and COBIT 5 ISACA STRATEGIC ADVISORY BOARD VICE PRESIDENT STRATEGY & INNOVATION CA TECHNOLOGIES 2012 ISACA. All Rights Reserved.

Similar documents
2012 ISACA. All rights reserved. No part of this publication may be used, copied, reproduced, modified, distributed, displayed, stored in a retrieval

ISACA All Rights Reserved.

2012 ISACA Webinar Program. ISACA All rights reserved.

COBIT 5: IT is complicated. IT governance does not have to be

Translate stakeholder needs into strategy. Governance is about negotiating and deciding amongst different stakeholders value interests.

Achieving Business/IT Alignment through COBIT 5

If It s not a Business Initiative, It s not COBIT 5

COBIT 5 for Information Security. Dr. Derek J. Oliver Co-Chair, COBIT 5 Task Force

September 17, 2012 Pittsburgh ISACA Chapter

Annex 1 (Integrated frameworks on Business/IT alignment) Annex 2 Goals Cascade, adapted from COBIT5

Introduction to COBIT 5

COBIT 5. COBIT 5 Online Collaborative Environment

Evidence Management for the COBIT 5 Assessment Programme By Jorge E. Barrera N., CISA, CGEIT, CRISC, COBIT (F), ITIL V3F, PMP

COBIT 5. COBIT 5 Online Collaborative Environment

Portfolio, Program and Project Management Using COBIT 5

Governance, COBIT and the Cloud a match made in the sky! Robert E Stroud CGEIT International Vice President ISACA Treasurer, Director Audit,

COBIT 5 Foundation Exam

Selftestengine COBIT5 36q

IT and Security Governance. Jacqueline Johnson

COBIT 5. COBIT 5 Online Collaborative Environment

Information and Technology. Governance. System for

Enterprise Governance of IT

Braindumps COBIT5 50q

Driving Enterprise IT Strategy Alignment and Creating Value Using the COBIT 5 Goals Cascade

COBIT 5. COBIT 5 Online Collaborative Environment

ISO/IEC Process Mapping to COBIT 4.1 to Derive a Balanced Scorecard for IT Governance

CGEIT Certification Job Practice

Benchmarking of COBIT 5 PAM Assessments Performed in Brazilian Public Sector Banking Organizations

Implementation of Service Integration in a Multiprovider Environment Using COBIT 5

ISACA. The recognized global leader in IT governance, control, security and assurance

Call for Articles. By Sudarsan Jayaraman, CISA, CISM, BS LA, COBIT (F), ITIL V3 Expert, ISO LA, ISO LA, ISO 9001 LA

An IT Governance Journey April Disclaimer: opinion being those of presenter(s) and not necessarily State Farm

Feature. Unlocking Hidden Value in ERP System Acquisitions Using Risk Management. Risk. Monitoring. Residual Risk Acceptance.

Communicating Trends and Risks Found in. Robert E Stroud CGEIT CRISC Vice President Strategy & Innovation CA Technologies

Principles, Policies and Frameworks. Processes. Organisational Structures. Culture, Ethics and Behaviour. Information

A COBIT 5 PAM Update Compliant With ISO/IEC 330xx Family

Understanding the Challenge and Incredible Potential of IT Governance

Assessment of IT Operations. Frameworks* An Overview

Cobit 5! Not just for your Auditor!! Fusion (Cobit as an approach to Business & IT Alignment)! Integra(on

Changes Reviewed by Date. JO Technology Manager - Samer Huwwari JO Manager, Risk & Control Technology: Issa Laty. CIO, Jordan- Mohammad Aburoub

A Case Study Implementing COBIT 5

CGEIT QAE ITEM DEVELOPMENT GUIDE

Existing interactions within COBIT 5 and their driving forces

COBIT 5.0: Capability Level of Information Technology Directorate General of Treasury

Log of Changes Implemented to the COBIT 5 Product Family

Implementation of the CO BIT -3 Maturity Model in Royal Philips Electronics

IT Audit Process. Prof. Mike Romeu. February 13, IT Audit Process. Prof. Mike Romeu

COBIT 5: a bridge too far or a giant leap forward? A view from the field

Governance and Management of Information and Related Technologies Guide. Prepared for Jordan Ahli Bank

Cabinet Office Mandate for Change Project Requirements for Portfolio, Programme and Project Management Maturity Model (P3M3 ) Revisions

Agile Capability Improvement with IT- CMF

Does Assurance Add Value? (We Don t Know What We Don t Know Until We Know It) John Mitchell. PhD, MBA, CEng, CITP, FBCS, CFIIA, CISA, CGEIT, QiCA, CFE

COBIT 5 for Business Benefits Realization: A Preview. Sushil Chatterji, CGEIT

6. IT Governance 2006

HEALTH PURCHASING VICTORIA STRATEGY. December 2017

Job Description. No of Direct Reports : 0. Titles of Direct Reports: Size of Department: 5. Budget Responsibility (direct) :

Auditing Identity & Access Management: Addressing the Root Causes

Developing a successful governance strategy. By Muhammad Iqbal Hanafri, S.Pi., M.Kom. IT GOVERNANCE STMIK BINA SARANA GLOBAL

CGEIT ITEM DEVELOPMENT GUIDE

Senior Manager. Develop and design effective enterprise solutions that meet the business requirements while ensuring alignment to the IT strategy.

Outlines. Background Overviews Benefits of IT Governance Definitions IT Governance vs IT management/it controls Implementation and Frameworks

EVALUATION OF THE IMPLEMENTATION PROCESS AND SUPPORT ON THE VESTYNA APPLICATION

Service Strategy Quick Reference Guide

Enterprise Security Architecture A Top-down Approach. Contextual Security Architecture. Logical Security Architecture. Physical Security Architecture

Service management. The future. Colin Rudd FBCS, CITP, CEng, FLPI, (Copenhagen September 2013)

EOH Managed Services EOH MANAGED & OUTSOURCED SERVICES. We re in IT together

Enterprise SPICE Good to Go!

COBIT & SFIA as Organisational Design Tools

The IT Management Mistakes Report 2016

ITIL V3 Managing Across the Lifecycle

Supervisory Committee Expectations of Internal Audit

D ENABLE. Dimension 4 competence title and generic description level 1 level 2 level 3 level 4 level 5 knowledge skills

Technology s Role in Enterprise Risk Management

C**** COBIT. Nootdorp

Personal Copy of: Mr. Le Thanh Trung

Final Audit Report. Audit of Information Technology (IT) Planning. June Canada

What is the Best Approach for BA s, PM s, BRM s, and EA s to Work Together?

Further excellence. Freedom of association. How can you enhance social responsibility within your supply chain? Social responsibility Audit solutions

The Value of IT Frameworks

CONTINUAL SERVICE IMPROVEMENT ITIL INTERMEDIATE TRAINING & CERTIFICATION

What do you mean, the whole business is a service provider?!? We re not IT

BT Identity and Access Management Quick Start Service

Kaplan-Norton Balanced Scorecard Certification Boot Camp

Embed with SFIA Secrets from the missing Framework

The Chartered Project Professional Standard

The information contained herein is subject to change without notice.

Vacancy reference: Applications close: Friday 27 April 2018

Purposing the entirety of COBIT5 for the Assurance Professional. Ross E. Wescott MA CISA CIA CCP CUERME Wescott & Associates

Education Quality Development for Excellence Performance with Higher Education by Using COBIT 5

May 2018 Latest update. ISO/IEC Understanding the requirements of ISO/IEC :2011 and ISO/IEC FDIS

ISO at Scottish Water. Colin Duguid. Lesley Juskowiak. November 2014

The Balanced Scorecard

The IT Balanced Scorecard Revisited

Asset Management Maturity

May 2018 Latest update. ISO/IEC Understanding the requirements of ISO/IEC :2011 and ISO/IEC FDIS

Responsive Risk Management. Francesca Gomez, Deloitte

PART 1: INTRODUCTION. Purpose of the BIZBOK Guide. What is Business Architecture?

The purpose of this document is to define the overall IT Strategy for the period 2016 to 2021

Implementation of ITIL within Royal London Group. Stephanie Addison

Transcription:

Comparing COBIT4.1 and COBIT 5 ROBERT E STROUD CGEIT CRISC ISACA STRATEGIC ADVISORY BOARD VICE PRESIDENT STRATEGY & INNOVATION CA TECHNOLOGIES 1 2012 ISACA. All Rights Reserved.

Comparing COBIT 4.1 and COBIT 5 Abstract COBIT 5 integrates Risk IT, Val IT, BMIS and COBIT 4.1 into a single business framework. This integrated approach facilitates more effective delivery of value to stakeholders from the more appropriate and effective governance and management of enterprise IT assets. By now you are aware that COBIT 5 distinguishes between governance and management, but did you know that COBIT 5 is now organized around five governance of enterprise IT (GEIT) principles and seven enablers, delivers a new process reference model, covers enterprise activities endto-end and much more? This session will provide you with information on the differences between COBIT 4.1 and COBIT 5 and provide you information you need to move forward with COBIT 5! 2 2012 ISACA. All Rights Reserved.

Robert E Stroud CRISC CGEIT Vice President Strategy & Innovation Evangelist Service Management, Governance & Cloud Computing Immediate Past International Vice President ISACA\ITGI ISACA Strategic Advisory Council 15 years Banking Experience Contributor t COBIT, VALIT and RISK IT Immediate Past Executive Board itsmf Intl. Treasurer and Director Audit Standards & compliance Former Board Member USA itsmf Author, Public Speaker & Industry GeeK 3

Where are we COBIT 4.1, Val IT and Risk IT users who are already engaged in governance of enterprise IT (GEIT) Implementation activities can transition to COBIT 5 and benefit from the latest and dimproved guidance COBIT 5 builds on previous versions ISACA IP 4

Stakeholder Value and Business Objectives Enterprises exist to create value for their stakeholders Consequently, any enterprise, commercial or not will have value creation as a governance objective Value creation: Realising benefits at an optimal resource cost while optimising risk Source: COBIT 5, figure 3. 2012 ISACA All rights reserved. 5

Stakeholder Value and Business Objectives Principle 1. Meeting Stakeholder Needs: Stakeholder needs transformed into an enterprise s s actionable strategy COBIT 5 goals cascade translates stakeholder needs into specific, actionable and customised goals within the context t of the enterprise, IT-related goals and enabler goals 6 Source: COBIT 5, figure 4. 2012 ISACA All rights reserved.

Stakeholder Value and Business Objectives (cont.) Stakeholder needs can be related to a set of generic enterprise goals These enterprise goals have been developed using the Balanced Scorecard (BSC) dimensions. (Kaplan, Robert S.; David P. Norton; The Balanced Scorecard: Translating Strategy into Action, Harvard University Press, USA, 1996) The enterprise goals are a list of commonly used goals that an enterprise has defined for itself Although h this list is not exhaustive, most enterprise-specific ifi goals can be easily mapped onto one or more of the generic enterprise goals 7

Stakeholder Value and Business Objectives (cont.) 8 Source: COBIT 5, figure 5. 2012 ISACA All rights reserved.

Stakeholder Value and Business Objectives (cont.) Goals cascade introduced in COBIT 4.0 in 2005 Goals cascade supports the COBIT 5 stakeholder needs principle The goals cascade has been revisited and updated for the COBIT 5 release 9

COBIT framework evolution Governance of Enterprise IT ution of scope Evol IT Governance Management Control Audit VlIT20 Val 2.0 (2008) Risk IT (2009) COBIT1 COBIT2 COBIT3 COBIT4.0/4.1 COBIT 5 1996 1998 2000 2005/7 2012 An business framework from ISACA, at www.isaca.org/cobit 10 2012 ISACA All rights reserved.

Governance and Management Defined Governance ensures that enterprise objectives are achieved by evaluating stakeholder needs, conditions and options; setting direction through prioritisation and decision making; and monitoring performance, compliance and progress against agreed-on direction and objectives (EDM). Management plans, builds, runs and monitors activities in alignment with the direction set by the governance body to achieve the enterprise objectives (PBRM). 11

Governance and Management Defined 12 Source: COBIT 5, figure 15. 2012 ISACA All rights reserved.

Areas of Change Major changes in COBIT 5 content New GEIT Principles Increased Focus on Enablers New Process Reference Model New and Modified Processes Practices and Activities Goals and Metrics Inputs and Outputs RACI Charts Process Capability Maturity Models and Assessments 13

14 Source: COBIT 5, figure 2. 2012 ISACA All rights reserved. New GEIT Principles

New GEIT Principles (cont.) Val IT and Risk IT frameworks are principles-based Feedback indicated that principles are easy to understand and put into an enterprise context, allowing value to be derived dfrom the supporting guidance more effectively. ISO/IEC 38500 also incorporates principles to underpin its messages to achieve the same market benefit delivery Principles in ISO/IEC 38500 and COBIT 5 differ 15

16 Source: COBIT 5, figure 12. 2012 ISACA All rights reserved. Focus on Enablers

Increased Focus on Enablers Information, infrastructure, applications (services) and people (people, skills and competencies) were COBIT 4.1 resources Principles, policies and frameworks were mentioned in a few COBIT 4.1 processes Processes were central to COBIT 4.1 Organisational structure was implied through the responsible, accountable, consulted or informed (RACI) roles and their definitions Culture, ethics and behaviour were mentioned in a few COBIT 4.1 processes 17

New Process Reference Model for COBIT 5 Revised process reference model with a new governance domain Several new and modified processes Enterprise activities end-to-end Business and IT function areas Aligns with current best practices, e.g., ITIL, TOGAF, PmBok, ISO\IEC 27000, etc The new model can be used as a guide for adjusting as necessary the enterprise s own process model 18

19 Source: COBIT 5, figure 16. 2012 ISACA All rights reserved.

New and Modified Processes Five new governance processes that have leveraged and improved COBIT 4.1, Val IT and Risk IT governance approaches This guidance: Helps enterprises to further refine and strengthen executive management-level GEIT practices and activities Supports GEIT integration with existing enterprise governance practices and is aligned with ISO/IEC 38500 20

New and Modified Processes Single process reference model 21

New and Modified Processes New and modified processes: APO03 Manage enterprise architecture. t APO04 Manage innovation. APO05 Manage portfolio. APO06 Manage budget and costs. APO08 Manage relationships. APO13 Manage security. BAI05 Manage organisational change enablement. BAI08 Manage knowledge. BAI09 Manage assets. DSS05 Manage security service. DSS06 Manage business process controls. 22

New and Modified Processes COBIT 5 processes now cover end-to-end business and IT activities, i.e., a full enterprise-level view This provides for a more holistic and complete coverage of practices reflecting the pervasive enterprise-wide id nature of IT use The involvement, responsibilities and accountabilities of business stakeholders in the use of IT more explicit and transparent 23

Practices and Activities The COBIT 5 governance or management practices are equivalent to the COBIT4.1 control objectives and dval IT and Risk IT processes www.isaca.org/journal/past-issues/2011/volume-4/pages/where- / / /V / g /W Have-All-the-Control-Objectives-Gone.aspx The COBIT 5 activities are equivalent to the COBIT 4.1 control practices and Val IT and Risk IT management practices COBIT 5 integrates and updates all of the previous content into the one new model, making it easier for users to understand and use this material when implementing improvements 24

Goals and Metrics COBIT 5 follows the same goal and metric concepts as COBIT 4.1, Val IT and Risk IT, but these are renamed enterprise goals, IT-related goals and process goals reflecting an enterprise level view COBIT 5 provides a revised goals cascade based on enterprise goals driving IT-related goals and then supported by critical processes COBIT 5 provides examples of goals and metrics at the enterprise, process and management practice levels. This is a change to COBIT 4.1, Val IT and Risk IT, which went down one level lower 25

Inputs and Outputs COBIT 5 provides inputs and outputs for every management practice, whereas COBIT 4.1 only provided these at the process level Additional i detailed dguidance for designing i processes to include essential work products and to assist with inter- process integration 26

RACI Charts COBIT 5 provides RACI charts describing roles and responsibilities in a similar way to COBIT 4.1, Val IT and Risk IT COBIT 5 provides a more complete, detailed d and clearer range of generic business and IT role players and charts than COBIT 4.1 for each management practice, enabling better definition of role player responsibilities or level of involvement when designing and implementing processes 27

RACI Charts (cont.) Source: COBIT 4.1, page 39. 2007 IT Governance Institute All rights reserved. 28 Source: COBIT 5: Enabling Processes, page 31. 2012 ISACA All rights reserved.

Process Capability Maturity Models and Assessments COBIT 4.1, Val IT and Risk IT CMM-based capability maturity modelling approach terminated New process capability assessment approach based on ISO/IEC 15504, and the COBIT Assessment Programme www.isaca.org/knowledge-center/cobit/pages/cobit- Assessment-Programme.aspx COBIT 4.1, Val IT and Risk IT CMM-based approaches are not considered compatible with the ISO/IEC 15504 approach because the methods use different attributes and measurement scales. 29

Process Capability Maturity Models and Assessments COBIT 4.1/5 30 2012 ISACA All rights reserved.

Process Capability Maturity Models and Assessments The COBIT Assessment Programme approach is considered d by ISACA to be more robust, reliable and repeatable as a process capability assessment method The COBIT Assessment Programme supports: Formal assessments by accredited assessors Less rigorous self-assessments for internal gap gpanalysis and process improvement planning The COBIT Assessment Programme potentially enable an enterprise to obtain an independent and certified assessments aligned to the ISO/IEC standard 31

Process Capability Maturity Models and Assessments COBIT Process Assessment Model (PAM): Using COBIT 41 4.1 Serves as a base reference document for the performance of a capability assessment of an organisation s current IT processes against COBIT COBIT Assessor Guide: Using COBIT 4.1 Provides details on how to undertake a full ISO-compliant assessment COBIT Self-assessment Guide: Using COBIT 4.1 Provides guidance on how to perform a basic self-assessment of an organisation s current IT process capability levels against COBIT processes 32

Process Capability Maturity Models and Assessments COBIT 4.1, Val IT and Risk IT users wishing to move to the new COBIT Assessment Programme approach will need to: realign their previous ratings adopt and learn the new method initiate anewsetofassessments assessments 33

Process Capability Maturity Models and Assessments COBIT 4.1, Val IT and Risk IT users wishing to continue with the CMM-based approach, either as an interim or ongoing approach, can use the COBIT 5 guidance, but must use the COBIT 4.1 generic attribute table without the high-level maturity models. 34

COBIT 5 delivers value! COBIT 5 helps enterprises create optimal value from IT by maintaining a balance between realising benefits and optimising risk levels and resource use. COBIT 5 enables information and related technology to be governed and managed in a holistic manner The COBIT 5 principles and enablers are generic generally applicable! A series of publications, education and online collaboration will drive COBIT forward! 35

36 Source: COBIT 5, figure 11. 2012 ISACA All rights reserved. COBIT 5 Product Family

COBIT 5 Future Supporting Products 37 Professional Guides: COBIT 5 for Information Security COBIT 5 for Assurance COBIT 5 for Risk Enabler Guides: COBIT 5: Enabling Information COBIT Online Replacement COBIT Assessment Programme: Process Assessment Model (PAM): Using COBIT 5 Assessor Guide: Using COBIT 5 Self-assessment Guide: Using COBIT 5