<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance Blog &#187; COBIT</title>
	<atom:link href="http://www.itgovernanceblog.com/category/cobit/feed" rel="self" type="application/rss+xml" />
	<link>http://www.itgovernanceblog.com</link>
	<description>One man's journey into the world of IT Governance</description>
	<lastBuildDate>Sun, 26 Jun 2011 00:17:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>PO4.2 IT Strategy Committee</title>
		<link>http://www.itgovernanceblog.com/po4-2-it-strategy-committee-335.htm</link>
		<comments>http://www.itgovernanceblog.com/po4-2-it-strategy-committee-335.htm#comments</comments>
		<pubDate>Sun, 31 Oct 2010 13:28:15 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[IT Strategy Committee]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[process improvement]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=335</guid>
		<description><![CDATA[<p>CobiT definition: Establish an IT strategy committee at the board level. This committee should ensure that IT governance, as part of enterprise governance, is adequately addressed; advise on strategic direction; and review major investments on behalf of the full board. Bill says, One of the important things to remember when looking at a framework such [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/po4-2-it-strategy-committee-335.htm">PO4.2 IT Strategy Committee</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Establish an IT strategy committee at the board level. This committee should ensure that IT governance, as part of enterprise governance, is adequately addressed; advise on strategic direction; and review major investments on behalf of the full board.</p></blockquote>
<p><strong>Bill</strong> says,</p>
<p>One of the important things to remember when looking at a framework such as CobiT is that it isn&#8217;t right for everyone, or rather, parts of it may need to be adjusted to fit your organization.  Whether your <strong>IT Strategy Committee</strong> will be a different group than your IT Steering Committee (which is the next control object), is a question of the size, maturity and industry of your company.  As defined by Cobit, this IT Strategy Committee is at the board level, which may very well work in certain companies.  Perhaps those companies have boards interested in having an IT Strategy Committee alongside their Executive Compensation Committee.  But not in my experience.</p>
<p>Certainly large IT investments or directions changes that have a material impact on the business should be raised to the board level, but at least in my company we would never form such a committee at the board level; there simply would be no interest in it.  Does that mean you shouldn&#8217;t do this?  Of course not &#8211; if you an get the interest at the board level then go for it!  Otherwise, you simply implement your IT Strategy Committee at a lower level in the organization, certainly including senior business managers.</p>
<p>At my company we have both an IT Strategy Committee, which meets only once a year, and an IT Steering Committee, which meets quarterly.  The Strategy Committee&#8217;s role is very big picture and simply serves as a beacon of &#8220;true north&#8221; from an IT investment and direction standpoint.  Every decision we make should align with the annual strategy developed and/or approved by the IT Strategy Committee.</p>
<p>The governance around how that strategy comes to fruition is done at the IT Steering Committee level, which we&#8217;ll discuss next.</p>
<p>The second step in <a href="http://www.itgovernanceblog.com/po4-define-the-it-processes-organisation-and-relationships-156.htm">Defining the IT Processes, Organization and Relationships</a> is to form a solid <strong>IT Strategy Committee</strong>.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/po4-2-it-strategy-committee-335.htm">PO4.2 IT Strategy Committee</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/po4-2-it-strategy-committee-335.htm/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>PO4.1 IT Process Framework</title>
		<link>http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm</link>
		<comments>http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm#comments</comments>
		<pubDate>Sun, 17 Jan 2010 15:02:41 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[framework]]></category>
		<category><![CDATA[information technology process framework]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[it process framwork]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[process framework]]></category>
		<category><![CDATA[process improvement]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=324</guid>
		<description><![CDATA[<p>CobiT definition: Define an IT process framework to execute the IT strategic plan. This framework should include an IT process structure and relationships (e.g., to manage process gaps and overlaps), ownership, maturity, performance measurement, improvement, compliance, quality targets and plans to achieve them. It should provide integration amongst the processes that are specific to IT, [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm">PO4.1 IT Process Framework</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Define an IT process framework to execute the IT strategic plan. This framework should include an IT process structure and relationships (e.g., to manage process gaps and overlaps), ownership, maturity, performance measurement, improvement, compliance, quality targets and plans to achieve them. It should provide integration amongst the processes that are specific to IT, enterprise portfolio management, business processes and business change processes. The IT process framework should be integrated into a quality management system (QMS) and the internal control framework.</p></blockquote>
<p><strong>Bill</strong> says,</p>
<p>First of all, for those of you subscribed and reading in a reader, I apologize for the rash of posts yesterday &#8211; I decided it would be easier for me to keep these updates coming if I fleshed out the entire CobiT framework first so that now all I need to focus on is the content and updating the links in the tables of contents.  So I think that meant I posted 25 or so posts yesterday.  Certainly not the norm!</p>
<p>Speaking of frameworks, this control objective talks about establishing an <strong>IT Process Framework</strong>.  Now I don&#8217;t take this to mean overall IT governance, that is something not addressed until we get to the <a href="http://www.itgovernanceblog.com/cobit-domain-monitor-and-evaluate-148.htm">Monitor and Evaluate</a> domain.  But I do feel as though this is related.  The very first thing that we did in CobiT is to define our <a href="http://www.itgovernanceblog.com/define-a-strategic-it-plan-17.htm">Strategic IT Plan</a> and this control objective is all about establishing the rules for how you will ensure adherence to that strategic plan.  A plan is useless unless followed! </p>
<p>In the definition it refers to an internal control framework and to be honest that is something I struggle with because rather than that being something different I see the process framework as basically the same thing.  But remember, I am coming from a small organization so I do tend to see things differently as I prefer to lump many of these control objectives together where it makes sense.</p>
<p>Here is the bottom line for me &#8211; what you need is some sort of plan for how you will keep your people and your processes aligned to your strategic plan.  There needs to be some gating mechanisms and some methods for reporting and analyzing results.  The key is that this is something that just needs to be included in everyone&#8217;s daily work, not some thing you whip out when reviewing your strategic plan with the Board.</p>
<p>The first step in <a href="http://www.itgovernanceblog.com/po4-define-the-it-processes-organisation-and-relationships-156.htm">Defining the IT Processes, Organization and Relationships</a> is to define a solid<strong> IT Process Framework</strong>.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm">PO4.1 IT Process Framework</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ME4 Provide IT Governance</title>
		<link>http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm</link>
		<comments>http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:47:37 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME4]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[govern information technology]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=319</guid>
		<description><![CDATA[<p>CobiT definition: Establishing an effective governance framework includes defining organisational structures, processes, leadership, roles and responsibilities to ensure that enterprise IT investments are aligned and delivered in accordance with enterprise strategies and objectives. Control over the IT process of Provide IT governance that satisfies the business requirement for IT of integrating IT governance with corporate [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm">ME4 Provide IT Governance</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Establishing an effective governance framework includes defining organisational structures, processes, leadership, roles and responsibilities to ensure that enterprise IT investments are aligned and delivered in accordance with enterprise strategies and objectives.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Provide IT governance</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
integrating IT governance with corporate governance objectives and complying with laws, regulations and contracts</p>
<p><strong>by focusing on</strong><br />
preparing board reports on IT strategy, performance and risks, and responding to governance requirements in line with board directions</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Establishing an IT governance framework integrated into corporate governance</li>
<li>Obtaining independent assurance over the IT governance status</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Frequency of board reporting on IT to stakeholders (including maturity)</li>
<li>Frequency of reporting from IT to the board (including maturity)</li>
<li>Frequency of independent reviews of IT compliance</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME4 Provide IT Governance</strong></p>
<p>ME4.1 Establishment of an IT Governance Framework<br />
ME4.2 Strategic Alignment<br />
ME4.3 Value Delivery<br />
ME4.4 Resource Management<br />
ME4.5 Risk Management<br />
ME4.6 Performance Measurement<br />
ME4.7 Independent Assurance</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm">ME4 Provide IT Governance</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ME3 Ensure Compliance With External Requirements</title>
		<link>http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm</link>
		<comments>http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:42:00 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME3]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[ensure compliance]]></category>
		<category><![CDATA[external requirements]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=313</guid>
		<description><![CDATA[<p>CobiT definition: Effective oversight of compliance requires the establishment of a review process to ensure compliance with laws, regulations and contractual requirements. This process includes identifying compliance requirements, optimising and evaluating the response, obtaining assurance that the requirements have been complied with and, finally, integrating IT’s compliance reporting with the rest of the business. Control [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm">ME3 Ensure Compliance With External Requirements</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective oversight of compliance requires the establishment of a review process to ensure compliance with laws, regulations and contractual requirements. This process includes identifying compliance requirements, optimising and evaluating the response, obtaining assurance that the requirements have been complied with and, finally, integrating IT’s compliance reporting with the rest of the business.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Ensure compliance with external requirements</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
ensuring compliance with laws, regulations and contractual requirements</p>
<p><strong>by focusing on</strong><br />
identifying all applicable laws, regulations and contracts and the corresponding level of IT compliance and optimising IT processes to reduce the risk of non-compliance</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Identifying legal, regulatory and contractual requirements related to IT</li>
<li>Assessing the impact of compliance requirements</li>
<li>Monitoring and reporting on compliance with these requirements</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Cost of IT non-compliance, including settlements and fines</li>
<li>Average time lag between identification of external compliance issues and resolution</li>
<li>Frequency of compliance reviews</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME3 Ensure Compliance With External Requirements</strong></p>
<p>ME3.1 Identification of External Legal, Regulatory and Contractual Compliance Requirements<br />
ME3.2 Optimisation of Response to External Requirements<br />
ME3.3 Evaluation of Compliance With External Requirements<br />
ME3.4 Positive Assurance of Compliance<br />
ME3.5 Integrated Reporting</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm">ME3 Ensure Compliance With External Requirements</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ME2 Monitor and Evaluate Internal Control</title>
		<link>http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm</link>
		<comments>http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:35:57 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME2]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it general controls]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[monitor internal control]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=308</guid>
		<description><![CDATA[<p>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring and reporting of control exceptions, results of self-assessments and third-party reviews. A key benefit of internal control monitoring is to provide assurance regarding effective and efficient operations and compliance with applicable laws and regulations. Control [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm">ME2 Monitor and Evaluate Internal Control</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring and reporting of control exceptions, results of self-assessments and third-party reviews. A key benefit of internal control monitoring is to provide assurance regarding effective and efficient operations and compliance with applicable laws and regulations.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Monitor and evaluate internal control</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
protecting the achievement of IT objectives and complying with IT-related laws, regulations and contracts</p>
<p><strong>by focusing on</strong><br />
monitoring the internal control processes for IT-related activities and identifying improvement actions</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Defining a system of internal controls embedded in the IT process framework</li>
<li>Monitoring and reporting on the effectiveness of the internal controls over IT</li>
<li>Reporting control exceptions to management for action</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Number of major internal control breaches</li>
<li>Number of control improvement initiatives</li>
<li>Number and coverage of control self-assessments</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME2 Monitor and Evaluate Internal Control</strong></p>
<p>ME2.1 Monitoring of Internal Control Framework<br />
ME2.2 Supervisory Review<br />
ME2.3 Control Exceptions<br />
ME2.4 Control Self-assessment<br />
ME2.5 Assurance of Internal Control<br />
ME2.6 Internal Control at Third Parties<br />
ME2.7 Remedial Actions</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm">ME2 Monitor and Evaluate Internal Control</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ME1 Monitor and Evaluate IT Performance</title>
		<link>http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm</link>
		<comments>http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:29:00 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME1]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[it performance]]></category>
		<category><![CDATA[monitor and evaluate]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=303</guid>
		<description><![CDATA[<p>CobiT definition: Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely reporting of performance, and prompt acting upon deviations. Monitoring is needed to make sure that the right things are done and are in line with the set directions and policies. Control over the IT process [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm">ME1 Monitor and Evaluate IT Performance</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely reporting of performance, and prompt acting upon deviations. Monitoring is needed to make sure that the right things are done and are in line with the set directions and policies.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Monitor and evaluate IT performance</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
transparency and understanding of IT cost, benefits, strategy, policies and service levels in accordance with governance requirements</p>
<p><strong>by focusing on</strong><br />
monitoring and reporting process metrics and identifying and implementing performance improvement actions</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Collating and translating process performance reports into management reports</li>
<li>Reviewing performance against agreed-upon targets and initiating necessary remedial action</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Satisfaction of management and the governance entity with the performance reporting</li>
<li>Number of improvement actions driven by monitoring activities</li>
<li>Percent of critical processes monitored</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME1 Monitor and Evaluate IT Performance</strong></p>
<p>ME1.1 Monitoring Approach<br />
ME1.2 Definition and Collection of Monitoring Data<br />
ME1.3 Monitoring Method<br />
ME1.4 Performance Assessment<br />
ME1.5 Board and Executive Reporting<br />
ME1.6 Remedial Actions</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm">ME1 Monitor and Evaluate IT Performance</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS13 Manage Operations</title>
		<link>http://www.itgovernanceblog.com/ds13-manage-operations-298.htm</link>
		<comments>http://www.itgovernanceblog.com/ds13-manage-operations-298.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:20:07 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS13]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[manage operations]]></category>
		<category><![CDATA[operations management]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=298</guid>
		<description><![CDATA[<p>CobiT definition: Complete and accurate processing of data requires effective management of data processing procedures and diligent maintenance of hardware. This process includes defining operating policies and procedures for effective management of scheduled processing, protecting sensitive output, monitoring infrastructure performance and ensuring preventive maintenance of hardware. Effective operations management helps maintain data integrity and reduces [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds13-manage-operations-298.htm">DS13 Manage Operations</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Complete and accurate processing of data requires effective management of data processing procedures and diligent maintenance of hardware. This process includes defining operating policies and procedures for effective management of scheduled processing, protecting sensitive output, monitoring infrastructure performance and ensuring preventive maintenance of hardware. Effective operations management helps maintain data integrity and reduces business delays and IT operating costs.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage operations</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
maintaining data integrity and ensuring that IT infrastructure can resist and recover from errors and failures</p>
<p><strong>by focusing on</strong><br />
meeting operational service levels for scheduled data processing, protecting sensitive output, and monitoring and maintaining infrastructure</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Operating the IT environment in line with agreed-upon service levels and defined instructions</li>
<li>Maintaining the IT infrastructure</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Number of service levels impacted by operational incidents</li>
<li>Hours of unplanned downtime caused by operational incidents</li>
<li>Percent of hardware assets included in preventive maintenance schedules</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS13 Manage Operations</strong></p>
<p>DS13.1 Operations Procedures and Instructions<br />
DS13.2 Job Scheduling<br />
DS13.3 IT Infrastructure Monitoring<br />
DS13.4 Sensitive Documents and Output Devices<br />
DS13.5 Preventive Maintenance for Hardware</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds13-manage-operations-298.htm">DS13 Manage Operations</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds13-manage-operations-298.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS12 Manage the Physical Environment</title>
		<link>http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm</link>
		<comments>http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:14:41 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS12]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[physical environment management]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=293</guid>
		<description><![CDATA[<p>CobiT definition: Protection for computer equipment and personnel requires well-designed and well-managed physical facilities. The process of managing the physical environment includes defining the physical site requirements, selecting appropriate facilities, and designing effective processes for monitoring environmental factors and managing physical access. Effective management of the physical environment reduces business interruptions from damage to computer [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm">DS12 Manage the Physical Environment</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Protection for computer equipment and personnel requires well-designed and well-managed physical facilities. The process of managing the physical environment includes defining the physical site requirements, selecting appropriate facilities, and designing effective processes for monitoring environmental factors and managing physical access. Effective management of the physical environment reduces business interruptions from damage to computer equipment and personnel.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage the physical environment</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
protecting computer assets and business data and minimising the risk of business disruption</p>
<p><strong>by focusing on</strong><br />
providing and maintaining a suitable physical environment to protect IT assets from access, damage or theft</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Implementing physical security measures</li>
<li>Selecting and managing facilities</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Amount of downtime arising from physical environment incidents</li>
<li>Number of incidents due to physical security breaches or failures</li>
<li>Frequency of physical risk assessment and reviews</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS12 Manage the Physical Environment</strong></p>
<p>DS12.1 Site Selection and Layout<br />
DS12.2 Physical Security Measures<br />
DS12.3 Physical Access<br />
DS12.4 Protection Against Environmental Factors<br />
DS12.5 Physical Facilities Management</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm">DS12 Manage the Physical Environment</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS11 Manage Data</title>
		<link>http://www.itgovernanceblog.com/ds11-manage-data-288.htm</link>
		<comments>http://www.itgovernanceblog.com/ds11-manage-data-288.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:09:15 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS11]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[data management]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[manage data]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=288</guid>
		<description><![CDATA[<p>CobiT definition: Effective data management requires identifying data requirements. The data management process also includes the establishment of effective procedures to manage the media library, backup and recovery of data, and proper disposal of media. Effective data management helps ensure the quality, timeliness and availability of business data. Control over the IT process of Manage [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds11-manage-data-288.htm">DS11 Manage Data</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective data management requires identifying data requirements. The data management process also includes the establishment of effective procedures to manage the media library, backup and recovery of data, and proper disposal of media. Effective data management helps ensure the quality, timeliness and availability of business data.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage data</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
optimising the use of information and ensuring that information is available as required</p>
<p><strong>by focusing on</strong><br />
maintaining the completeness, accuracy, availability and protection of data</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Backing up data and testing restoration</li>
<li>Managing onsite and offsite storage of data</li>
<li>Securely disposing of data and equipment</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Percent of user satisfaction with availability of data</li>
<li>Percent of successful data restorations</li>
<li>Number of incidents where sensitive data were retrieved after media were disposed</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS11 Manage Data</strong></p>
<p>DS11.1 Business Requirements for Data Management<br />
DS11.2 Storage and Retention Arrangements<br />
DS11.3 Media Library Management System<br />
DS11.4 Disposal<br />
DS11.5 Backup and Restoration<br />
DS11.6 Security Requirements for Data Management</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds11-manage-data-288.htm">DS11 Manage Data</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds11-manage-data-288.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS10 Manage Problems</title>
		<link>http://www.itgovernanceblog.com/ds10-manage-problems-283.htm</link>
		<comments>http://www.itgovernanceblog.com/ds10-manage-problems-283.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:01:20 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS10]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[manage problems]]></category>
		<category><![CDATA[problem management]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=283</guid>
		<description><![CDATA[<p>CobiT definition: Effective problem management requires the identification and classification of problems, root cause analysis and resolution of problems. The problem management process also includes the formulation of recommendations for improvement, maintenance of problem records and review of the status of corrective actions. An effective problem management process maximises system availability, improves service levels, reduces [...]</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds10-manage-problems-283.htm">DS10 Manage Problems</a></p>
No related posts.]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective problem management requires the identification and classification of problems, root cause analysis and resolution of problems. The problem management process also includes the formulation of recommendations for improvement, maintenance of problem records and review of the status of corrective actions. An effective problem management process maximises system availability, improves service levels, reduces costs, and improves customer convenience and satisfaction.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage problems</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
ensuring end users’ satisfaction with service offerings and service levels, and reducing solution and service delivery defects and rework</p>
<p><strong>by focusing on</strong><br />
recording, tracking and resolving operational problems; investigating the root cause of all significant problems; and defining solutions for identified operations problems</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Performing root cause analysis of reported problems</li>
<li>Analysing trends</li>
<li>Taking ownership of problems and progressing problem resolution</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Number of recurring problems with an impact on the business</li>
<li>Percent of problems resolved within the required time period</li>
<li>Frequency of reports or updates to an ongoing problem, based on the problem severity</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS10 Manage Problems</strong></p>
<p>DS10.1 Identification and Classification of Problems<br />
DS10.2 Problem Tracking and Resolution<br />
DS10.3 Problem Closure<br />
DS10.4 Integration of Configuration, Incident and Problem Management</p>
<p>Check out the links for details on the control objectives.</p>
<p>No related posts.</p><p>Post from: <a href="http://www.itgovernanceblog.com">IT Governance - COBIT AND ITIL</a><br/><br/><a href="http://www.itgovernanceblog.com/ds10-manage-problems-283.htm">DS10 Manage Problems</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds10-manage-problems-283.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: www.itgovernanceblog.com @ 2012-02-04 02:18:26 -->
