SlideShare ist ein Scribd-Unternehmen logo
1 von 27
Introduction-BenefitsIntroduction-Benefits
COBIT FrameworkCOBIT Framework
With ExampleWith Example
Sanjiv Arora, CISA, CISM, CGEIT
Principal Consultant
TECHNOLOGICS
& CONTROLS
Protecting the ABCs of your business.
AgendaAgenda
 IT Governance
 COBIT framework
 Example - Cost Management Controls in IT Operations using
COBIT
 About Technologics and Controls
IT Governance – Need?IT Governance – Need?
What is driving today’s businesses?
Assertive Stakeholders
Aggressive Competition
Emerging Regulations
Recessionary trends direct / indirect
Extremely high IT Dependence
Impacts
Enterprise GovernanceEnterprise Governance
IT Governance - AlignmentIT Governance - Alignment
Value Delivery
•Secure
•On Time
•Within Budgets
•Good Quality
•Reduce Expense
•Proven best
practices
Business Benefits
•Customer satisfaction
•Brand Loyalty
•Competitive advantage
•Profitability
Crux - Fill what's empty. Empty what's full. And scratch where
it itches. – Murphy’s law
Why COBIT?Why COBIT?
 Better alignment based on business focus
 Demonstrates management viewpoint and expectations
 Clear ownerships and responsibilities based on
processes
 Increasing acceptability with third parties and regulators
 Eases IT Governance communication between
stakeholders and other parties
 Fulfillment of the COSO requirements for IT control
environment
Lack of IT Governance makes it....Lack of IT Governance makes it....
 Difficult to make a link to the business requirements
 Complex to measure performance against the
requirements
 Cumbersome to control activities using a generally
accepted process model
 Difficult to identify the resources to be leveraged
 A problem to define management control objectives
Use of COBIT – Practical ScenarioUse of COBIT – Practical Scenario
 Uses are
 Implement and Manage IT governance
 Risk Assessment and Management
 Defining KPI and KGI
 Mapping to other standards
 Customize controls
 Provides direction and recommendations for weak
controls
 Aid to implement ERP, BCP, BPR and other IT
projects
 Implement Cost Savings on IT spend (Capex and
Opex)
 Assessment of IT governance maturity
 Demonstrate IT alignment (using Balance Score card)
COBIT – It is ImplementableCOBIT – It is Implementable

Based on self assessment

Very comprehensive yet flexible

Does not enforce COMPLETE implementation

Customizable

Easy to understand (Subject Matter Experts are
available)

Implementation maybe fast track, with help of tools
COBIT – Importance Vs Other standardsCOBIT – Importance Vs Other standards
 Comprehensive for business requirements
 Business operations completely dependent on IT
 Business applications (ERP), workflows, resource sharing,
communication (chat, email,video conferencing) controls are all
logical controls
 Approval and authorization – financial or non-financial is mostly
handled by logical controls
 Confidentiality is primarily managed within technology
 COBIT encompasses all aspects of IT Governance
 Other standards where COBIT is useful
 ITIL
 SOX compliance
 PCI-DSS
 NIST
 HIPAA
 ISO27001
 Others
COBITCOBIT – Other Standards– Other Standards
http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=31702
Common misunderstanding: We already have xyz standard, so we do
not need COBIT.
COBIT FrameworkCOBIT Framework
Source – ITGI presentation materials
The following slides explain an example
of COBIT framework implementation.
The slides are prepared using the Meycor COBIT suite software tools.
Actual tool may also be demonstrated as necessary,
time and audience permitting.
Thanks.
COBIT FrameworkCOBIT Framework
COBIT – Key Objectives and ControlsCOBIT – Key Objectives and Controls
COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach
4 Domains
34 Processes
(select applicable processes)
210 Control Objectives
(select from applicable objectives)
Controls
(Select / add / modify controls to
Suit your IT Governance needs)
* Equals =
4 Domains
22 processes
145 controls objectives
N Controls
* An example
COBIT – Processes and Controls – Tangible Cost ManagementCOBIT – Processes and Controls – Tangible Cost Management
Source - http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=47399
Cost Management Controls = Selected 10 processes
COBIT – Processes and Controls – Excess Labour ManagementCOBIT – Processes and Controls – Excess Labour Management
Too many cooks….!
COBIT – Assessment and gaps – Tangible Cost ManagementCOBIT – Assessment and gaps – Tangible Cost Management
COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving
Cont’d
COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving
COBIT – Tangible Cost Management – Recommendation – DS2COBIT – Tangible Cost Management – Recommendation – DS2
Customize recommendations
according to business objectives.
COBIT – Tangible Cost Management–Tasks/linked RecommendationCOBIT – Tangible Cost Management–Tasks/linked Recommendation
COBIT – Tangible Cost Management–Tasks Manage / ComplyCOBIT – Tangible Cost Management–Tasks Manage / Comply
Verify and validate to ensure
compliance and success.
COBIT – Tangible Cost Management– Communicate ResultsCOBIT – Tangible Cost Management– Communicate Results
 Proactive IT initiatives and operational improvements
 Enhance credibility of the IT organization
 Benefits
 Tangibles
 Current period vs previous period
 % saving from alternate options
 Forecast reduction in expense / ROI
 Intangibles
 Efficiency of operations
 Reduced incidents
 High uptime
 Link to business objectives
 Faster product launch
 Timely service delivery
 Increase in customers / revenue
COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach
4 Domains
34 Processes
(select applicable processes)
210 Control Objectives
(select from applicable objectives)
Controls
(Select / add / modify controls to
Suit your IT Governance needs)
* Equals =
4 Domains
22 processes
145 controls objectives
N Controls
* An example
The funnel model can be used for
implementation of ERP, Other IT Projects,
Project Monitoring and controls,
Compliance checklists
Introduction : Technologics & ControlsIntroduction : Technologics & Controls
 Founded in 2001
 Based in New Delhi, India
 Services: IT Audits, Risk Management consulting, Information
security assessment and management, IT Governance services,
compliance and related services.
 Products: Sole reseller in India of DataSec S.R.L providing software
solutions based on COBIT / ISO27001 / COSO and other standards
COBIT – BenefitsCOBIT – Benefits
We offer our rich experience to meet your Business Requirements and Objectives in the IT
Audits, IT Governance, Risk, Security Awareness, CISA, CISM Training and IT Strategy
consulting areas.
Our specializations includes reviews of ERP, CBS, Information Architecture, IT Efficiency
and Effectiveness to deliver value amongst other things.
We have worked with Al Rajhi Takaful in KSA, Qatar Steel, WFP, WHO, UNOPS, Govt of
India and many other reputed companies across the world.
We shall be happy to discuss your requirements,
Look forward.
Sanjiv Arora
Contact us on +91 98102 93733 or email sa@tech-controls.com
www.tech-controls.com

Weitere ähnliche Inhalte

Was ist angesagt?

A Practical Example to Using SABSA Extended Security-in-Depth Strategy
A Practical Example to Using SABSA Extended Security-in-Depth Strategy A Practical Example to Using SABSA Extended Security-in-Depth Strategy
A Practical Example to Using SABSA Extended Security-in-Depth Strategy Allen Baranov
 
SABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 contextSABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 contextDavid Sweigert
 
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...Edureka!
 
NQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA
 
ITIL,COBIT and IT4IT Mapping
ITIL,COBIT and IT4IT MappingITIL,COBIT and IT4IT Mapping
ITIL,COBIT and IT4IT MappingRob Akershoek
 
SOC Certification Runbook Template
SOC Certification Runbook TemplateSOC Certification Runbook Template
SOC Certification Runbook TemplateMark S. Mahre
 
IT Operating Model - Fundamental
IT Operating Model - FundamentalIT Operating Model - Fundamental
IT Operating Model - FundamentalEryk Budi Pratama
 
Extended Detection and Response (XDR) An Overhyped Product Category With Ulti...
Extended Detection and Response (XDR)An Overhyped Product Category With Ulti...Extended Detection and Response (XDR)An Overhyped Product Category With Ulti...
Extended Detection and Response (XDR) An Overhyped Product Category With Ulti...Raffael Marty
 
IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 Rob Akershoek
 
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORKZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORKMaganathin Veeraragaloo
 
Security operation center (SOC)
Security operation center (SOC)Security operation center (SOC)
Security operation center (SOC)Ahmed Ayman
 
Information Security Governance and Strategy
Information Security Governance and Strategy Information Security Governance and Strategy
Information Security Governance and Strategy Dam Frank
 
Addressing the cyber kill chain
Addressing the cyber kill chainAddressing the cyber kill chain
Addressing the cyber kill chainSymantec Brasil
 
Zero Trust Network Access
Zero Trust Network Access Zero Trust Network Access
Zero Trust Network Access Er. Ajay Sirsat
 
Iso 27001 foundation sample slides
Iso 27001 foundation sample slidesIso 27001 foundation sample slides
Iso 27001 foundation sample slidesStratos Lazaridis
 
Cloud Security using NIST guidelines
Cloud Security using NIST guidelinesCloud Security using NIST guidelines
Cloud Security using NIST guidelinesSrishti Ahuja
 
Cyber Security roadmap.pptx
Cyber Security roadmap.pptxCyber Security roadmap.pptx
Cyber Security roadmap.pptxSandeepK707540
 
Building a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS EnvironmentsBuilding a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS EnvironmentsShah Sheikh
 

Was ist angesagt? (20)

A Practical Example to Using SABSA Extended Security-in-Depth Strategy
A Practical Example to Using SABSA Extended Security-in-Depth Strategy A Practical Example to Using SABSA Extended Security-in-Depth Strategy
A Practical Example to Using SABSA Extended Security-in-Depth Strategy
 
SABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 contextSABSA vs. TOGAF in a RMF NIST 800-30 context
SABSA vs. TOGAF in a RMF NIST 800-30 context
 
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
 
Iso 27001 2013
Iso 27001 2013Iso 27001 2013
Iso 27001 2013
 
NQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation Guide
 
ITIL,COBIT and IT4IT Mapping
ITIL,COBIT and IT4IT MappingITIL,COBIT and IT4IT Mapping
ITIL,COBIT and IT4IT Mapping
 
SOC Certification Runbook Template
SOC Certification Runbook TemplateSOC Certification Runbook Template
SOC Certification Runbook Template
 
IT Operating Model - Fundamental
IT Operating Model - FundamentalIT Operating Model - Fundamental
IT Operating Model - Fundamental
 
Extended Detection and Response (XDR) An Overhyped Product Category With Ulti...
Extended Detection and Response (XDR)An Overhyped Product Category With Ulti...Extended Detection and Response (XDR)An Overhyped Product Category With Ulti...
Extended Detection and Response (XDR) An Overhyped Product Category With Ulti...
 
IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022
 
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORKZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
ZERO TRUST ARCHITECTURE - DIGITAL TRUST FRAMEWORK
 
Security operation center (SOC)
Security operation center (SOC)Security operation center (SOC)
Security operation center (SOC)
 
Information Security Governance and Strategy
Information Security Governance and Strategy Information Security Governance and Strategy
Information Security Governance and Strategy
 
Addressing the cyber kill chain
Addressing the cyber kill chainAddressing the cyber kill chain
Addressing the cyber kill chain
 
Zero Trust Network Access
Zero Trust Network Access Zero Trust Network Access
Zero Trust Network Access
 
Iso 27001 foundation sample slides
Iso 27001 foundation sample slidesIso 27001 foundation sample slides
Iso 27001 foundation sample slides
 
Cloud Security using NIST guidelines
Cloud Security using NIST guidelinesCloud Security using NIST guidelines
Cloud Security using NIST guidelines
 
Itil,cobit and ıso27001
Itil,cobit and ıso27001Itil,cobit and ıso27001
Itil,cobit and ıso27001
 
Cyber Security roadmap.pptx
Cyber Security roadmap.pptxCyber Security roadmap.pptx
Cyber Security roadmap.pptx
 
Building a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS EnvironmentsBuilding a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS Environments
 

Andere mochten auch

Russain Optical Core Switch Market
Russain Optical Core Switch MarketRussain Optical Core Switch Market
Russain Optical Core Switch Marketguestba6d0cd
 
【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書env25
 
Wellspiration 6 - Fighting Heart Disease Naturally
Wellspiration 6  - Fighting Heart Disease NaturallyWellspiration 6  - Fighting Heart Disease Naturally
Wellspiration 6 - Fighting Heart Disease NaturallyYafa Sakkejha
 
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàngFacebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàngHoàng Nguyễn
 
Tdd pecha kucha_v2
Tdd pecha kucha_v2Tdd pecha kucha_v2
Tdd pecha kucha_v2Paul Boos
 
Supermods Enter Rehab
Supermods Enter RehabSupermods Enter Rehab
Supermods Enter Rehabguestda81b6
 
Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010Marko Gargenta
 
Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)Yuriy Silvestrov
 
Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009Bonnier
 
100道素菜(心經版)
100道素菜(心經版)100道素菜(心經版)
100道素菜(心經版)Richja
 
BMES @ SJSU
BMES @ SJSUBMES @ SJSU
BMES @ SJSUSheena
 
Social Media Legal Issues & Best Practices
Social Media Legal Issues & Best PracticesSocial Media Legal Issues & Best Practices
Social Media Legal Issues & Best Practicesskmarcus
 
Lezione Ed Ambientale
Lezione Ed AmbientaleLezione Ed Ambientale
Lezione Ed AmbientaleTeresa Fresu
 
Meeting Change Game
Meeting Change GameMeeting Change Game
Meeting Change GamePaul Boos
 

Andere mochten auch (20)

Russain Optical Core Switch Market
Russain Optical Core Switch MarketRussain Optical Core Switch Market
Russain Optical Core Switch Market
 
【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書【労働者健康福祉機構】平成19年度環境報告書
【労働者健康福祉機構】平成19年度環境報告書
 
Wellspiration 6 - Fighting Heart Disease Naturally
Wellspiration 6  - Fighting Heart Disease NaturallyWellspiration 6  - Fighting Heart Disease Naturally
Wellspiration 6 - Fighting Heart Disease Naturally
 
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàngFacebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
Facebook Marketing Hoàng Nguyễn-2. Tìm kiếm khách hàng
 
Tdd pecha kucha_v2
Tdd pecha kucha_v2Tdd pecha kucha_v2
Tdd pecha kucha_v2
 
Email Marketing & Landing Pages
Email Marketing & Landing PagesEmail Marketing & Landing Pages
Email Marketing & Landing Pages
 
Supermods Enter Rehab
Supermods Enter RehabSupermods Enter Rehab
Supermods Enter Rehab
 
Android Internals
Android InternalsAndroid Internals
Android Internals
 
Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010Android for Java Developers at OSCON 2010
Android for Java Developers at OSCON 2010
 
Resursele Regenerabile (2)
Resursele Regenerabile  (2)Resursele Regenerabile  (2)
Resursele Regenerabile (2)
 
Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)Agile antipatterns (Odessa, Vinnitsa)
Agile antipatterns (Odessa, Vinnitsa)
 
Linda
LindaLinda
Linda
 
Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009Bonnier Årsberättelse 2009
Bonnier Årsberättelse 2009
 
Pertussis en niños Lima
Pertussis en niños LimaPertussis en niños Lima
Pertussis en niños Lima
 
Hispaania
HispaaniaHispaania
Hispaania
 
100道素菜(心經版)
100道素菜(心經版)100道素菜(心經版)
100道素菜(心經版)
 
BMES @ SJSU
BMES @ SJSUBMES @ SJSU
BMES @ SJSU
 
Social Media Legal Issues & Best Practices
Social Media Legal Issues & Best PracticesSocial Media Legal Issues & Best Practices
Social Media Legal Issues & Best Practices
 
Lezione Ed Ambientale
Lezione Ed AmbientaleLezione Ed Ambientale
Lezione Ed Ambientale
 
Meeting Change Game
Meeting Change GameMeeting Change Game
Meeting Change Game
 

Ähnlich wie Use COBIT for IT SAVINGS

Cobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiCobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiIvo Oktavianti
 
CobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced ScorecardsCobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced ScorecardsMichael Sim
 
Frameworks For Predictability
Frameworks For PredictabilityFrameworks For Predictability
Frameworks For Predictabilitytlknecht
 
Frameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information TechnologyFrameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information TechnologyJohn Halliday
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance FrameworkSherri Booher
 
Pmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewPmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewAlan McSweeney
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Meghna Verma
 
IT frameworks
IT frameworksIT frameworks
IT frameworkscyouss
 
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practiceJohn Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practiceitSMF UK
 
COBIT® Presentation Package.ppt
COBIT® Presentation Package.pptCOBIT® Presentation Package.ppt
COBIT® Presentation Package.pptEmmacuet
 

Ähnlich wie Use COBIT for IT SAVINGS (20)

Cobit 4.1 indri
Cobit 4.1 indriCobit 4.1 indri
Cobit 4.1 indri
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
Cobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiCobit 4.1 ivooktavianti
Cobit 4.1 ivooktavianti
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
CobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced ScorecardsCobiT, Val IT & Balanced Scorecards
CobiT, Val IT & Balanced Scorecards
 
Frameworks For Predictability
Frameworks For PredictabilityFrameworks For Predictability
Frameworks For Predictability
 
Donna Febriani
Donna FebrianiDonna Febriani
Donna Febriani
 
Frameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information TechnologyFrameworks to drive value from your investment in Information Technology
Frameworks to drive value from your investment in Information Technology
 
Uas dwi widiastuti
Uas dwi widiastutiUas dwi widiastuti
Uas dwi widiastuti
 
IT Governance Framework
IT Governance FrameworkIT Governance Framework
IT Governance Framework
 
Pmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewPmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment Overview
 
Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799Comparison of it governance framework-COBIT, ITIL, BS7799
Comparison of it governance framework-COBIT, ITIL, BS7799
 
CobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast SeminarCobiT And ITIL Breakfast Seminar
CobiT And ITIL Breakfast Seminar
 
IT frameworks
IT frameworksIT frameworks
IT frameworks
 
Darmin ritonga 11353205418
Darmin ritonga 11353205418Darmin ritonga 11353205418
Darmin ritonga 11353205418
 
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
 
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practiceJohn Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
John Mcdermott - Gold sponsor session: Hybrid - IT needs hybrid good practice
 
IT Governance - COBIT Perspective
IT Governance - COBIT PerspectiveIT Governance - COBIT Perspective
IT Governance - COBIT Perspective
 
Audit rizkie hafizzah
Audit rizkie hafizzahAudit rizkie hafizzah
Audit rizkie hafizzah
 
COBIT® Presentation Package.ppt
COBIT® Presentation Package.pptCOBIT® Presentation Package.ppt
COBIT® Presentation Package.ppt
 

Kürzlich hochgeladen

PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationAnamaria Contreras
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024Adnet Communications
 
Chapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditChapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditNhtLNguyn9
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...ssuserf63bd7
 
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxFinancial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxsaniyaimamuddin
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Servicecallgirls2057
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdfShaun Heinrichs
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Seta Wicaksana
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaoncallgirls2057
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Kirill Klimov
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?Olivia Kresic
 

Kürzlich hochgeladen (20)

PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement Presentation
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024
 
Chapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditChapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal audit
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...
 
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxFinancial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?
 

Use COBIT for IT SAVINGS

  • 1. Introduction-BenefitsIntroduction-Benefits COBIT FrameworkCOBIT Framework With ExampleWith Example Sanjiv Arora, CISA, CISM, CGEIT Principal Consultant TECHNOLOGICS & CONTROLS Protecting the ABCs of your business.
  • 2. AgendaAgenda  IT Governance  COBIT framework  Example - Cost Management Controls in IT Operations using COBIT  About Technologics and Controls
  • 3. IT Governance – Need?IT Governance – Need? What is driving today’s businesses? Assertive Stakeholders Aggressive Competition Emerging Regulations Recessionary trends direct / indirect Extremely high IT Dependence Impacts Enterprise GovernanceEnterprise Governance
  • 4. IT Governance - AlignmentIT Governance - Alignment Value Delivery •Secure •On Time •Within Budgets •Good Quality •Reduce Expense •Proven best practices Business Benefits •Customer satisfaction •Brand Loyalty •Competitive advantage •Profitability Crux - Fill what's empty. Empty what's full. And scratch where it itches. – Murphy’s law
  • 5. Why COBIT?Why COBIT?  Better alignment based on business focus  Demonstrates management viewpoint and expectations  Clear ownerships and responsibilities based on processes  Increasing acceptability with third parties and regulators  Eases IT Governance communication between stakeholders and other parties  Fulfillment of the COSO requirements for IT control environment
  • 6. Lack of IT Governance makes it....Lack of IT Governance makes it....  Difficult to make a link to the business requirements  Complex to measure performance against the requirements  Cumbersome to control activities using a generally accepted process model  Difficult to identify the resources to be leveraged  A problem to define management control objectives
  • 7. Use of COBIT – Practical ScenarioUse of COBIT – Practical Scenario  Uses are  Implement and Manage IT governance  Risk Assessment and Management  Defining KPI and KGI  Mapping to other standards  Customize controls  Provides direction and recommendations for weak controls  Aid to implement ERP, BCP, BPR and other IT projects  Implement Cost Savings on IT spend (Capex and Opex)  Assessment of IT governance maturity  Demonstrate IT alignment (using Balance Score card)
  • 8. COBIT – It is ImplementableCOBIT – It is Implementable  Based on self assessment  Very comprehensive yet flexible  Does not enforce COMPLETE implementation  Customizable  Easy to understand (Subject Matter Experts are available)  Implementation maybe fast track, with help of tools
  • 9. COBIT – Importance Vs Other standardsCOBIT – Importance Vs Other standards  Comprehensive for business requirements  Business operations completely dependent on IT  Business applications (ERP), workflows, resource sharing, communication (chat, email,video conferencing) controls are all logical controls  Approval and authorization – financial or non-financial is mostly handled by logical controls  Confidentiality is primarily managed within technology  COBIT encompasses all aspects of IT Governance  Other standards where COBIT is useful  ITIL  SOX compliance  PCI-DSS  NIST  HIPAA  ISO27001  Others
  • 10. COBITCOBIT – Other Standards– Other Standards http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=31702 Common misunderstanding: We already have xyz standard, so we do not need COBIT.
  • 11. COBIT FrameworkCOBIT Framework Source – ITGI presentation materials
  • 12. The following slides explain an example of COBIT framework implementation. The slides are prepared using the Meycor COBIT suite software tools. Actual tool may also be demonstrated as necessary, time and audience permitting. Thanks.
  • 14. COBIT – Key Objectives and ControlsCOBIT – Key Objectives and Controls
  • 15. COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach 4 Domains 34 Processes (select applicable processes) 210 Control Objectives (select from applicable objectives) Controls (Select / add / modify controls to Suit your IT Governance needs) * Equals = 4 Domains 22 processes 145 controls objectives N Controls * An example
  • 16. COBIT – Processes and Controls – Tangible Cost ManagementCOBIT – Processes and Controls – Tangible Cost Management Source - http://www.isaca.org/AMTemplate.cfm?Section=COBIT_Focus&Template=/ContentManagement/ContentDisplay.cfm&ContentID=47399 Cost Management Controls = Selected 10 processes
  • 17. COBIT – Processes and Controls – Excess Labour ManagementCOBIT – Processes and Controls – Excess Labour Management Too many cooks….!
  • 18. COBIT – Assessment and gaps – Tangible Cost ManagementCOBIT – Assessment and gaps – Tangible Cost Management
  • 19. COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving Cont’d
  • 20. COBIT – Tangible Cost Management – Concerns / SavingCOBIT – Tangible Cost Management – Concerns / Saving
  • 21. COBIT – Tangible Cost Management – Recommendation – DS2COBIT – Tangible Cost Management – Recommendation – DS2 Customize recommendations according to business objectives.
  • 22. COBIT – Tangible Cost Management–Tasks/linked RecommendationCOBIT – Tangible Cost Management–Tasks/linked Recommendation
  • 23. COBIT – Tangible Cost Management–Tasks Manage / ComplyCOBIT – Tangible Cost Management–Tasks Manage / Comply Verify and validate to ensure compliance and success.
  • 24. COBIT – Tangible Cost Management– Communicate ResultsCOBIT – Tangible Cost Management– Communicate Results  Proactive IT initiatives and operational improvements  Enhance credibility of the IT organization  Benefits  Tangibles  Current period vs previous period  % saving from alternate options  Forecast reduction in expense / ROI  Intangibles  Efficiency of operations  Reduced incidents  High uptime  Link to business objectives  Faster product launch  Timely service delivery  Increase in customers / revenue
  • 25. COBIT – Map Business objectives using Funnel ApproachCOBIT – Map Business objectives using Funnel Approach 4 Domains 34 Processes (select applicable processes) 210 Control Objectives (select from applicable objectives) Controls (Select / add / modify controls to Suit your IT Governance needs) * Equals = 4 Domains 22 processes 145 controls objectives N Controls * An example The funnel model can be used for implementation of ERP, Other IT Projects, Project Monitoring and controls, Compliance checklists
  • 26. Introduction : Technologics & ControlsIntroduction : Technologics & Controls  Founded in 2001  Based in New Delhi, India  Services: IT Audits, Risk Management consulting, Information security assessment and management, IT Governance services, compliance and related services.  Products: Sole reseller in India of DataSec S.R.L providing software solutions based on COBIT / ISO27001 / COSO and other standards
  • 27. COBIT – BenefitsCOBIT – Benefits We offer our rich experience to meet your Business Requirements and Objectives in the IT Audits, IT Governance, Risk, Security Awareness, CISA, CISM Training and IT Strategy consulting areas. Our specializations includes reviews of ERP, CBS, Information Architecture, IT Efficiency and Effectiveness to deliver value amongst other things. We have worked with Al Rajhi Takaful in KSA, Qatar Steel, WFP, WHO, UNOPS, Govt of India and many other reputed companies across the world. We shall be happy to discuss your requirements, Look forward. Sanjiv Arora Contact us on +91 98102 93733 or email sa@tech-controls.com www.tech-controls.com