExplanationofgoalsandmetricsintheframeworksectionBetterdefinitionsofthecoreconcepts.Itisimportanttomentionthatthedefinitionofacontrolobjectivechanged,shiftingmoretowardamanagementpracticestatement.ImprovedcontrolobjectivesresultingfromupdatedcontrolpracticesandValITdevelopmentactivity.Somecontrolobjectivesweregroupedand/orrewordedtoavoidoverlapsandmakethelistofcontrolobjectiveswithinaprocessmoreconsistent.Thesechangesresultedintherenumberingoftheremainingcontrolobjectives.Someothercontrolobjectiveswererewordedtomakethemmoreaction-orientedandconsistentinwording.Specificrevisionsinclude:-AI5.5andAI5.6werecombinedwithAI5.4-AI7.9,AI7.10andAI7.11werecombinedwithAI7.8-ME3wasrevisedtoincludecompliancewithcontractualrequirementsinadditiontolegalandregulatoryrequirementsApplicationcontrolshavebeenreworkedtobemoreeffective,basedonworktosupportcontrolseffectivenessassessmentandreporting.Thisresultedinalistofsixapplicationcontrolsreplacingthe18applicationcontrolsinCOBIT4.0,withfurtherdetailprovidedinCOBITControlPractices,2ndEdition.ThelistofbusinessgoalsandITgoalsinappendixIwasimproved,basedonnewinsightsobtainedduringvalidationresearchexecutedbytheUniversityofAntwerpManagementSchool(Belgium).Thepull-outhasbeenexpandedtoprovideaquickreferencelistoftheCOBITprocesses,andtheoverviewdiagramdepictingthedomainshasbeenrevisedtoincludereferencetotheprocessandapplicationcontrolelementsoftheCOBITframework.ImprovementsidentifiedbyCOBITusers(COBIT4.0andCOBITOnline)havebeenreviewedandincorporatedasappropriate.SITC:Service&Security11ITGovernanceModelITGovernancehelpsascertainhowautomatedsystems:•Simplifyoperations•CutcostsNeedanITControlframework•IncreaserevenueSITC:Service&Security12WhydoesITneedacontrolframework?ManagementneedstogetITundercontrolProvidevalue/Nosurprises/PushtheenvelopeSITC:Service&Security13Whoneedsacontrolframework?BoardandExecutiveToensuremanagementfollowsandimplementsthestrategicdirectionforITManagementTomakeITinvestmentdecisionsTobalanceriskandcontrolinvestmentTobenchmarkexistingandfutureITenvironmentUsersToObtainassuranceonsecurityandcontrolofproductsandservicesacquireinternallyorexternallyAuditorsTosubstantiateopinionstomanagementoninternalcontrolsToadviseonwhatminimumcontrolsarenecessarySITC:Service&Security14ThefivecharacteristicsofcontrolframeworkBusinessfocusProcessorientationGeneralacceptabilityCommonlang
本文标题:COBITFramework_ManagementGuidelines---IT治理框
链接地址:https://www.777doc.com/doc-196 .html