SlideShare ist ein Scribd-Unternehmen logo
1 von 21
How to? Combining SCRUM with
Corporate Compliance (COBIT AI.6)
Intro
Is there a way to combine
agile and flexible product
development aproach &
requirements of Corporate
Governance?
SCRUM – rules and agreements
 Iterations
 Each sprint delivers „closed”, working functionality
 Flexible, allows frequent change of direction
 Responsibility for the product delivery and quality
 Accordingly to Product/Story Owner requirements
COBIT – Change Control (AI6)
Characteristics of SCRUM & COBIT
SCRUM
• Rapid (Agile), and
iterationary delivery of
products
• Moderate to high
changeability
• Flexible approach
• No guarantee (high apetite
for risk)
COBIT
• Stabilization (through using
controls)
• Preffered low changeability
• „Strict” requirements
• Required guarantee (low
apetite for risk)
So we’re done… You cannot
provide high changeability of
product and provide
stabilization at the time.
Really? What if we look at
rules and agreement in
SCRUM?
Problem Statement
How to, using SCRUM mechanisms,
deliver proof of following COBIT
controls???
Roles in SCRUM
SCRUM
Master
Product
Owner
Developer
 Product Backlog
 Authorization for DoD
 Authorization for
sprints
 Validation of DoD i
sprints’ products
 Coordination
 SCRUM
„compliance”
 „Accountancy” of
sprints/team
 Estimation
 Production
 QA
 Deployment
Roles in SCRUM (2)
SCRUM
Master
Product
Owner
Developer Developer Developer
QA
QA
QA
Definition
Control
Validation
ACTIVITY
Develop and implement the process
to consistently record, assess, and
prioritise change requests.
Assess impact and prioritise changes
based on business needs 
Assure that any emergency and
critical change follows the approved
process
Authorise changes
Manage and disseminate relevant
information regarding changes.
SCRUM tasks’ types & Products distribution
EPIC
STORY
STORY
BUGBUGBUG
 Bug ->Sprints’
technological debt ->
Emergency Change
 Epic<>Story – ability
to use SoD (e.g.
Test/Prod deployment
done in diff. Stories of
the same Epic
 Sprint & Product
backlog Mgmt -
prioritization
SCRUM tasks’ types & Products distribution (2)
Backlog of Sprint 1
 Task 1
 Task 2
 Task 3
 Task 4
Backlog of Sprint 2
 Task 5
 Task 6
 Task 7
 Task 8
OK, what about
Authorization? We spoke
about it yet…
ACTIVITY OK?
Develop and implement the process to
consistently record, assess, and
prioritise change requests.
Assess impact and prioritise changes
based on business needs 
Assure that any emergency and critical
change follows the approved process 
Authorise changes
Manage and disseminate relevant
information regarding changes.
Authorization of changes
 Product Backlog
 Authorization for DoD
 Authorization for
sprints
 Validation of DoD i
sprints’ products
Product
Owner
Product Owner is responsible for
authorization. This role manages both
authorization and prioritization of
tasks/products. If there is more
stakeholders – PO is responsible for gaining
decisions and final authorization.
ACTIVITY OK?
Develop and implement the process to
consistently record, assess, and
prioritise change requests.
Assess impact and prioritise changes
based on business needs 
Assure that any emergency and critical
change follows the approved process 
Authorise changes

Manage and disseminate relevant
information regarding changes.
OK, We got 3 of 5 controls
checked. 2 remaining?
Lets see…
Information about Changes
We need some assumptions for
our SCRUM „agreement”:
1. SCRUM is transparent – we
do not hide product nor
information
2. SCRUM has wing-2-wing
responsibility for products
3. Product Owner is acting as
Customer/users
representative.
Makes sense…
Information about Changes (2)
Product
Owner
Product Owner is responsible for
communication. Depending on product,
actual comm actions may differ. They will
cover checks from public access to backlog
through sprints scope access up to specific
channels related to particular deploys.
Users, Customer, Other POs, Teams, etc.
ACTIVITY OK?
Develop and implement the process to consistently record, assess, and prioritise
change requests.
Assess impact and prioritise changes based on business needs 
Assure that any emergency and critical change follows the approved process 
Authorise changes 
Manage and disseminate relevant information regarding changes. 
What about prioritization of
CRs…
It’s the simplest thing:
1. User Story
2. Product Backlog
3. Sprint Backlog
4. PO’s decision
Problem Solved!
ACTIVITY OK?
Develop and implement the process to consistently record, assess, and
prioritise change requests.

Assess impact and prioritise changes based on business needs 
Assure that any emergency and critical change follows the approved
process

Authorise changes 
Manage and disseminate relevant information regarding changes. 
Is that all?
Of course we have not shown everything.
Apart from CC (AI 6) there is in COBIT
many areas around changes. However
„mind/toolset” is similar. It requires basic
knowledge:
a) Acknowledgement that SCRUM is based
on Human-2-Human interactions
b) Acknowledgement that meeting the
controls don’t have to be machine
interface one. Control Models require
validation/documentation.
What else?
PCI
(VISA)
Similar approach
a bit different SoD
and some details
ISO20000Similar approach ITIL ChM
Other
models
I duknow…
Dont be afrais of
asking! 
CMMi
100% compatibility
(with given
requirements)
100% compatibility
(with given
requirements)
???
…
Discussion?
Thanks!
Przemek Wysota
ITSM/IT Management Expert
Contact
Mail: przemek.wysota@outlook.com
Tweet: @pwysota
LinkedIn: https://pl.linkedin.com/in/przemekwysota

Weitere ähnliche Inhalte

Was ist angesagt?

Major themes in change management
Major themes in change management Major themes in change management
Major themes in change management Maven
 
ADKAR Change Management Model
ADKAR   Change Management ModelADKAR   Change Management Model
ADKAR Change Management ModelSyed Arh
 
Change management models - ADKAR, Satir, 8 step, Switch and Lewin models
Change management models - ADKAR, Satir, 8 step, Switch and Lewin modelsChange management models - ADKAR, Satir, 8 step, Switch and Lewin models
Change management models - ADKAR, Satir, 8 step, Switch and Lewin modelsSrinath Ramakrishnan
 
An Insider's Guide to Building a Successful Consulting Practice
An Insider's Guide to Building a Successful Consulting PracticeAn Insider's Guide to Building a Successful Consulting Practice
An Insider's Guide to Building a Successful Consulting PracticeBusiness Book Summaries
 
Introduction to change management
Introduction to change managementIntroduction to change management
Introduction to change managementKapil Kant Kaul
 
Change Management Fundamentals PowerPoint Presentation Slides
Change Management Fundamentals PowerPoint Presentation SlidesChange Management Fundamentals PowerPoint Presentation Slides
Change Management Fundamentals PowerPoint Presentation SlidesSlideTeam
 
Accenture Learning Academy
Accenture Learning AcademyAccenture Learning Academy
Accenture Learning Academyaccenture
 
8 step change management
8 step change management8 step change management
8 step change managementApty123
 
How To Implement Change
How To Implement ChangeHow To Implement Change
How To Implement ChangeSteve Wise
 
Operational Excellence Models, Strategies, Principles & Tools
Operational Excellence Models, Strategies, Principles & ToolsOperational Excellence Models, Strategies, Principles & Tools
Operational Excellence Models, Strategies, Principles & ToolsAurelien Domont, MBA
 
Change management
Change management Change management
Change management Abhi Bhatt
 
Change Management - How to manage change in your organization successfully. A...
Change Management - How to manage change in your organization successfully. A...Change Management - How to manage change in your organization successfully. A...
Change Management - How to manage change in your organization successfully. A...HRM Toolshop
 
The Process of Change / Transformation
The Process of Change / TransformationThe Process of Change / Transformation
The Process of Change / TransformationSubbuiyer
 
Change Management Consulting Case Study
Change Management Consulting   Case StudyChange Management Consulting   Case Study
Change Management Consulting Case StudyRyan Gunhold
 
Change management strategy_team_xyz
Change management strategy_team_xyzChange management strategy_team_xyz
Change management strategy_team_xyzBao Nguyen
 

Was ist angesagt? (20)

Major themes in change management
Major themes in change management Major themes in change management
Major themes in change management
 
Change Management Learning Module
Change Management Learning ModuleChange Management Learning Module
Change Management Learning Module
 
ADKAR Change Management Model
ADKAR   Change Management ModelADKAR   Change Management Model
ADKAR Change Management Model
 
Change management models - ADKAR, Satir, 8 step, Switch and Lewin models
Change management models - ADKAR, Satir, 8 step, Switch and Lewin modelsChange management models - ADKAR, Satir, 8 step, Switch and Lewin models
Change management models - ADKAR, Satir, 8 step, Switch and Lewin models
 
Strategic Agility
Strategic AgilityStrategic Agility
Strategic Agility
 
An Insider's Guide to Building a Successful Consulting Practice
An Insider's Guide to Building a Successful Consulting PracticeAn Insider's Guide to Building a Successful Consulting Practice
An Insider's Guide to Building a Successful Consulting Practice
 
Change management
Change managementChange management
Change management
 
Introduction to change management
Introduction to change managementIntroduction to change management
Introduction to change management
 
Change Management Fundamentals PowerPoint Presentation Slides
Change Management Fundamentals PowerPoint Presentation SlidesChange Management Fundamentals PowerPoint Presentation Slides
Change Management Fundamentals PowerPoint Presentation Slides
 
Accenture Learning Academy
Accenture Learning AcademyAccenture Learning Academy
Accenture Learning Academy
 
8 step change management
8 step change management8 step change management
8 step change management
 
How To Implement Change
How To Implement ChangeHow To Implement Change
How To Implement Change
 
Operational Excellence Models, Strategies, Principles & Tools
Operational Excellence Models, Strategies, Principles & ToolsOperational Excellence Models, Strategies, Principles & Tools
Operational Excellence Models, Strategies, Principles & Tools
 
Change Management
Change ManagementChange Management
Change Management
 
Change management
Change management Change management
Change management
 
Change Management - How to manage change in your organization successfully. A...
Change Management - How to manage change in your organization successfully. A...Change Management - How to manage change in your organization successfully. A...
Change Management - How to manage change in your organization successfully. A...
 
The Process of Change / Transformation
The Process of Change / TransformationThe Process of Change / Transformation
The Process of Change / Transformation
 
Change Management Consulting Case Study
Change Management Consulting   Case StudyChange Management Consulting   Case Study
Change Management Consulting Case Study
 
Change management strategy_team_xyz
Change management strategy_team_xyzChange management strategy_team_xyz
Change management strategy_team_xyz
 
Change management PMI
Change management PMIChange management PMI
Change management PMI
 

Andere mochten auch

Vendor management using COBIT 5
Vendor management using COBIT 5Vendor management using COBIT 5
Vendor management using COBIT 5Robert Stroud
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Meghna Verma
 
Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGoutama Bachtiar
 
Five Keys To Software Projects
Five Keys To Software ProjectsFive Keys To Software Projects
Five Keys To Software ProjectsLauri Jutila
 
Joburg cobit assurance
Joburg cobit assuranceJoburg cobit assurance
Joburg cobit assuranceAldee2013
 
Školení procesního řízení - základní úvod
Školení procesního řízení - základní úvodŠkolení procesního řízení - základní úvod
Školení procesního řízení - základní úvodPetr Snajdr
 
Scaling agile diy agile_fest2016
Scaling agile diy agile_fest2016Scaling agile diy agile_fest2016
Scaling agile diy agile_fest2016Ankit Tandon
 
ITIL versus COBIT - Um breve comparativo
ITIL versus COBIT - Um breve comparativoITIL versus COBIT - Um breve comparativo
ITIL versus COBIT - Um breve comparativomvitor
 
Cobit from Mars ITIL from Venus - alignment
Cobit from Mars ITIL from Venus - alignmentCobit from Mars ITIL from Venus - alignment
Cobit from Mars ITIL from Venus - alignmentKathryn Howard
 
MSP Best Practice | Using Strategic IT Roadmaps to Get More Contracts
MSP Best Practice | Using Strategic IT Roadmaps to Get More ContractsMSP Best Practice | Using Strategic IT Roadmaps to Get More Contracts
MSP Best Practice | Using Strategic IT Roadmaps to Get More ContractsDavid Castro
 
ITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der Frameworks
ITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der FrameworksITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der Frameworks
ITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der FrameworksDigicomp Academy AG
 
Scaling agile scrum practices 2.0
Scaling agile   scrum practices 2.0Scaling agile   scrum practices 2.0
Scaling agile scrum practices 2.0Reedy Feggins Jr
 
Cobit, itil and cmmi - a tutorial
Cobit, itil and cmmi  - a tutorialCobit, itil and cmmi  - a tutorial
Cobit, itil and cmmi - a tutorialseveman
 
Comparing Agile transformation approaches at Twitter and Salesforce
Comparing Agile transformation approaches at Twitter and SalesforceComparing Agile transformation approaches at Twitter and Salesforce
Comparing Agile transformation approaches at Twitter and SalesforceSteve Greene
 
An Agile Practice Framework for Scaling Agile Adoption in an Enterprise
An Agile Practice Framework for Scaling Agile Adoption in an EnterpriseAn Agile Practice Framework for Scaling Agile Adoption in an Enterprise
An Agile Practice Framework for Scaling Agile Adoption in an EnterpriseBrad Appleton
 
ADD: New itil implementation approach
ADD: New itil implementation approachADD: New itil implementation approach
ADD: New itil implementation approachMohamed Zohair
 
EN 6.3: 2 IT-Compliance und IT-Sicherheitsmanagement
EN 6.3: 2 IT-Compliance und IT-SicherheitsmanagementEN 6.3: 2 IT-Compliance und IT-Sicherheitsmanagement
EN 6.3: 2 IT-Compliance und IT-SicherheitsmanagementSven Wohlgemuth
 

Andere mochten auch (20)

Vendor management using COBIT 5
Vendor management using COBIT 5Vendor management using COBIT 5
Vendor management using COBIT 5
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799
 
Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 Framework
 
CobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast SeminarCobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast Seminar
 
Five Keys To Software Projects
Five Keys To Software ProjectsFive Keys To Software Projects
Five Keys To Software Projects
 
Joburg cobit assurance
Joburg cobit assuranceJoburg cobit assurance
Joburg cobit assurance
 
Školení procesního řízení - základní úvod
Školení procesního řízení - základní úvodŠkolení procesního řízení - základní úvod
Školení procesního řízení - základní úvod
 
Scaling agile diy agile_fest2016
Scaling agile diy agile_fest2016Scaling agile diy agile_fest2016
Scaling agile diy agile_fest2016
 
ITIL versus COBIT - Um breve comparativo
ITIL versus COBIT - Um breve comparativoITIL versus COBIT - Um breve comparativo
ITIL versus COBIT - Um breve comparativo
 
Cobit from Mars ITIL from Venus - alignment
Cobit from Mars ITIL from Venus - alignmentCobit from Mars ITIL from Venus - alignment
Cobit from Mars ITIL from Venus - alignment
 
MSP Best Practice | Using Strategic IT Roadmaps to Get More Contracts
MSP Best Practice | Using Strategic IT Roadmaps to Get More ContractsMSP Best Practice | Using Strategic IT Roadmaps to Get More Contracts
MSP Best Practice | Using Strategic IT Roadmaps to Get More Contracts
 
ITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der Frameworks
ITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der FrameworksITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der Frameworks
ITIL® – COBIT® Mapping Gemeinsamkeiten und Unterschiede der Frameworks
 
Scaling agile scrum practices 2.0
Scaling agile   scrum practices 2.0Scaling agile   scrum practices 2.0
Scaling agile scrum practices 2.0
 
Cobi T Para Que Sirve
Cobi T Para Que SirveCobi T Para Que Sirve
Cobi T Para Que Sirve
 
Cobit, itil and cmmi - a tutorial
Cobit, itil and cmmi  - a tutorialCobit, itil and cmmi  - a tutorial
Cobit, itil and cmmi - a tutorial
 
Scaling agile with sa fe v1.0
Scaling agile with sa fe v1.0Scaling agile with sa fe v1.0
Scaling agile with sa fe v1.0
 
Comparing Agile transformation approaches at Twitter and Salesforce
Comparing Agile transformation approaches at Twitter and SalesforceComparing Agile transformation approaches at Twitter and Salesforce
Comparing Agile transformation approaches at Twitter and Salesforce
 
An Agile Practice Framework for Scaling Agile Adoption in an Enterprise
An Agile Practice Framework for Scaling Agile Adoption in an EnterpriseAn Agile Practice Framework for Scaling Agile Adoption in an Enterprise
An Agile Practice Framework for Scaling Agile Adoption in an Enterprise
 
ADD: New itil implementation approach
ADD: New itil implementation approachADD: New itil implementation approach
ADD: New itil implementation approach
 
EN 6.3: 2 IT-Compliance und IT-Sicherheitsmanagement
EN 6.3: 2 IT-Compliance und IT-SicherheitsmanagementEN 6.3: 2 IT-Compliance und IT-Sicherheitsmanagement
EN 6.3: 2 IT-Compliance und IT-Sicherheitsmanagement
 

Ähnlich wie Agility under Control - SCRUM vs COBIT

Introduction to Agile change agent
Introduction to Agile change agentIntroduction to Agile change agent
Introduction to Agile change agentTraining Bytesize
 
Innovative Engineering Workshop Npi 30march10
Innovative Engineering Workshop   Npi   30march10Innovative Engineering Workshop   Npi   30march10
Innovative Engineering Workshop Npi 30march10mccall1966
 
Optimize your Change Management Process
Optimize your Change Management ProcessOptimize your Change Management Process
Optimize your Change Management ProcessJason Goncalves
 
Presentation by meghna jadhav
Presentation by meghna jadhavPresentation by meghna jadhav
Presentation by meghna jadhavPMI_IREP_TP
 
P2 how to develop an it change management program
P2 how to develop an it change management programP2 how to develop an it change management program
P2 how to develop an it change management programIT-Toolkits.org
 
Configuration Management
Configuration ManagementConfiguration Management
Configuration Managementelliando dias
 
CaseStudy_MOC_PX_2015_LI
CaseStudy_MOC_PX_2015_LICaseStudy_MOC_PX_2015_LI
CaseStudy_MOC_PX_2015_LISean Cull
 
Change Management Options
Change Management Options Change Management Options
Change Management Options Aras
 
Agile transformation approach by first consulting
Agile transformation approach by first consultingAgile transformation approach by first consulting
Agile transformation approach by first consultingRoel van Overdam
 
Agile transformation approach by First Consulting
Agile transformation approach by First ConsultingAgile transformation approach by First Consulting
Agile transformation approach by First ConsultingRoel van Overdam
 
Operational Decisions Management 101
Operational Decisions Management 101Operational Decisions Management 101
Operational Decisions Management 101Alain Neyroud
 
The great divide v2.0
The great divide v2.0The great divide v2.0
The great divide v2.0mharbolt
 
Agile vs waterfall
Agile vs waterfallAgile vs waterfall
Agile vs waterfallgosain20
 
293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...
293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...
293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...kndnewguade
 
Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)
Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)
Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)Samuel Chin, PMP, CSM
 
The Business value of agile development
The Business value of agile developmentThe Business value of agile development
The Business value of agile developmentPhavadol Srisarnsakul
 

Ähnlich wie Agility under Control - SCRUM vs COBIT (20)

Software Configuration Management
Software Configuration ManagementSoftware Configuration Management
Software Configuration Management
 
Introduction to Agile change agent
Introduction to Agile change agentIntroduction to Agile change agent
Introduction to Agile change agent
 
Innovative Engineering Workshop Npi 30march10
Innovative Engineering Workshop   Npi   30march10Innovative Engineering Workshop   Npi   30march10
Innovative Engineering Workshop Npi 30march10
 
Optimize your Change Management Process
Optimize your Change Management ProcessOptimize your Change Management Process
Optimize your Change Management Process
 
Presentation by meghna jadhav
Presentation by meghna jadhavPresentation by meghna jadhav
Presentation by meghna jadhav
 
P2 how to develop an it change management program
P2 how to develop an it change management programP2 how to develop an it change management program
P2 how to develop an it change management program
 
Configuration Management
Configuration ManagementConfiguration Management
Configuration Management
 
CaseStudy_MOC_PX_2015_LI
CaseStudy_MOC_PX_2015_LICaseStudy_MOC_PX_2015_LI
CaseStudy_MOC_PX_2015_LI
 
Change Management Options
Change Management Options Change Management Options
Change Management Options
 
Agile Development Process
Agile Development ProcessAgile Development Process
Agile Development Process
 
Agile transformation approach by first consulting
Agile transformation approach by first consultingAgile transformation approach by first consulting
Agile transformation approach by first consulting
 
Agile transformation approach by First Consulting
Agile transformation approach by First ConsultingAgile transformation approach by First Consulting
Agile transformation approach by First Consulting
 
Operational Decisions Management 101
Operational Decisions Management 101Operational Decisions Management 101
Operational Decisions Management 101
 
Sdlc plan
Sdlc planSdlc plan
Sdlc plan
 
Product management
Product managementProduct management
Product management
 
The great divide v2.0
The great divide v2.0The great divide v2.0
The great divide v2.0
 
Agile vs waterfall
Agile vs waterfallAgile vs waterfall
Agile vs waterfall
 
293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...
293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...
293504541-ict-its4-03-0811-assist-with-policy-development-for-client-support-...
 
Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)
Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)
Products and Value: An Agile Perspective BY Matt Nudelmann (GUEST PRESENTER)
 
The Business value of agile development
The Business value of agile developmentThe Business value of agile development
The Business value of agile development
 

Kürzlich hochgeladen

Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar TrainingKylaCullinane
 
Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)Chameera Dedduwage
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lodhisaajjda
 
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, YardstickSaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, Yardsticksaastr
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Baileyhlharris
 
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesVVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesPooja Nehwal
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIINhPhngng3
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfSkillCertProExams
 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfSenaatti-kiinteistöt
 
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Delhi Call girls
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaKayode Fayemi
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoKayode Fayemi
 
Air breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsAir breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsaqsarehman5055
 
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Hasting Chen
 
Presentation on Engagement in Book Clubs
Presentation on Engagement in Book ClubsPresentation on Engagement in Book Clubs
Presentation on Engagement in Book Clubssamaasim06
 
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCamilleBoulbin1
 
Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Vipesco
 

Kürzlich hochgeladen (20)

Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar Training
 
Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
 
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
 
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, YardstickSaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
 
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara ServicesVVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
VVIP Call Girls Nalasopara : 9892124323, Call Girls in Nalasopara Services
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
 
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 
Air breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsAir breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animals
 
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
Re-membering the Bard: Revisiting The Compleat Wrks of Wllm Shkspr (Abridged)...
 
Presentation on Engagement in Book Clubs
Presentation on Engagement in Book ClubsPresentation on Engagement in Book Clubs
Presentation on Engagement in Book Clubs
 
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptx
 
Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510
 

Agility under Control - SCRUM vs COBIT

  • 1. How to? Combining SCRUM with Corporate Compliance (COBIT AI.6)
  • 2. Intro Is there a way to combine agile and flexible product development aproach & requirements of Corporate Governance?
  • 3. SCRUM – rules and agreements  Iterations  Each sprint delivers „closed”, working functionality  Flexible, allows frequent change of direction  Responsibility for the product delivery and quality  Accordingly to Product/Story Owner requirements
  • 4. COBIT – Change Control (AI6)
  • 5. Characteristics of SCRUM & COBIT SCRUM • Rapid (Agile), and iterationary delivery of products • Moderate to high changeability • Flexible approach • No guarantee (high apetite for risk) COBIT • Stabilization (through using controls) • Preffered low changeability • „Strict” requirements • Required guarantee (low apetite for risk)
  • 6. So we’re done… You cannot provide high changeability of product and provide stabilization at the time. Really? What if we look at rules and agreement in SCRUM?
  • 7. Problem Statement How to, using SCRUM mechanisms, deliver proof of following COBIT controls???
  • 8. Roles in SCRUM SCRUM Master Product Owner Developer  Product Backlog  Authorization for DoD  Authorization for sprints  Validation of DoD i sprints’ products  Coordination  SCRUM „compliance”  „Accountancy” of sprints/team  Estimation  Production  QA  Deployment
  • 9. Roles in SCRUM (2) SCRUM Master Product Owner Developer Developer Developer QA QA QA Definition Control Validation ACTIVITY Develop and implement the process to consistently record, assess, and prioritise change requests. Assess impact and prioritise changes based on business needs  Assure that any emergency and critical change follows the approved process Authorise changes Manage and disseminate relevant information regarding changes.
  • 10. SCRUM tasks’ types & Products distribution EPIC STORY STORY BUGBUGBUG  Bug ->Sprints’ technological debt -> Emergency Change  Epic<>Story – ability to use SoD (e.g. Test/Prod deployment done in diff. Stories of the same Epic  Sprint & Product backlog Mgmt - prioritization
  • 11. SCRUM tasks’ types & Products distribution (2) Backlog of Sprint 1  Task 1  Task 2  Task 3  Task 4 Backlog of Sprint 2  Task 5  Task 6  Task 7  Task 8 OK, what about Authorization? We spoke about it yet… ACTIVITY OK? Develop and implement the process to consistently record, assess, and prioritise change requests. Assess impact and prioritise changes based on business needs  Assure that any emergency and critical change follows the approved process  Authorise changes Manage and disseminate relevant information regarding changes.
  • 12. Authorization of changes  Product Backlog  Authorization for DoD  Authorization for sprints  Validation of DoD i sprints’ products Product Owner Product Owner is responsible for authorization. This role manages both authorization and prioritization of tasks/products. If there is more stakeholders – PO is responsible for gaining decisions and final authorization. ACTIVITY OK? Develop and implement the process to consistently record, assess, and prioritise change requests. Assess impact and prioritise changes based on business needs  Assure that any emergency and critical change follows the approved process  Authorise changes  Manage and disseminate relevant information regarding changes.
  • 13. OK, We got 3 of 5 controls checked. 2 remaining? Lets see…
  • 14. Information about Changes We need some assumptions for our SCRUM „agreement”: 1. SCRUM is transparent – we do not hide product nor information 2. SCRUM has wing-2-wing responsibility for products 3. Product Owner is acting as Customer/users representative. Makes sense…
  • 15. Information about Changes (2) Product Owner Product Owner is responsible for communication. Depending on product, actual comm actions may differ. They will cover checks from public access to backlog through sprints scope access up to specific channels related to particular deploys. Users, Customer, Other POs, Teams, etc. ACTIVITY OK? Develop and implement the process to consistently record, assess, and prioritise change requests. Assess impact and prioritise changes based on business needs  Assure that any emergency and critical change follows the approved process  Authorise changes  Manage and disseminate relevant information regarding changes. 
  • 16. What about prioritization of CRs… It’s the simplest thing: 1. User Story 2. Product Backlog 3. Sprint Backlog 4. PO’s decision
  • 17. Problem Solved! ACTIVITY OK? Develop and implement the process to consistently record, assess, and prioritise change requests.  Assess impact and prioritise changes based on business needs  Assure that any emergency and critical change follows the approved process  Authorise changes  Manage and disseminate relevant information regarding changes. 
  • 18. Is that all? Of course we have not shown everything. Apart from CC (AI 6) there is in COBIT many areas around changes. However „mind/toolset” is similar. It requires basic knowledge: a) Acknowledgement that SCRUM is based on Human-2-Human interactions b) Acknowledgement that meeting the controls don’t have to be machine interface one. Control Models require validation/documentation.
  • 19. What else? PCI (VISA) Similar approach a bit different SoD and some details ISO20000Similar approach ITIL ChM Other models I duknow… Dont be afrais of asking!  CMMi 100% compatibility (with given requirements) 100% compatibility (with given requirements)
  • 21. Thanks! Przemek Wysota ITSM/IT Management Expert Contact Mail: przemek.wysota@outlook.com Tweet: @pwysota LinkedIn: https://pl.linkedin.com/in/przemekwysota