Cobit 5 - An Overview

89
COBIT – 5 A Brief Overview Anurag Purohit MILES Series

Transcript of Cobit 5 - An Overview

Page 1: Cobit 5 - An Overview

COBIT – 5A Brief Overview

Anurag PurohitMILES Series

Page 2: Cobit 5 - An Overview

About Me ..

Page 3: Cobit 5 - An Overview

• Computer Engineer with Around 12 Yrs. of Experience in IT

• MS Software Systems – BITS Pilani, India

• ISACA Certified CISA Professional• Working With Saud Bahwan

Group-Muscat for Around 10 Yrs.• Experienced in Application

Developments, Project Management, Agile, BI

• Areas of Interest are Corporate Governance of Enterprise IT, IT Management, Risk, Compliance, QMS, IT Audit, Dashboards & Development of KPIs, KGIs & KRIs

• Can be contacted at [email protected]

Page 4: Cobit 5 - An Overview

References..

• ISACA.org• CISA Manual• CISM Manual• CRISC Manual• Various Publications of COBIT• ISO.org• PMI.org• Google.com and many other websites for diagrams, logos and

Pictures• IBM.com• Microsoft.com• Breach of copyright is totally unintentional and for knowledge

sharing purpose only.• View Presented in the Presentation are purely author’s

understanding of the subject. It may defer than the actual subject.

Page 5: Cobit 5 - An Overview

Let’s Start …

Page 6: Cobit 5 - An Overview

IT and it’s Implementation..

Some of the Exciting, NotableAnd Sometimes Confusing

Common Phrases and Challenging (or Alien) Terms Generally We Come Across

Page 7: Cobit 5 - An Overview

IT projects fail to deliver what they

promised

Restrictions in IT – Hurdle in

business strategyIT is not Available

%of critical business

processes Control cost of IT

Enough people, skill levels and performances

Assurance over IT Information is secured

IT projects fail to deliver what they

promised

Restrictions in IT – Hurdle in

business strategyIT is not available

%of critical business

processes

Page 8: Cobit 5 - An Overview

Efficient and resilient IT operation

Value from ITUser satisfaction

Levels and quality of IT Services

Are we exploiting new technologies for new strategic

opportunities

Structure my IT Dependency on

external providers

Management of outsourcing agreements

Control cost of IT Enough people, skill levels and performances

Assurance over IT

Information is secured

Page 9: Cobit 5 - An Overview

These are Some Common Concerns About

Management & Governance of

IT and Related Technologies

Page 10: Cobit 5 - An Overview

So..?

So What … There is a Solution

Page 11: Cobit 5 - An Overview

If You’re looking forward for the Solution…then Refer

Control Objectives for Information & Related Technologies

Page 12: Cobit 5 - An Overview

COBIT Is a

Business Framework for the

Governance & Management of

Enterprise IT

Page 13: Cobit 5 - An Overview

Generates Optimal Value from IT By

Benefit Realization

Risk Optimization

Page 14: Cobit 5 - An Overview

Based on

5Key Principles

Page 15: Cobit 5 - An Overview

Meeting Stakeholders Needs

Page 16: Cobit 5 - An Overview

Covering Enterprise End to End

Page 17: Cobit 5 - An Overview

Applying a Single Integrated Framework

Page 18: Cobit 5 - An Overview

Enabling a Holistic Approach

Page 19: Cobit 5 - An Overview

Separating Management From Governance

Page 20: Cobit 5 - An Overview

ARE You

StartingTheory???

Page 21: Cobit 5 - An Overview

No ..

Page 22: Cobit 5 - An Overview

Not TheoryBut Yes

It is Conceptand the Learning Path Will be

Page 23: Cobit 5 - An Overview

COBIT 5 Principles

Meeting Stakeholders Needs

Goals Cascade

Covering Enterprise End to End

Governance Enablers

Governance Scope

Roles, Activities and Relationships

Applying a Single Integrated Framework

Framework Integrator

Enabling a Holistic Approach

Enablers

Interconnected Enablers

Enabler Dimensions

Enabler’s Performance Management

Separating Management From Governance

Governance & Management

COBIT 5 Process Reference Model

Page 24: Cobit 5 - An Overview

So…

We Have Challenges

1 • Meeting Stakeholders Needs

2 • Covering Enterprise End to End

3• Applying a Single

Integrated Framework

4 • Enabling a Holistic Approach

5• Separating

Management From Governance

Page 25: Cobit 5 - An Overview

Means, If We Understand the Principles

Then We’ll be Able to Understand COBIT

Page 26: Cobit 5 - An Overview

So, Lets Start the

Journey …

Page 27: Cobit 5 - An Overview

Principle 1 Meeting Stakeholder’s Need

Page 28: Cobit 5 - An Overview

Stakeholder’s Need - Fear of Unknown

• What stakeholder needs?• Governance Objectives?• Enterprise Goals?• IT Goals?• Can I relate these goals with Governance Objectives?• Relation Between Enterprise Goals and IT Goals• Relation Between IT Goals and Process (or any Enablers'

Goal)• Relation Between Stakeholders Needs and Enterprise

Goals

Page 29: Cobit 5 - An Overview

This is How COBIT 5 Helps in Resolving

the Fear of Unknown…

Page 30: Cobit 5 - An Overview

What stakeholder needs? COBIT 5 Provides Generic S/H Needs Statements e.g.

Page 31: Cobit 5 - An Overview

Governance Objectives?COBIT 5 Provides 3 Standard Governance Objectives

Page 32: Cobit 5 - An Overview

Enterprise Goals? COBIT 5 Provides 17 Generic Enterprise Goals and their

relationship with Governance Objectives

Page 33: Cobit 5 - An Overview

IT Goals? COBIT 5 Provides 17 Generic IT Goals

Page 34: Cobit 5 - An Overview

Relation Between Enterprise Goals and IT GoalsCOBIT 5 Provides Mapping of Enterprise and IT Goals

Page 35: Cobit 5 - An Overview

Hence with COBIT 5•We can write an statement of Stakeholder’s Need from a give list of generic Stakeholder's Goals

•These Statements can be mapped with Selected Enterprise Goals

•Enterprise Goals Can be than Mapped with Selected IT Goals

•Subsequently, Enabler Goals (e.g. Processes) can be derived from the Selected IT Goals

Page 36: Cobit 5 - An Overview

This will Result in

A well defined link between Stakeholder’s Need with Process (or Enabler’s Goals) and in term

provide an assurance of IT alignment with Stakeholder’s Needs.

Page 37: Cobit 5 - An Overview

COBIT 5 Principles

• Meeting Stakeholders Needs• Covering Enterprise End to End• Applying a Single Integrated Framework• Enabling a Holistic Approach• Separating Management From Governance

Page 38: Cobit 5 - An Overview

Covering Enterprise End to End Means…

Seamless Integration of Enterprise Governance

With Enterprise IT Governance

i.e. covering all internal and external IT Services & business processes of the Enterprise

Page 39: Cobit 5 - An Overview

Seamless Integration of Enterprise Governance

With Enterprise IT Governance

Means Managed flow of

Information

COBIT 5 Treats Information as One of the Enabler

Page 40: Cobit 5 - An Overview

Information – An Enabler

• The COBIT 5 Allows every stakeholder to define their requirement for information and the information processing life cycle.

• Hence, connecting business and its need for adequate information and IT function in term supporting the business and context focus.

Page 41: Cobit 5 - An Overview

The Approach of the Governance is

Page 42: Cobit 5 - An Overview

Along with Governance Objectives, the COBIT 5 Provides

• Frameworks

• Principles

• Structures

• Processes & practices

• Service Capabilities (IT Infrastructure, applications etc.)

• people and Information

Governance Scope

• Enterprise, an entity or an asset

Governance of Roles, Activities and Relationships

Page 43: Cobit 5 - An Overview

COBIT 5 Principles

• Meeting Stakeholders Needs• Covering Enterprise End to End• Applying a Single Integrated Framework• Enabling a Holistic Approach• Separating Management From Governance

Page 44: Cobit 5 - An Overview

Means What ?

Page 45: Cobit 5 - An Overview

There are Many Recommended Standards, Frameworks

and Best Practices

Available in the Market

Page 46: Cobit 5 - An Overview

COBIT 5Aligns with Latest Relevant Standards and Frameworks

and hence can be Used as

The Primary or Umbrella FrameworkFor

Integrating Various Governance and Management

Frameworks

Page 47: Cobit 5 - An Overview
Page 48: Cobit 5 - An Overview

COBIT 5 Principles

• Meeting Stakeholders Needs• Covering Enterprise End to End• Applying a Single Integrated Framework• Enabling a Holistic Approach• Separating Management From Governance

Page 49: Cobit 5 - An Overview

Enabling Holistic Approach MeansGovern and Manage IT

on Enterprise Level

While Considering

Full end-to-end Business and IT Functional Areas

+IT Related Interests of All Stakeholders

(Internal and External)

Page 50: Cobit 5 - An Overview

COBIT 5 Achieve it By Means of

Enterprise Wide

Enablers

Page 51: Cobit 5 - An Overview

Enablers are factors that, Individually and/or Collectively

influence whether

Something will work

In our case it is Governance and Management

of Enterprise IT

Page 52: Cobit 5 - An Overview

Enablers are Driven by the

Goals Cascade. Higher Level

IT related goals define

what the different enablers

should achieve.

* Appendix and Other references are provided here from COBIT 5 reference.

Page 53: Cobit 5 - An Overview

COBIT 5 Describes 7

Different Categories of

Enablers

Page 54: Cobit 5 - An Overview

An Enterprise Must Consider Interconnected Enablers

For AchievingSystematic

Governance and Management

Page 55: Cobit 5 - An Overview
Page 56: Cobit 5 - An Overview

An Enabler Needs the i/p from other enabler to be fully effective i.e. process need info,

organizational structure needs skill and behavior

An Enabler Delivers o/p for the benefit of other enabler i.e. process deliver info, skill and

behavior make process sufficient

Page 57: Cobit 5 - An Overview

So..• When dealing with governance and

management of enterprise IT, good decisions can be taken only when this systematic nature of governance and management is taken into account.

• It means to deal with any stakeholder’s need, all interrelated enablers have to be analyzed for relevance and addressed if required.

Page 58: Cobit 5 - An Overview

Challenges With the Enablers

Is there a Common, Simple and Structured

way to deal with enablers?

How to allow an entity to manage its complex

interactions?

How to Facilitate successful outcome of

the enablers?

Page 59: Cobit 5 - An Overview

For this, in COBIT

All Enablers share a set of

Common Dimensions

Page 60: Cobit 5 - An Overview

This Set of Common Dimensions

• Provides a common, simple and structured way to deal with enablers

• Allow an entity to manage its complex interactions

• Facilitate successful outcome of the enablers

Page 61: Cobit 5 - An Overview

Deals with Actual Outcome of the Indicator

Deals with Functioning of Enablers

Page 62: Cobit 5 - An Overview

Enabler Example

Principles, Policies and Frameworks

Page 63: Cobit 5 - An Overview
Page 64: Cobit 5 - An Overview

Enabler Example

Process

Page 65: Cobit 5 - An Overview
Page 66: Cobit 5 - An Overview

Example: Enabler –ProcessJust for Reference

Page 67: Cobit 5 - An Overview

COBIT 5 Principles

• Meeting Stakeholders Needs• Covering Enterprise End to End• Applying a Single Integrated Framework• Enabling a Holistic Approach• Separating Management From Governance

Page 68: Cobit 5 - An Overview

Governance and Management

Two Disciplines

Encompasses Different Types of Activities, Require Different Organizational Structures and

Serve Different Purposes.

Page 69: Cobit 5 - An Overview

COBIT 5 Makes Clear Distinction Between Governance and Management

Page 70: Cobit 5 - An Overview

Governance

• Ensures that Stakeholder’s needs, conditions and options are evaluated to determine balanced, agreed-on-enterprise objectives to be achieved

• Sets directions through prioritization and decision making

• And monitors performance and compliance against agreed on direction and objectives.

Page 71: Cobit 5 - An Overview

Management

Plans, builds, runs and monitor activities in alignment with the direction set by the governance body to achieve enterprise

objectives

Page 72: Cobit 5 - An Overview

COBIT 5 Recommends that an Enterprise must Implement

Governance and Management Processes

Such that

all the Key Areas are Covered

Page 73: Cobit 5 - An Overview

Key Areas of Governance and Management

Page 74: Cobit 5 - An Overview

COBIT Provides

Process Reference ModelTo

Clearly Identify and Segregate Key Areas

in these Domains

Page 75: Cobit 5 - An Overview

COBIT 5 Process Reference Model

Page 76: Cobit 5 - An Overview

Defines and Describes (in detail)a Number of

Governance and Management Processes

Represents all of the Processes Normally found in an Enterprise Relating to IT Activities

Page 77: Cobit 5 - An Overview

• Provides a common reference model understandable to operational IT and business managers.

• A complete, comprehensive model, but it is not the only possible process model

• Allows an enterprise to define its own process set based on its structure and work culture

Process Reference Model Also

Page 78: Cobit 5 - An Overview

?Advantages of the Process Model

Page 79: Cobit 5 - An Overview

Incorporating an operational model and a common language for all parts of the

enterprise involved in IT activities is one of the most important and critical steps towards good

governance

Page 80: Cobit 5 - An Overview

The Process Model Framework

• Can be a critical tool in measuring and monitoring IT performance and Providing IT assurance

• Can help in establishing effective Communication with service providers and

• Helps in Integrating best management practices.

Page 81: Cobit 5 - An Overview

The Process Reference Model Divides the

Governance and Management Processes of Enterprise IT into

2 Main

Process Domains

Page 82: Cobit 5 - An Overview

Governance Domain

Contains Five Governance Processes

Within each process Evaluate, Direct and Monitor (EDM)

Practices are defined

Page 83: Cobit 5 - An Overview

Management Domain

Contains four domainsThese domains are in line with the

responsibility areas of Plan, Build, Run and Monitor (PBRM)

and Hence provides end-to-end coverage of IT.

Page 84: Cobit 5 - An Overview

The names of the domains are chosen in line with these main area designations, but contain more verbs to describe them:

– Align, Plan and Organise (APO)– Build, Acquire and Implement (BAI)– Deliver, Service and Support (DSS)– Monitor, Evaluate and Assess (MEA)

Page 85: Cobit 5 - An Overview

• Each domain contain number of processes

• Most of these processes require planning, Implementation, execution and monitoring activities

Page 86: Cobit 5 - An Overview

In total COBIT 5 Provide

a set of

37 Governance and Management

Processes

Page 87: Cobit 5 - An Overview
Page 88: Cobit 5 - An Overview

The details of all processes, according to the process model are included in “COBIT 5: Enabling Processes”

Page 89: Cobit 5 - An Overview

Thanks You may reach me at

[email protected]