COBIT 5. COBIT 5 Online Collaborative Environment

Size: px
Start display at page:

Download "COBIT 5. COBIT 5 Online Collaborative Environment"

Transcription

1 COBIT 5 Product Family COBIT 5 COBIT 5 Enabler Guides COBIT 5: Enabling es COBIT 5: Enabling Information Other Enabler Guides COBIT 5 Professional Guides COBIT 5 Implementation COBIT 5 for Information Security COBIT 5 for Assurance COBIT 5 for Other Professional Guides COBIT 5 Online Collaborative Environment Source: COBIT 5 for, figure 1 COBIT 5 Principles 1. Meeting Stakeholder Needs 5. Separating From COBIT 5 Principles 2. Covering the Enterprise End-to-end 4. Enabling a Holistic Approach 3. Applying a Single Integrated Framework Source: COBIT 5, figure Algonquin Road, Suite 1010 Rolling Meadows, IL USA Phone: Fax: info@isaca.org Web site:

2 COBIT 5 Goals Cascade Overview Stakeholder Drivers (Environment, Technology Evolution, ) Stakeholder Needs Influence Benefits Realisation Resource Cascade to Enterprise Goals Cascade to IT-related Goals Cascade to Enabler Goals Source: COBIT 5, figure 4 Selected Guidance From the COBIT 5 Family These charts and figures are elements of COBIT 5 and its supporting guides. This excerpt is available as a complimentary PDF ( and for purchase in hard copy ( It provides an overview of the COBIT 5 guidance, its five principles and seven enablers. We encourage you to share this document with your enterprise leaders, team members, clients and/or consultants. COBIT enables enterprises to maximise the value and minimise the risk related to information, which has become the currency of the 21 st century. COBIT 5 is a comprehensive framework of globally accepted principles, practices, analytical tools and models that can help any enterprise effectively address critical business issues related to the governance and management of information and technology. Additional information is available at

3 and in COBIT 5 Objective: Value Creation Benefits Realisation Resource Enablers Scope Roles, Activities and Relationships Source: COBIT 5, figure 8 Key Roles, Activities and Relationships Roles, Activities and Relationships Owners and Stakeholders Delegate Accountable Governing Body Set Direction Monitor Instruct and Align Report Operations and Execution Source: COBIT 5, figure 9 COBIT 5 and Key Areas Business Needs Evaluate Direct Feedback Monitor Plan (APO) Build (BAI) Run (DSS) Monitor (MEA) Source: COBIT 5, figure 15

4 Two s on Function The risk function perspective describes how to build and sustain a risk function in the enterprise by using the COBIT 5 enablers. Function es Information COBIT 5 Enablers Organisational Structures Principles, Policies and Frameworks Services, Infrastructure and Applications Culture, Ethics and Behaviour People, Skills and Competencies The risk management perspective looks at core risk governance and risk managment processes and risk scenarios. This perspective describes how risk can be mitigated by using COBIT 5 enablers. Source: COBIT 5 for, figure 8 Scope of COBIT 5 for COBIT 5 for es Information COBIT 5 Enablers for the Function Organisational Structures Principles, Policies and Frameworks Services, Infrastructure and Applications Culture, Ethics and Behaviour People, Skills and Competencies Function Core es Scenarios Mapping Scenarios to COBIT 5 Enablers COBIT 5 Framework COBIT 5: Enabling es COSO ERM ISO ISO/IEC Others ITIL. ISO/IEC ISO/IEC 27001/2 Others Enterprise Standards IT Frameworks Source: COBIT 5 for, figure 10

5 The (AP012) Scenario Overview All Related Enablers Principles, Policies and Frameworks Organisational Structures Culture, Ethics and Behaviour APO12.01 Collect Data APO12.02 Analyse APO12.03 Maintain a Profile Top Down Business Goals Identify business objectives. Identify scenarios with highest impact on achievement of business objectives. Scenarios Factors Internal Environmental Factors External Environmental Factors Information Services, Infrastructure and Applications People, Skills and Competencies APO12.04 Articulate APO12.05 Define a Action Portfolio APO12.06 Respond to Identify hypothetical scenarios. Reduce through high-level analysis. Generic Scenarios Bottom Up Capabilities IT-related Capabilities Source: COBIT 5 for, figure 34 Scenario Structure Threat Type Malicious Accidental Error Failure Nature External requirement Event Disclosure Interruption Modification Theft Destruction Ineffective design Ineffective execution Rules and regulations Inappropriate use Asset/Resource People and skills Organisational structures Infrastructure (facilities) IT infrastructure Information Applications Actor Internal (staff, contractor) External (competitor, outsider, business partner, regulator, market) Scenario Time Duration Timing occurrence (critical or non-critical) Detection Time lag Source: COBIT 5 for, figure 36

6 Supporting es for the Function es for of Enterprise IT Evaluate, Direct and Monitor EDM01 Ensure Framework Setting and Maintenance EDM02 Ensure Benefits Delivery EDM03 Ensure EDM04 Ensure Resource EDM05 Ensure Stakeholder Transparency Align, Plan and Organise Monitor, Evaluate and Assess APO01 Manage the IT Framework APO02 Manage Strategy APO03 Manage Enterprise Architecture APO04 Manage Innovation APO05 Manage Portfolio APO06 Manage Budget and Costs APO07 Manage Human Resources APO08 Manage Relationships APO09 Manage Service Agreements APO10 Manage Suppliers APO11 Manage Quality APO12 Manage APO13 Manage Security MEA01 Monitor, Evaluate and Assess Performance and Conformance Build, Acquire and Implement BAI01 Manage Programmes and Projects BAI02 Manage Requirements Definition BAI03 Manage Solutions Identification and Build BAI04 Manage Availability and Capacity BAI05 Manage Organisational Change Enablement BAI06 Manage Changes BAI07 Manage Change Acceptance and Transitioning MEA02 Monitor, Evaluate and Assess the System of Internal Control BAI08 Manage Knowledge BAI09 Manage Assets BAI10 Manage Configuration Deliver, Service and Support DSS01 Manage Operations DSS02 Manage Service Requests and Incidents DSS03 Manage Problems DSS04 Manage Continuity DSS05 Manage Security Services DSS06 Manage Business Controls MEA03 Monitor, Evaluate and Assess Compliance With External Requirements es for of Enterprise IT This figure highlights the key supporting COBIT 5 processes (shown in dark pink), as well as the other supporting processes (shown in light pink). The core risk processes are shown in light blue. Source: COBIT 5 for, figure 18

7 COBIT 5 Enterprise Enablers 2. es 3. Organisational Structures 4. Culture, Ethics and Behaviour 1. Principles, Policies and Frameworks 5. Information 6. Services, Infrastructure and Applications Resources 7. People, Skills and Competencies Source: COBIT 5, figure 12 COBIT 5 Enablers: Generic Enabler Dimension Stakeholders Goals Life Cycle Good Practices Internal Stakeholders External Stakeholders Intrinsic Quality Contextual Quality (Relevance, Effectiveness) Accessibility and Security Plan Design Build/Acquire/ Create/Implement Use/Operate Evaluate/Monitor Update/Dispose Practices Work Products (Inputs/Outputs) Enabler Performance Are Stakeholders Needs Addressed? Are Enabler Goals Achieved? Metrics for Achievement of Goals (Lag Indicators) Is Life Cycle Managed? Are Good Practices Applied? Metrics for Application of Practice (Lead Indicators) Source: COBIT 5, figure 13

8 The Seven Phases of the Implementation Life Cycle 6 Did we get there? 5 How do we get there? 7 How do we keep the momentum going? Realise benefits Embed new Execute plan approaches Review effectiveness Operate and use Operate Sustain and measure Implement improvements Monitor and evaluate Build improvements Identify role players Plan programme 4 What needs to be done? 1 What are the drivers? Initiate programme Establish desire to change Recognise need to act state Define target Assess current state Form implementation team outcome Communicate Define problems and opportunities Define road map 3 Where do we want to be? 2 Where are we now? Programme management (outer ring) Change enablement (middle ring) Continual improvement life cycle (inner ring) Source: COBIT 5, figure 17 and COBIT 5 Implementation, figure 6 Summary of the COBIT 5 Capability Model Generic Capability Attributes Performance Attribute (PA) 1.1 Performance PA 2.1 PA 2.2 Performance Work Product PA 3.1 Definition PA 3.2 Deployment PA 4.1 PA 4.2 Control PA 5.1 Innovation PA 5.2 Incomplete Performed Managed Established Predictable Optimising COBIT 5 Assessment Model Performance Indicators Outcomes COBIT 5 Assessment Model Capability Indicators Base Practices (/ Practices) Work Products (Inputs/ Outputs) Generic Practices Generic Resources Generic Work Products Source: COBIT 5, figure 19

COBIT 5. COBIT 5 Online Collaborative Environment

COBIT 5. COBIT 5 Online Collaborative Environment COBIT 5 Product Family COBIT 5 Enabler Guides COBIT 5 COBIT 5: Enabling es COBIT 5: Enabling Information Other Enabler Guides COBIT 5 Professional Guides COBIT 5 Implementation COBIT 5 for Information

More information

COBIT 5. COBIT 5 Online Collaborative Environment

COBIT 5. COBIT 5 Online Collaborative Environment COBIT 5 Product Family COBIT 5 COBIT 5 Enabler Guides COBIT 5: Enabling es COBIT 5: Enabling Information Other Enabler Guides COBIT 5 Professional Guides COBIT 5 Implementation COBIT 5 for Information

More information

Translate stakeholder needs into strategy. Governance is about negotiating and deciding amongst different stakeholders value interests.

Translate stakeholder needs into strategy. Governance is about negotiating and deciding amongst different stakeholders value interests. Principles Principle 1 - Meeting stakeholder needs The governing body is ultimately responsible for setting the direction of the organisation and needs to account to stakeholders specifically owners or

More information

COBIT 5 Foundation Exam

COBIT 5 Foundation Exam COBIT 5 Foundation Exam Sample Paper Multiple Choice Instructions 1. All 50 questions should be attempted. 2. All answers are to be marked on the answer sheet provided. 3. Please use a pencil and NOT ink

More information

If It s not a Business Initiative, It s not COBIT 5

If It s not a Business Initiative, It s not COBIT 5 If It s not a Business Initiative, It s not COBIT 5 Steve Romero CISSP PMP CPM Romero Consulting Core Competencies C22 CRISC CGEIT CISM CISA 1 9/13/2013 1 COBIT Page 11 COBIT 5 product family 2 COBIT Page

More information

Selftestengine COBIT5 36q

Selftestengine COBIT5 36q Selftestengine COBIT5 36q Number: COBIT5 Passing Score: 800 Time Limit: 120 min File Version: 16.5 http://www.gratisexam.com/ Isaca COBIT 5 COBIT 5 Foundation I have correct many of questions answers.

More information

Braindumps COBIT5 50q

Braindumps COBIT5 50q Braindumps COBIT5 50q Number: COBIT5 Passing Score: 800 Time Limit: 120 min File Version: 16.5 http://www.gratisexam.com/ Isaca COBIT 5 COBIT 5 Foundation I have correct many of questions answers. If there

More information

Changes Reviewed by Date. JO Technology Manager - Samer Huwwari JO Manager, Risk & Control Technology: Issa Laty. CIO, Jordan- Mohammad Aburoub

Changes Reviewed by Date. JO Technology Manager - Samer Huwwari JO Manager, Risk & Control Technology: Issa Laty. CIO, Jordan- Mohammad Aburoub Governance and Management of Information and Related Technologies Guide 2017 Revision History Changes Reviewed by Date Version Author JO Technology Manager - Samer Huwwari JO Manager, Risk & Control Technology:

More information

IT Assurance Services And Role Of CA In BPO-KPO. IT Enabled Services And Emerging Technologies

IT Assurance Services And Role Of CA In BPO-KPO. IT Enabled Services And Emerging Technologies IT Assurance Services And Role Of CA In BPO-KPO IT Enabled Services And Emerging Technologies Chapter 2: Facilitated e-learning Part 1 of 2 CA M S Mehta, FCA 1 IT Assurance Services and Role of CA in BPO-KPO

More information

Governance SPICE. Using COSO and COBIT Process Assessment Models BPM GOSPEL

Governance SPICE. Using COSO and COBIT Process Assessment Models BPM GOSPEL Governance SPICE Using COSO and COBIT Process Assessment Models Linking Governance to Sustainable Value Creation BPM GOSPEL (LLP-LDV-TOI-2010-HU-001) This project has been funded with support from the

More information

COBIT 5: IT is complicated. IT governance does not have to be

COBIT 5: IT is complicated. IT governance does not have to be COBIT 5: IT is complicated. IT governance does not have to be ค ณวรางคณา ม ส กะส งข - นายกสมาคมผ ตรวจสอบและควบค มระบบสารสนเทศภาคพ น กร งเทพฯ และ Director, Assurance RCS PricewaterhouseCoopers ABAS Ltd.

More information

Governance and Management of Information and Related Technologies Guide. Prepared for Jordan Ahli Bank

Governance and Management of Information and Related Technologies Guide. Prepared for Jordan Ahli Bank Governance and Management of Information and Related Technologies Guide Prepared for Jordan Ahli Bank 2017 Revision History Changes Reviewed by Approval Date Version Author ISACA Peter Tessin Feb 2017

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy 2017-2019 Created by: Role Name Title Author / Editor Kevin McMahon Head of Risk Management & Resilience Lead Executive Margo McGurk Director of Finance & Performance Approved

More information

Portfolio, Program and Project Management Using COBIT 5

Portfolio, Program and Project Management Using COBIT 5 DISCUSS THIS ARTICLE Portfolio, Program and Project Using COBIT 5 By Sunil Bakshi, CISA, CRISC, CISM, CGEIT, ABCI, AMIIB, BS 25999 LI, CEH, CISSP, ISO 27001 LA, MCA, PMP COBIT Focus 11 September 2017 Many

More information

IT Management & Governance Tool Assess the importance and effectiveness of your core IT processes

IT Management & Governance Tool Assess the importance and effectiveness of your core IT processes IT & Governance Tool Assess the importance and effectiveness of your core IT processes STRATEGY& GOVERNANCE IT & Governance Framework APPS EDM01 ITRG04 DATA &BI ITRG06 IT Governance Application Portfolio

More information

Enterprise Architecture and COBIT

Enterprise Architecture and COBIT Enterprise and COBIT The Open Group October 22, 2003 www.realirm.co.za reducing risk, adding value, driving change Agenda 2 Introduction Case Study Enterprise and IT Governance Conclusion Business Orientation

More information

ISC: UNRESTRICTED AC Attachment. Virtual Desktop Information Technology

ISC: UNRESTRICTED AC Attachment. Virtual Desktop Information Technology Virtual Desktop Information Technology February 4, 2015 THIS PAGE INTENTIONALLY LEFT BLANK ISC: UNRESTRICTED Table of Contents Executive Summary... 5 1.0 Background... 6 1.1 Explanation of the Technology

More information

IS STRATEGY & ICT GOVERNANCE PLAN FOR VICROADS

IS STRATEGY & ICT GOVERNANCE PLAN FOR VICROADS IS STRATEGY & ICT GOVERNANCE PLAN FOR VICROADS A Proposal Report Assignment: A02 - IS Strategy & ICT Governance Report Subject: IS Strategy & Governance (ISYS900038 Sem 1 2014) Group X: Ahmed Dédeche Prashanth

More information

Assistant Regional Asset Manager EU, Wider Europe and Americas. Department/Country Global Estates. Duration of job

Assistant Regional Asset Manager EU, Wider Europe and Americas. Department/Country Global Estates. Duration of job Role Profile Job Description Job Title Ref no: Assistant Regional Asset Manager EU, Wider Europe and Americas Directorate or Region Resources/Busines s Support Services Department/Country Global Estates

More information

COBIT 5 for Business Benefits Realization: A Preview. Sushil Chatterji, CGEIT

COBIT 5 for Business Benefits Realization: A Preview. Sushil Chatterji, CGEIT COBIT 5 for Business Benefits Realization: A Preview Sushil Chatterji, CGEIT AGENDA About the Publication Business Benefits: Why the time is NOW Short primer on Enterprise and IT Strategic Planning Business

More information

COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY

COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY 1. INTRODUCTION The effective management of risk is central to the ongoing success and resilience of Coca-Cola Hellenic Bottling Company (CCHBC).

More information

COBIT 5. Jimmy Heschl. Process Analytics and Control. Wien, April 12

COBIT 5. Jimmy Heschl. Process Analytics and Control. Wien, April 12 COBIT 5 Process Analytics and Control Wien, April 12 Anmerkung: Sämtliche Informationen und Abbildungen dieser Präsentation unterliegen dem Urheber- und Werknutzungsrecht und anderen Bestimmungen. Jegliche

More information

Education Quality Development for Excellence Performance with Higher Education by Using COBIT 5

Education Quality Development for Excellence Performance with Higher Education by Using COBIT 5 Education Quality Development for Excellence Performance with Higher Education by Using COBIT 5 Kemkanit Sanyanunthana Abstract The purpose of this research is to study the management system of information

More information

ENTERPRISE RISK MANAGEMENT THE KEY TO BUSINESS SUCCESS By Phil Griffiths FCA

ENTERPRISE RISK MANAGEMENT THE KEY TO BUSINESS SUCCESS By Phil Griffiths FCA ENTERPRISE RISK MANAGEMENT THE KEY TO BUSINESS SUCCESS By Phil Griffiths FCA Chapter 1 Fundamentals of Enterprise Risk Management Risk management has become a vital ingredient in the entrepreneurial culture

More information

The Value of IT Frameworks

The Value of IT Frameworks The Value of IT Frameworks Recent views from Chief Information Officers Results from the CIONET survey of European CIO s on the business value of IT Frameworks What s next. Table of Contents _ 2 Introduction...

More information

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM) The Intersection of Enterprise-wide Risk (ERM) and Business Continuity (BCM) Marc Dominus 2005 Protiviti Inc. EOE Agenda Terminology and Process Introductions ERM Process Overview BCM Process Overview

More information

Inside of a ring or out, ain t nothing wrong with going down. It s staying down that s wrong. Muhammad Ali

Inside of a ring or out, ain t nothing wrong with going down. It s staying down that s wrong. Muhammad Ali MANAGING OPERATIONAL RISK IN THE 21 ST CENTURY White Paper Series Inside of a ring or out, ain t nothing wrong with going down. It s staying down that s wrong. Muhammad Ali 2 In today s competitive and

More information

BT Identity and Access Management Quick Start Service

BT Identity and Access Management Quick Start Service BT Identity and Access Management Quick Start Service The BT Identity and Access Management Quick Start Service enables organisations to rapidly assess their Identity and Access Management (IAM) implementation

More information

ISMS AUDIT CHECKLIST

ISMS AUDIT CHECKLIST 4.1 REQUIREMENT REFER TO BS ISO / IEC 27001 : 2005 Has the organisation developed a documented ISMS based on the PDCA model? Checked at Stage 1 for development and Stage 2/surveillance for implementation,

More information

ISO INTERNATIONAL STANDARD. Risk management Principles and guidelines. Management du risque Principes et lignes directrices

ISO INTERNATIONAL STANDARD. Risk management Principles and guidelines. Management du risque Principes et lignes directrices INTERNATIONAL STANDARD ISO 31000 First edition 2009-11-15 Risk management Principles and guidelines Management du risque Principes et lignes directrices http://mahdi.hashemitabar.com Reference number ISO

More information

Building an. Effective Board

Building an. Effective Board Building an Effective Board Who we are Established in 1996, Effective Governance is now Australasia s largest and most experienced independent corporate governance consulting firm. Our mission is to deliver

More information

KING III IT GOVERNANCE ALIGNED TO. Simon Liell-Cock Julio Graham Peter Hill CISA CISM CGEIT

KING III IT GOVERNANCE ALIGNED TO. Simon Liell-Cock Julio Graham Peter Hill CISA CISM CGEIT IT GOVERNANCE ALIGNED TO KING III Simon Liell-Cock Julio Graham Peter Hill CISA CISM CGEIT IT Governance Network South Africa USA UK Switzerland www.itgovernance.co.za info@itgovernance.com 0825588732

More information

Role Description Head of Information & Digital Technology

Role Description Head of Information & Digital Technology Role Description Head of Information & Digital Technology Cluster Agency Division/Branch/Unit Location Department of Planning & Environment Office of Environment and Heritage Taronga Conservation Society

More information

Proposed IT Governance at Hospital Based on COBIT 5 Framework

Proposed IT Governance at Hospital Based on COBIT 5 Framework Int. Journal of Applied IT Vol. 01 No. 02 (2017) International Journal of Applied Information Technology http://journals.telkomuniversity.ac.id/ijait Proposed IT Governance at Hospital Based on COBIT 5

More information

ISACA. The recognized global leader in IT governance, control, security and assurance

ISACA. The recognized global leader in IT governance, control, security and assurance ISACA The recognized global leader in IT governance, control, security and assurance High-level session overview 1. CRISC background information 2. Part I The Big Picture CRISC Background information About

More information

IT and Enterprise Governance By Michael J. A. Parkinson, CISA, CIA, and Nicholas J. Baker, CPA

IT and Enterprise Governance By Michael J. A. Parkinson, CISA, CIA, and Nicholas J. Baker, CPA Copyright 2005 Information Systems Audit and Control Association. All rights reserved. www.isaca.org. IT and Enterprise Governance By Michael J. A. Parkinson, CISA, CIA, and Nicholas J. Baker, CPA Enterprise

More information

Our Corporate Strategy Information & Intelligence

Our Corporate Strategy Information & Intelligence Our Corporate Strategy Information & Intelligence May 2016 UNCLASSIFIED Information & Intelligence: Executive Summary What is our strategic approach for information & intelligence? Our decisions and actions

More information

This resource is associated with the following paper: Assessing the maturity of software testing services using CMMI-SVC: an industrial case study

This resource is associated with the following paper: Assessing the maturity of software testing services using CMMI-SVC: an industrial case study RESOURCE: MATURITY LEVELS OF THE CUSTOMIZED CMMI-SVC FOR TESTING SERVICES AND THEIR PROCESS AREAS This resource is associated with the following paper: Assessing the maturity of software testing services

More information

Guidelines for Information Asset Management: Roles and Responsibilities

Guidelines for Information Asset Management: Roles and Responsibilities Guidelines for Information Asset Management: Roles and Responsibilities Document Version: 1.0 Document Classification: Public Published Date: April 2017 P a g e 1 Contents 1. Overview:... 3 2. Audience...

More information

ASSET MANAGEMENT SERVICES

ASSET MANAGEMENT SERVICES ASSET MANAGEMENT SERVICES Petrofac Engineering & Production Services 02 ASSET MANAGEMENT SERVICES ASSET MANAGEMENT SERVICES 03 Introducing Petrofac Asset Management Services Petrofac is an international

More information

Internal Audit of ICT Governance in WFP. Office of the Inspector General Internal Audit Report AR/15/11

Internal Audit of ICT Governance in WFP. Office of the Inspector General Internal Audit Report AR/15/11 Fighting Hunger Worldwide Internal Audit of ICT Governance in WFP Office of the Inspector General Internal Audit Report AR/15/11 Contents Page I. Executive summary 3 II. Context and scope 5 III. Results

More information

Governance in a Multi-Supplier Environment

Governance in a Multi-Supplier Environment Governance in a Multi-Supplier Environment This paper provides advice and guidance for organisations faced with governing a multi-supplier environment. 1. The Need for Governance ISACA, the global IT governance

More information

HRIS TECHNICAL ARCHITECT ST VINCENT S HEALTH AUSTRALIA POSITION DESCRIPTION

HRIS TECHNICAL ARCHITECT ST VINCENT S HEALTH AUSTRALIA POSITION DESCRIPTION HRIS TECHNICAL ARCHITECT ST VINCENT S HEALTH AUSTRALIA POSITION DESCRIPTION POSITION TITLE: REPORTS TO: HRIS Technical Architect HRIS Project Director KEY RELATIONSHIPS (INTERNAL): KEY RELATIONSHIPS (EXTERNAL):

More information

SUSTAINABILITY STRATEGY

SUSTAINABILITY STRATEGY SUSTAINABILITY STRATEGY FOREWORD From the outset our business has followed a sustainable path, not only in terms of how we manage our business and create value for our shareholders, but also how we approach

More information

DUBAL s ISO based ERM Program

DUBAL s ISO based ERM Program DUBAL s ISO 31000-based ERM Program Building a Harmonized, Proactive and Sustainable Approach to Risk Management October, 2013 Toby Shore Corporate Treasurer & Chief Risk Officer DUBAL Key Things To Discuss

More information

Experience at Hinkley Point C: building Information Modelling (bim) and Enterprise Lifecycle Management Solutions Presented By: Sue Hewish & Jason

Experience at Hinkley Point C: building Information Modelling (bim) and Enterprise Lifecycle Management Solutions Presented By: Sue Hewish & Jason Experience at Hinkley Point C: building Information Modelling (bim) and Enterprise Lifecycle Management Solutions Presented By: Sue Hewish & Jason Walker Agenda: Introductions Section 1: Introduction to

More information

Business Context of ISO conform Internal Financial Control Assessment

Business Context of ISO conform Internal Financial Control Assessment Business Context of ISO 15504 conform Internal Financial Control Assessment By János Ivanyos, Memolux Ltd. (H), IIA Hungary Introduction In this paper the business context of the ISO/IEC 15504 [1] conformant

More information

COBIT 5. Isaca - COBIT 5 COBIT 5 Foundation Version: 4.0

COBIT 5. Isaca - COBIT 5 COBIT 5 Foundation Version: 4.0 Isaca - COBIT 5 COBIT 5 Foundation Version: 4.0 1 QUESTION: 1 Which principle is key for the governance and management of enterprise IT? A. ManagingIT Operations B. InsureResourceOptimization C. Enabling

More information

Risk awareness in conducting business. Why is it worth to implement risk management progamme? - Marcin Marczewski, Konrad Roziewski - SASMA TEAM

Risk awareness in conducting business. Why is it worth to implement risk management progamme? - Marcin Marczewski, Konrad Roziewski - SASMA TEAM SASMA Portal 2011 Risk awareness in conducting business. Why is it worth to implement risk management progamme? - Marcin Marczewski, Konrad Roziewski - SASMA TEAM - Marcin Marczewski, Konrad Roziewski

More information

Improved Risk Management via Data Quality Improvement

Improved Risk Management via Data Quality Improvement Improved Risk Management via Data Quality Improvement Prepared by: David Loshin Knowledge Integrity, Inc. January, 2011 Sponsored by: 2011 Knowledge Integrity, Inc. 1 Introduction All too frequently, we

More information

Advisory Services Governance, Risk & Compliance

Advisory Services Governance, Risk & Compliance Advisory Services Governance, Risk & Compliance Caribbean Association of Audit Committee Members Inc. 2010 Conference Caretakers of Integrity and Accountability: The Role of Internal Audit in Corporate

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Guidelines for information security management systems auditing

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Guidelines for information security management systems auditing INTERNATIONAL STANDARD ISO/IEC 27007 First edition 2011-11-15 Information technology Security techniques Guidelines for information security management systems auditing Technologies de l'information Techniques

More information

Transactional Products and Services Our Capabilities

Transactional Products and Services Our Capabilities and Services Our Capabilities Hasan Khan Group Head Africa s growth continues to deepen the continent s integration with the global economy. Business activity within, across, into and out of the continent

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

Environmental and Social Policy Management Systems for Financial Institutions (FI) February 2016

Environmental and Social Policy Management Systems for Financial Institutions (FI) February 2016 Environmental and Social Policy Management Systems for Financial Institutions (FI) February 2016 Agenda Welcome & Introduction What is an Environmental & Social Management System (ESMS) Including: Elements

More information

ASSURANCE FRAMEWORK. A framework to assure the Board that it is delivering the best possible service for its citizens SEPTEMBER 2010.

ASSURANCE FRAMEWORK. A framework to assure the Board that it is delivering the best possible service for its citizens SEPTEMBER 2010. ASSURANCE FRAMEWORK A framework to assure the Board that it is delivering the best possible service for its citizens SEPTEMBER 2010 V3 Draft 1 SECTION NO. ASSURANCE FRAMEWORK CONTENTS 1. INTRODUCTION 3

More information

INTEGRATED APPLICATION LIFECYCLE MANAGEMENT

INTEGRATED APPLICATION LIFECYCLE MANAGEMENT WHITEPAPER INTEGRATED APPLICATION LIFECYCLE MANAGEMENT HOW TO MANAGE SOFTWARE APPLICATIONS MORE EFFICIENTLY - AND MORE WISELY This paper will introduce you to the concept of integrated Application Lifecycle

More information

ITIL Foundation Instructor-led Live Online Training Program

ITIL Foundation Instructor-led Live Online Training Program Course Outline Service management as a practice Describe the concept of best practices in the public domain Describe and explain why ITIL is successful Define and explain the concept of a service Define

More information

Digital and Technology Solutions Specialist Degree Apprenticeship standard (Level 7)

Digital and Technology Solutions Specialist Degree Apprenticeship standard (Level 7) Digital and Technology Solutions Specialist Degree Apprenticeship standard (Level 7) 1. Digital and Technology Solutions Specialist Overview A digital and technology solutions specialist is a specialist

More information

( %)'* + 7# (&)*)')%&&+)*)-.)/##############################################################!

( %)'* + 7# (&)*)')%&&+)*)-.)/##############################################################! "$%&'% ( %)'* + " $%&'(&)*)')%&&+), " (&)*)')%&&+)(&-( "" (&)*)')%&&+)*)-.)/0 " (&)*)')%&&+)*)-.)/$1 + '%, - "%&&%. 0 /(.(.&%(&)*)'23-(&%2-+()'4 0 &%5&((&)*)'()-(/(&4 / 0$%'% 1 -+'(.-(6.(/(&6&-((26&3&-/*6/(&,

More information

Enterprise intelligence in modern shipping

Enterprise intelligence in modern shipping Enterprise intelligence in modern shipping Leveraging commercial and cost performance with data analytics 7th Capital Link Greek Shipping Forum 16 February 2016 Agenda I. What is Enterprise Intelligence?

More information

Measuring and Improving Information Technology Governance through the Balanced Scorecard

Measuring and Improving Information Technology Governance through the Balanced Scorecard Measuring and Improving Information Technology Governance through the Balanced Scorecard Wim Van Grembergen University of Antwerp University Antwerp Management School Steven De Haes University Antwerp

More information

Guidance for Smaller Public Companies Reporting on Internal Control Over Financial Reporting Exposure Draft

Guidance for Smaller Public Companies Reporting on Internal Control Over Financial Reporting Exposure Draft 3701 Algonquin Road, Suite 1010 Telephone: 847.253.1545 Rolling Meadows, Illinois 60008, USA Facsimile: 847.253.1443 Web Sites: www.isaca.org and www.itgi.org 13 January 2006 COSO Board In care of Dr.

More information

Recognised for Excellence

Recognised for Excellence Recognised for Excellence Applicant Guide The objective of this guide is to help you prepare a submission document for Recognised for Excellence. Recognised for Excellence Guidelines These guidelines have

More information

Internal audit operating at the strategic level

Internal audit operating at the strategic level Internal audit operating at the strategic level Strategic collaboration Auditing strategic risks Audit plan alignment Malcolm Zack Director Zack Associates Limited Major retailer Zack Associates Limited

More information

Risk Management Policy

Risk Management Policy Risk Management Policy IPH Limited ACN 169 015 838 1. Introduction Organisations of all types and scale face internal and external factors and influences that make it uncertain whether and when they will

More information

Practical Process Improvement: the Journey and Benefits

Practical Process Improvement: the Journey and Benefits Practical Process Improvement: the Journey and Benefits 27-29 September 2004 Colin Connaughton AMS Metrics Consultant CMM, Capability Maturity Model, and Capability Maturity Modeling are registered in

More information

Applying Integrated Assurance Management Scenarios for Governance Capability Assessment

Applying Integrated Assurance Management Scenarios for Governance Capability Assessment Applying Integrated Assurance Management Scenarios for Governance Capability Assessment János Ivanyos Trusted Business Partners Ltd, Budapest, Hungary, ivanyos@trusted.hu Abstract. The well established

More information

Harbinger Escrow Services Backup and Archiving Policy. Document version: 2.8. Harbinger Group Pty Limited Delivered on: 18 March 2015

Harbinger Escrow Services Backup and Archiving Policy. Document version: 2.8. Harbinger Group Pty Limited Delivered on: 18 March 2015 Document version: 2.8 Issued to: Harbinger Escrow Services Issued by: Harbinger Group Pty Limited Delivered on: 18 March 2015 Harbinger Group Pty Limited, Commercial in Confidence Table of Contents 1 Introduction...

More information

Business Principles. Business Principles

Business Principles. Business Principles Business Principles Business Principles 1 1.1. Introduction As one of Europe s leading independent oil and gas companies, Cairn Energy PLC ( Cairn or the Company ) aims to discover, develop and deliver

More information

DECISION 10/2014/GB OF THE GOVERNING BOARD OF THE EUROPEAN POLICE COLLEGE ADOPTING THE EUROPEAN POLICE COLLEGE S INTERNAL CONTROL STANDARDS AND

DECISION 10/2014/GB OF THE GOVERNING BOARD OF THE EUROPEAN POLICE COLLEGE ADOPTING THE EUROPEAN POLICE COLLEGE S INTERNAL CONTROL STANDARDS AND DECISION 10/2014/GB OF THE GOVERNING BOARD OF THE EUROPEAN POLICE COLLEGE ADOPTING THE EUROPEAN POLICE COLLEGE S INTERNAL CONTROL STANDARDS AND AMENDING THE DECISION 08/2011/GB Adopted by the Governing

More information

Telehealth Quality Planning Guidelines and their relevance to Architecture, Maturity Models, and Implementation

Telehealth Quality Planning Guidelines and their relevance to Architecture, Maturity Models, and Implementation Telehealth Quality Planning Guidelines and their relevance to Architecture, Maturity Models, and Implementation Alan Taylor CEng MIEE Flinders University & edevelopment Solutions http://edevelopment.net.au/edevel/

More information

Response to Consultation on Governance Arrangements for the UPI: Key Criteria and Functions

Response to Consultation on Governance Arrangements for the UPI: Key Criteria and Functions FAO: Financial Stability Board (FSB) and Working Group on UTI and UPI Governance (GUUG) Ms Emma Kalliomaki Managing Director Assoc. of National Numbering Agencies & Derivatives Service Bureau Phone: +46

More information

MECHANICAL JOINT INTEGRITY ROUTE TO COMPETENCE GUIDANCE. Working together to prevent hydrocarbon releases through safety critical competence

MECHANICAL JOINT INTEGRITY ROUTE TO COMPETENCE GUIDANCE. Working together to prevent hydrocarbon releases through safety critical competence MECHANICAL JOINT INTEGRITY ROUTE TO COMPETENCE GUIDANCE Working together to prevent hydrocarbon releases through safety critical competence Revision 2, June 2 2013 AN OVERVIEW Mechanical joints have the

More information

Taking ERM to a. 6 GRC Today / October 2015

Taking ERM to a. 6 GRC Today / October 2015 GLOBAL SCALE 6 GRC Today / October 2015 Global Scale lobal events highlighted by G business scandals, failures, information theft, and natural disasters have shone the spotlight yet again on risk management

More information

Authors: Steven Jewell Assistant Director IT and e-government Tel: ; Paul Fleming Systems Architect

Authors: Steven Jewell Assistant Director IT and e-government Tel: ; Paul Fleming Systems Architect IT SYSTEMS REPORT SYSTEMS INTERFACES AND INTEGRATION ITEM 8 AUDIT COMMITTEE 28 MARCH 2012 Authors: Steven Jewell Assistant Director IT and e-government Tel: 01908 254141; Paul Fleming Systems Architect

More information

Operational Excellence:

Operational Excellence: An Intensive 5 Day Training Course Operational Excellence: Managing Performance in the Oil & Gas Industry 16-20 Oct 2017, London 15-19 Jul 2018, Dubai 15-19 Oct 2018, London 24-JUL-17 This course is Designed,

More information

GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2))

GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2)) GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2)) Operational Risk Management MARCH 2017 STATUS OF GUIDANCE The Isle of Man Financial Services Authority ( the Authority ) issues guidance for

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO 19011 Second edition 2011-11-15 Guidelines for auditing management systems Lignes directrices pour l audit des systèmes de management Reference number ISO 19011:2011(E) ISO 2011

More information

CORPORATE GOVERNANCE KING III COMPLIANCE

CORPORATE GOVERNANCE KING III COMPLIANCE CORPORATE GOVERNANCE KING III COMPLIANCE Analysis of the application as at March 2013 by AngloGold Ashanti Limited (AngloGold Ashanti) of the 75 corporate governance principles as recommended by the King

More information

ISO Standards in Strengthening Organizational Resilience and Mitigating Risk while Addressing Quality and Sustainability

ISO Standards in Strengthening Organizational Resilience and Mitigating Risk while Addressing Quality and Sustainability ISO Standards in Strengthening Organizational Resilience and Mitigating Risk while Addressing Quality and Sustainability January 20, 2017 Copyright 2012 BSI. All rights reserved. Who is BSI? By Royal Charter:

More information

COURSE DESCRIPTION CUSTOMER EXPERIENCE MANAGEMENT IN TELECOMS. Format: Classroom. Duration: 2 Days

COURSE DESCRIPTION CUSTOMER EXPERIENCE MANAGEMENT IN TELECOMS. Format: Classroom. Duration: 2 Days COURSE DESCRIPTION CUSTOMER EXPERIENCE MANAGEMENT IN TELECOMS Format: Classroom Duration: 2 Days COURSE SUMMARY HIGHLIGHTS Transforms current churn reduction techniques into an holistic customer asset

More information

Job Description. Department

Job Description. Department Job Description Job Title Business Change Manager Department Corporate Portfolio Management Grade (if applicable) Location Riverside Head Office Job Purpose Undertake the role of Business Change Manager

More information

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

PASS4TEST. IT Certification Guaranteed, The Easy Way!  We offer free update service for one year PASS4TEST \ We offer free update service for one year Exam : ITIL-F Title : ITIL Foundation Vendor : EXIN Version : DEMO Get Latest & Valid ITIL-F Exam's Question and Answers 1from Pass4test. 1 NO.1 What

More information

Operating Management System Framework

Operating Management System Framework Operating Management System Framework OGP Report No. 510 June 2014 for controlling risk and delivering high performance in the oil and gas industry Disclaimer Whilst every effort has been made to ensure

More information

1010 La Trobe Street Docklands Victoria

1010 La Trobe Street Docklands Victoria Position description Position Group Reports to Location Service Desk Administrator Telecommunications IT Service Delivery Manager 1010 La Trobe Street Docklands Victoria Date 2018 Our organisation VicTrack

More information

Rules, Procedures, and Internal Controls Manual BRAM Bradesco Asset Management

Rules, Procedures, and Internal Controls Manual BRAM Bradesco Asset Management Rules, Procedures, and Internal Controls Manual BRAM Bradesco Asset Management MP_8231_0070 01 27/06/2016 1 / 12 Table of contents 1. OBJECTIVE... Erro! Indicador não definido. 2. DEFINITIONS... Erro!

More information

Using assessment & benchmarking techniques as a strategic approach to drive Continual Service Improvement

Using assessment & benchmarking techniques as a strategic approach to drive Continual Service Improvement Using assessment & benchmarking techniques as a strategic approach to drive Continual Service Improvement Ian MacDonald Function Leader, Group Technology Co-operative Group IT Session Outline What you

More information

NSW DIGITAL GOVERNMENT STRATEGY. digital nsw DRIVING WHOLE OF GOVERNMENT DIGITAL TRANSFORMATION DESIGNING IN OUR NSW DIGITAL FUTURE

NSW DIGITAL GOVERNMENT STRATEGY. digital nsw DRIVING WHOLE OF GOVERNMENT DIGITAL TRANSFORMATION DESIGNING IN OUR NSW DIGITAL FUTURE NSW DIGITAL GOVERNMENT STRATEGY digital nsw DRIVING WHOLE OF GOVERNMENT DIGITAL TRANSFORMATION DESIGNING IN OUR NSW DIGITAL FUTURE CONTENTS 1 MINISTER S FOREWORD 2 TRANSFORMATION IMPERATIVE 3 ROAD MAP

More information

Director Procurement & Value Delivery

Director Procurement & Value Delivery Position Reports to Direct Reports Band Director Procurement & Value Delivery Chief Executive Heads of Procurement (3), Sustainability Officer (1), Head Procurement Operations (1), Head Clinical Engagement

More information

Australian Standard 8015 : 2005

Australian Standard 8015 : 2005 Australian Standard 8015 : 2005 Arrianto Mukti Wibowo, M.Sc., CISA IT Governance Lab Faculty of Computer Science University of Indonesia Agenda Intro, Tujuan, definisi, Prinsip-prinsip Model AS-8015 Keluarga

More information

A Risk Management Process for Information Security and Business Continuity

A Risk Management Process for Information Security and Business Continuity A Risk Management Process for Information Security and Business Continuity João Carlos Gonçalves Fialho Instituto Superior Técnico - Taguspark joaogfialho@gmail.com ABSTRACT It was from the DNS.PT internship

More information

WHITE PAPER The Three Stages of Harnessing Inventory in the S&OP Journey. Executive Summary

WHITE PAPER The Three Stages of Harnessing Inventory in the S&OP Journey. Executive Summary WHITE PAPER The Three Stages of Harnessing Inventory in the S&OP Journey Sales and Operations Planning is a cross functional process to align and develop a conscientious plan between sales, marketing and

More information

The CIPD profession map: a guide

The CIPD profession map: a guide The CIPD profession map: a guide Contents Introduction... 3 The design principles and architecture of the Profession Map... 4 Bands and transitions... 5 Transitions: moving through the bands... 7 Professional

More information

ISO 14001: 2015 Environmental Gap Analysis

ISO 14001: 2015 Environmental Gap Analysis Environmental Gap Analysis The revised ISO 14001 standard was published on 14 TH September 2015. How to use this document This document provides an overview of the changes between ISO 14001:2004 and ISO

More information

Record requests, Capture events, Analyze results and trends. Prioritize based in facts and finding.

Record requests, Capture events, Analyze results and trends. Prioritize based in facts and finding. Facilitated Compliance Management How vast is Your Universe? Compliance is a universe of constraints enforcing business and technology practice aligned to minimally acceptable product, service and financial

More information

Group Chief Risk Officer

Group Chief Risk Officer 165 We made excellent progress towards Group 's 2015 roadmap of high performance risk culture across the Group, as we have built robust and scalable foundations, enabling us to create value to support

More information

Portfolio Management Professional

Portfolio Management Professional An Intensive 5 Day Training Course Portfolio Management Professional 13-17 May 2018, Dubai 30-JAN-18 This course is Designed, Developed, and will be Delivered under iso Quality standards Portfolio Management

More information

CFAM4.2.1 Develop advertising strategy

CFAM4.2.1 Develop advertising strategy Overview This is about identifying the role of advertising, setting advertising objectives, strategy and budget. It includes establishing `where we are now', and `where we want to be', establishing the

More information