<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance Blog &#187; COBIT</title>
	<atom:link href="http://www.itgovernanceblog.com/category/cobit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itgovernanceblog.com</link>
	<description>One man's journey into the world of IT Governance</description>
	<lastBuildDate>Fri, 19 Feb 2010 21:50:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>PO4.1 IT Process Framework</title>
		<link>http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm</link>
		<comments>http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm#comments</comments>
		<pubDate>Sun, 17 Jan 2010 15:02:41 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[framework]]></category>
		<category><![CDATA[information technology process framework]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[it process framwork]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[process framework]]></category>
		<category><![CDATA[process improvement]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=324</guid>
		<description><![CDATA[CobiT definition: Define an IT process framework to execute the IT strategic plan. This framework should include an IT process structure and relationships (e.g., to manage process gaps and overlaps), ownership, maturity, performance measurement, improvement, compliance, quality targets and plans to achieve them. It should provide integration amongst the processes that are specific to IT, [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/po4-define-the-it-processes-organisation-and-relationships-156.htm' rel='bookmark' title='Permanent Link: PO4 Define the IT Processes, Organisation and Relationships'>PO4 Define the IT Processes, Organisation and Relationships</a> <small>CobiT definition: An IT organisation is defined by considering requirements for staff, skills, functions, accountability, authority, roles and responsibilities, and...</small></li>
<li><a href='http://www.itgovernanceblog.com/po3-5-it-architecture-board-128.htm' rel='bookmark' title='Permanent Link: PO3.5 IT Architecture Board'>PO3.5 IT Architecture Board</a> <small>CobiT definition: Establish an IT architecture board to provide architecture guidelines and advice on their application, and to verify compliance....</small></li>
<li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Define an IT process framework to execute the IT strategic plan. This framework should include an IT process structure and relationships (e.g., to manage process gaps and overlaps), ownership, maturity, performance measurement, improvement, compliance, quality targets and plans to achieve them. It should provide integration amongst the processes that are specific to IT, enterprise portfolio management, business processes and business change processes. The IT process framework should be integrated into a quality management system (QMS) and the internal control framework.</p></blockquote>
<p><strong>Bill</strong> says,</p>
<p>First of all, for those of you subscribed and reading in a reader, I apologize for the rash of posts yesterday &#8211; I decided it would be easier for me to keep these updates coming if I fleshed out the entire CobiT framework first so that now all I need to focus on is the content and updating the links in the tables of contents.  So I think that meant I posted 25 or so posts yesterday.  Certainly not the norm!</p>
<p>Speaking of frameworks, this control objective talks about establishing an <strong>IT Process Framework</strong>.  Now I don&#8217;t take this to mean overall IT governance, that is something not addressed until we get to the <a href="http://www.itgovernanceblog.com/cobit-domain-monitor-and-evaluate-148.htm">Monitor and Evaluate</a> domain.  But I do feel as though this is related.  The very first thing that we did in CobiT is to define our <a href="http://www.itgovernanceblog.com/define-a-strategic-it-plan-17.htm">Strategic IT Plan</a> and this control objective is all about establishing the rules for how you will ensure adherence to that strategic plan.  A plan is useless unless followed! </p>
<p>In the definition it refers to an internal control framework and to be honest that is something I struggle with because rather than that being something different I see the process framework as basically the same thing.  But remember, I am coming from a small organization so I do tend to see things differently as I prefer to lump many of these control objectives together where it makes sense.</p>
<p>Here is the bottom line for me &#8211; what you need is some sort of plan for how you will keep your people and your processes aligned to your strategic plan.  There needs to be some gating mechanisms and some methods for reporting and analyzing results.  The key is that this is something that just needs to be included in everyone&#8217;s daily work, not some thing you whip out when reviewing your strategic plan with the Board.</p>
<p>The first step in <a href="http://www.itgovernanceblog.com/po4-define-the-it-processes-organisation-and-relationships-156.htm">Defining the IT Processes, Organization and Relationships</a> is to define a solid<strong> IT Process Framework</strong>.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/po4-define-the-it-processes-organisation-and-relationships-156.htm' rel='bookmark' title='Permanent Link: PO4 Define the IT Processes, Organisation and Relationships'>PO4 Define the IT Processes, Organisation and Relationships</a> <small>CobiT definition: An IT organisation is defined by considering requirements for staff, skills, functions, accountability, authority, roles and responsibilities, and...</small></li>
<li><a href='http://www.itgovernanceblog.com/po3-5-it-architecture-board-128.htm' rel='bookmark' title='Permanent Link: PO3.5 IT Architecture Board'>PO3.5 IT Architecture Board</a> <small>CobiT definition: Establish an IT architecture board to provide architecture guidelines and advice on their application, and to verify compliance....</small></li>
<li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/po4-1-it-process-framework-324.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ME4 Provide IT Governance</title>
		<link>http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm</link>
		<comments>http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:47:37 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME4]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[govern information technology]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=319</guid>
		<description><![CDATA[CobiT definition: Establishing an effective governance framework includes defining organisational structures, processes, leadership, roles and responsibilities to ensure that enterprise IT investments are aligned and delivered in accordance with enterprise strategies and objectives. Control over the IT process of Provide IT governance that satisfies the business requirement for IT of integrating IT governance with corporate [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
<li><a href='http://www.itgovernanceblog.com/ai6-manage-changes-224.htm' rel='bookmark' title='Permanent Link: AI6 Manage Changes'>AI6 Manage Changes</a> <small>CobiT definition: All changes, including emergency maintenance and patches, relating to infrastructure and applications within the production environment are formally...</small></li>
<li><a href='http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm' rel='bookmark' title='Permanent Link: ME1 Monitor and Evaluate IT Performance'>ME1 Monitor and Evaluate IT Performance</a> <small>CobiT definition: Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Establishing an effective governance framework includes defining organisational structures, processes, leadership, roles and responsibilities to ensure that enterprise IT investments are aligned and delivered in accordance with enterprise strategies and objectives.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Provide IT governance</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
integrating IT governance with corporate governance objectives and complying with laws, regulations and contracts</p>
<p><strong>by focusing on</strong><br />
preparing board reports on IT strategy, performance and risks, and responding to governance requirements in line with board directions</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Establishing an IT governance framework integrated into corporate governance</li>
<li>Obtaining independent assurance over the IT governance status</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Frequency of board reporting on IT to stakeholders (including maturity)</li>
<li>Frequency of reporting from IT to the board (including maturity)</li>
<li>Frequency of independent reviews of IT compliance</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME4 Provide IT Governance</strong></p>
<p>ME4.1 Establishment of an IT Governance Framework<br />
ME4.2 Strategic Alignment<br />
ME4.3 Value Delivery<br />
ME4.4 Resource Management<br />
ME4.5 Risk Management<br />
ME4.6 Performance Measurement<br />
ME4.7 Independent Assurance</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
<li><a href='http://www.itgovernanceblog.com/ai6-manage-changes-224.htm' rel='bookmark' title='Permanent Link: AI6 Manage Changes'>AI6 Manage Changes</a> <small>CobiT definition: All changes, including emergency maintenance and patches, relating to infrastructure and applications within the production environment are formally...</small></li>
<li><a href='http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm' rel='bookmark' title='Permanent Link: ME1 Monitor and Evaluate IT Performance'>ME1 Monitor and Evaluate IT Performance</a> <small>CobiT definition: Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me4-provide-it-governance-319.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ME3 Ensure Compliance With External Requirements</title>
		<link>http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm</link>
		<comments>http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:42:00 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME3]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[ensure compliance]]></category>
		<category><![CDATA[external requirements]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=313</guid>
		<description><![CDATA[CobiT definition: Effective oversight of compliance requires the establishment of a review process to ensure compliance with laws, regulations and contractual requirements. This process includes identifying compliance requirements, optimising and evaluating the response, obtaining assurance that the requirements have been complied with and, finally, integrating IT’s compliance reporting with the rest of the business. Control [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds3-manage-performance-and-capacity-245.htm' rel='bookmark' title='Permanent Link: DS3 Manage Performance and Capacity'>DS3 Manage Performance and Capacity</a> <small>CobiT definition: The need to manage performance and capacity of IT resources requires a process to periodically review current performance...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds7-educate-and-train-users-267.htm' rel='bookmark' title='Permanent Link: DS7 Educate and Train Users'>DS7 Educate and Train Users</a> <small>CobiT definition: Effective education of all users of IT systems, including those within IT, requires identifying the training needs of...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective oversight of compliance requires the establishment of a review process to ensure compliance with laws, regulations and contractual requirements. This process includes identifying compliance requirements, optimising and evaluating the response, obtaining assurance that the requirements have been complied with and, finally, integrating IT’s compliance reporting with the rest of the business.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Ensure compliance with external requirements</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
ensuring compliance with laws, regulations and contractual requirements</p>
<p><strong>by focusing on</strong><br />
identifying all applicable laws, regulations and contracts and the corresponding level of IT compliance and optimising IT processes to reduce the risk of non-compliance</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Identifying legal, regulatory and contractual requirements related to IT</li>
<li>Assessing the impact of compliance requirements</li>
<li>Monitoring and reporting on compliance with these requirements</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Cost of IT non-compliance, including settlements and fines</li>
<li>Average time lag between identification of external compliance issues and resolution</li>
<li>Frequency of compliance reviews</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME3 Ensure Compliance With External Requirements</strong></p>
<p>ME3.1 Identification of External Legal, Regulatory and Contractual Compliance Requirements<br />
ME3.2 Optimisation of Response to External Requirements<br />
ME3.3 Evaluation of Compliance With External Requirements<br />
ME3.4 Positive Assurance of Compliance<br />
ME3.5 Integrated Reporting</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds3-manage-performance-and-capacity-245.htm' rel='bookmark' title='Permanent Link: DS3 Manage Performance and Capacity'>DS3 Manage Performance and Capacity</a> <small>CobiT definition: The need to manage performance and capacity of IT resources requires a process to periodically review current performance...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds7-educate-and-train-users-267.htm' rel='bookmark' title='Permanent Link: DS7 Educate and Train Users'>DS7 Educate and Train Users</a> <small>CobiT definition: Effective education of all users of IT systems, including those within IT, requires identifying the training needs of...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me3-ensure-compliance-with-external-requirements-313.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ME2 Monitor and Evaluate Internal Control</title>
		<link>http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm</link>
		<comments>http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:35:57 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME2]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it general controls]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[monitor internal control]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=308</guid>
		<description><![CDATA[CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring and reporting of control exceptions, results of self-assessments and third-party reviews. A key benefit of internal control monitoring is to provide assurance regarding effective and efficient operations and compliance with applicable laws and regulations. Control [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm' rel='bookmark' title='Permanent Link: ME1 Monitor and Evaluate IT Performance'>ME1 Monitor and Evaluate IT Performance</a> <small>CobiT definition: Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely...</small></li>
<li><a href='http://www.itgovernanceblog.com/cobit-domain-monitor-and-evaluate-148.htm' rel='bookmark' title='Permanent Link: CobiT Domain &#8211; Monitor and Evaluate'>CobiT Domain &#8211; Monitor and Evaluate</a> <small>The fourth domain in CobiT is Monitor and Evaluate (ME). It is made up of 4 processes and 25 control...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds1-define-and-manage-service-levels-235.htm' rel='bookmark' title='Permanent Link: DS1 Define and Manage Service Levels'>DS1 Define and Manage Service Levels</a> <small>CobiT definition: Effective communication between IT management and business customers regarding services required is enabled by a documented definition of...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring and reporting of control exceptions, results of self-assessments and third-party reviews. A key benefit of internal control monitoring is to provide assurance regarding effective and efficient operations and compliance with applicable laws and regulations.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Monitor and evaluate internal control</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
protecting the achievement of IT objectives and complying with IT-related laws, regulations and contracts</p>
<p><strong>by focusing on</strong><br />
monitoring the internal control processes for IT-related activities and identifying improvement actions</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Defining a system of internal controls embedded in the IT process framework</li>
<li>Monitoring and reporting on the effectiveness of the internal controls over IT</li>
<li>Reporting control exceptions to management for action</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Number of major internal control breaches</li>
<li>Number of control improvement initiatives</li>
<li>Number and coverage of control self-assessments</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME2 Monitor and Evaluate Internal Control</strong></p>
<p>ME2.1 Monitoring of Internal Control Framework<br />
ME2.2 Supervisory Review<br />
ME2.3 Control Exceptions<br />
ME2.4 Control Self-assessment<br />
ME2.5 Assurance of Internal Control<br />
ME2.6 Internal Control at Third Parties<br />
ME2.7 Remedial Actions</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm' rel='bookmark' title='Permanent Link: ME1 Monitor and Evaluate IT Performance'>ME1 Monitor and Evaluate IT Performance</a> <small>CobiT definition: Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely...</small></li>
<li><a href='http://www.itgovernanceblog.com/cobit-domain-monitor-and-evaluate-148.htm' rel='bookmark' title='Permanent Link: CobiT Domain &#8211; Monitor and Evaluate'>CobiT Domain &#8211; Monitor and Evaluate</a> <small>The fourth domain in CobiT is Monitor and Evaluate (ME). It is made up of 4 processes and 25 control...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds1-define-and-manage-service-levels-235.htm' rel='bookmark' title='Permanent Link: DS1 Define and Manage Service Levels'>DS1 Define and Manage Service Levels</a> <small>CobiT definition: Effective communication between IT management and business customers regarding services required is enabled by a documented definition of...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ME1 Monitor and Evaluate IT Performance</title>
		<link>http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm</link>
		<comments>http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:29:00 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit ME1]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[it performance]]></category>
		<category><![CDATA[monitor and evaluate]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=303</guid>
		<description><![CDATA[CobiT definition: Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely reporting of performance, and prompt acting upon deviations. Monitoring is needed to make sure that the right things are done and are in line with the set directions and policies. Control over the IT process [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
<li><a href='http://www.itgovernanceblog.com/cobit-domain-monitor-and-evaluate-148.htm' rel='bookmark' title='Permanent Link: CobiT Domain &#8211; Monitor and Evaluate'>CobiT Domain &#8211; Monitor and Evaluate</a> <small>The fourth domain in CobiT is Monitor and Evaluate (ME). It is made up of 4 processes and 25 control...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds3-manage-performance-and-capacity-245.htm' rel='bookmark' title='Permanent Link: DS3 Manage Performance and Capacity'>DS3 Manage Performance and Capacity</a> <small>CobiT definition: The need to manage performance and capacity of IT resources requires a process to periodically review current performance...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective IT performance management requires a monitoring process. This process includes defining relevant performance indicators, systematic and timely reporting of performance, and prompt acting upon deviations. Monitoring is needed to make sure that the right things are done and are in line with the set directions and policies.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Monitor and evaluate IT performance</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
transparency and understanding of IT cost, benefits, strategy, policies and service levels in accordance with governance requirements</p>
<p><strong>by focusing on</strong><br />
monitoring and reporting process metrics and identifying and implementing performance improvement actions</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Collating and translating process performance reports into management reports</li>
<li>Reviewing performance against agreed-upon targets and initiating necessary remedial action</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Satisfaction of management and the governance entity with the performance reporting</li>
<li>Number of improvement actions driven by monitoring activities</li>
<li>Percent of critical processes monitored</li>
</ul>
<p>Control objectives:</p>
<p><strong>ME1 Monitor and Evaluate IT Performance</strong></p>
<p>ME1.1 Monitoring Approach<br />
ME1.2 Definition and Collection of Monitoring Data<br />
ME1.3 Monitoring Method<br />
ME1.4 Performance Assessment<br />
ME1.5 Board and Executive Reporting<br />
ME1.6 Remedial Actions</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/me2-monitor-and-evaluate-internal-control-308.htm' rel='bookmark' title='Permanent Link: ME2 Monitor and Evaluate Internal Control'>ME2 Monitor and Evaluate Internal Control</a> <small>CobiT definition: Establishing an effective internal control programme for IT requires a well-defined monitoring process. This process includes the monitoring...</small></li>
<li><a href='http://www.itgovernanceblog.com/cobit-domain-monitor-and-evaluate-148.htm' rel='bookmark' title='Permanent Link: CobiT Domain &#8211; Monitor and Evaluate'>CobiT Domain &#8211; Monitor and Evaluate</a> <small>The fourth domain in CobiT is Monitor and Evaluate (ME). It is made up of 4 processes and 25 control...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds3-manage-performance-and-capacity-245.htm' rel='bookmark' title='Permanent Link: DS3 Manage Performance and Capacity'>DS3 Manage Performance and Capacity</a> <small>CobiT definition: The need to manage performance and capacity of IT resources requires a process to periodically review current performance...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/me1-monitor-and-evaluate-it-performance-303.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS13 Manage Operations</title>
		<link>http://www.itgovernanceblog.com/ds13-manage-operations-298.htm</link>
		<comments>http://www.itgovernanceblog.com/ds13-manage-operations-298.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:20:07 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS13]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[manage operations]]></category>
		<category><![CDATA[operations management]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=298</guid>
		<description><![CDATA[CobiT definition: Complete and accurate processing of data requires effective management of data processing procedures and diligent maintenance of hardware. This process includes defining operating policies and procedures for effective management of scheduled processing, protecting sensitive output, monitoring infrastructure performance and ensuring preventive maintenance of hardware. Effective operations management helps maintain data integrity and reduces [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds5-ensure-systems-security-257.htm' rel='bookmark' title='Permanent Link: DS5 Ensure Systems Security'>DS5 Ensure Systems Security</a> <small>CobiT definition: The need to maintain the integrity of information and protect IT assets requires a security management process. This...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds1-define-and-manage-service-levels-235.htm' rel='bookmark' title='Permanent Link: DS1 Define and Manage Service Levels'>DS1 Define and Manage Service Levels</a> <small>CobiT definition: Effective communication between IT management and business customers regarding services required is enabled by a documented definition of...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds9-manage-the-configuration-277.htm' rel='bookmark' title='Permanent Link: DS9 Manage the Configuration'>DS9 Manage the Configuration</a> <small>CobiT definition: Ensuring the integrity of hardware and software configurations requires the establishment and maintenance of an accurate and complete...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Complete and accurate processing of data requires effective management of data processing procedures and diligent maintenance of hardware. This process includes defining operating policies and procedures for effective management of scheduled processing, protecting sensitive output, monitoring infrastructure performance and ensuring preventive maintenance of hardware. Effective operations management helps maintain data integrity and reduces business delays and IT operating costs.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage operations</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
maintaining data integrity and ensuring that IT infrastructure can resist and recover from errors and failures</p>
<p><strong>by focusing on</strong><br />
meeting operational service levels for scheduled data processing, protecting sensitive output, and monitoring and maintaining infrastructure</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Operating the IT environment in line with agreed-upon service levels and defined instructions</li>
<li>Maintaining the IT infrastructure</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Number of service levels impacted by operational incidents</li>
<li>Hours of unplanned downtime caused by operational incidents</li>
<li>Percent of hardware assets included in preventive maintenance schedules</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS13 Manage Operations</strong></p>
<p>DS13.1 Operations Procedures and Instructions<br />
DS13.2 Job Scheduling<br />
DS13.3 IT Infrastructure Monitoring<br />
DS13.4 Sensitive Documents and Output Devices<br />
DS13.5 Preventive Maintenance for Hardware</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds5-ensure-systems-security-257.htm' rel='bookmark' title='Permanent Link: DS5 Ensure Systems Security'>DS5 Ensure Systems Security</a> <small>CobiT definition: The need to maintain the integrity of information and protect IT assets requires a security management process. This...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds1-define-and-manage-service-levels-235.htm' rel='bookmark' title='Permanent Link: DS1 Define and Manage Service Levels'>DS1 Define and Manage Service Levels</a> <small>CobiT definition: Effective communication between IT management and business customers regarding services required is enabled by a documented definition of...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds9-manage-the-configuration-277.htm' rel='bookmark' title='Permanent Link: DS9 Manage the Configuration'>DS9 Manage the Configuration</a> <small>CobiT definition: Ensuring the integrity of hardware and software configurations requires the establishment and maintenance of an accurate and complete...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds13-manage-operations-298.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS12 Manage the Physical Environment</title>
		<link>http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm</link>
		<comments>http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:14:41 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS12]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[physical environment management]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=293</guid>
		<description><![CDATA[CobiT definition: Protection for computer equipment and personnel requires well-designed and well-managed physical facilities. The process of managing the physical environment includes defining the physical site requirements, selecting appropriate facilities, and designing effective processes for monitoring environmental factors and managing physical access. Effective management of the physical environment reduces business interruptions from damage to computer [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds5-ensure-systems-security-257.htm' rel='bookmark' title='Permanent Link: DS5 Ensure Systems Security'>DS5 Ensure Systems Security</a> <small>CobiT definition: The need to maintain the integrity of information and protect IT assets requires a security management process. This...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds11-manage-data-288.htm' rel='bookmark' title='Permanent Link: DS11 Manage Data'>DS11 Manage Data</a> <small>CobiT definition: Effective data management requires identifying data requirements. The data management process also includes the establishment of effective procedures...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds8-manage-service-desk-and-incidents-272.htm' rel='bookmark' title='Permanent Link: DS8 Manage Service Desk and Incidents'>DS8 Manage Service Desk and Incidents</a> <small>CobiT definition: Timely and effective response to IT user queries and problems requires a well-designed and well-executed service desk and...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Protection for computer equipment and personnel requires well-designed and well-managed physical facilities. The process of managing the physical environment includes defining the physical site requirements, selecting appropriate facilities, and designing effective processes for monitoring environmental factors and managing physical access. Effective management of the physical environment reduces business interruptions from damage to computer equipment and personnel.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage the physical environment</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
protecting computer assets and business data and minimising the risk of business disruption</p>
<p><strong>by focusing on</strong><br />
providing and maintaining a suitable physical environment to protect IT assets from access, damage or theft</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Implementing physical security measures</li>
<li>Selecting and managing facilities</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Amount of downtime arising from physical environment incidents</li>
<li>Number of incidents due to physical security breaches or failures</li>
<li>Frequency of physical risk assessment and reviews</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS12 Manage the Physical Environment</strong></p>
<p>DS12.1 Site Selection and Layout<br />
DS12.2 Physical Security Measures<br />
DS12.3 Physical Access<br />
DS12.4 Protection Against Environmental Factors<br />
DS12.5 Physical Facilities Management</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds5-ensure-systems-security-257.htm' rel='bookmark' title='Permanent Link: DS5 Ensure Systems Security'>DS5 Ensure Systems Security</a> <small>CobiT definition: The need to maintain the integrity of information and protect IT assets requires a security management process. This...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds11-manage-data-288.htm' rel='bookmark' title='Permanent Link: DS11 Manage Data'>DS11 Manage Data</a> <small>CobiT definition: Effective data management requires identifying data requirements. The data management process also includes the establishment of effective procedures...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds8-manage-service-desk-and-incidents-272.htm' rel='bookmark' title='Permanent Link: DS8 Manage Service Desk and Incidents'>DS8 Manage Service Desk and Incidents</a> <small>CobiT definition: Timely and effective response to IT user queries and problems requires a well-designed and well-executed service desk and...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds12-manage-the-physical-environment-293.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS11 Manage Data</title>
		<link>http://www.itgovernanceblog.com/ds11-manage-data-288.htm</link>
		<comments>http://www.itgovernanceblog.com/ds11-manage-data-288.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:09:15 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS11]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[data management]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[manage data]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=288</guid>
		<description><![CDATA[CobiT definition: Effective data management requires identifying data requirements. The data management process also includes the establishment of effective procedures to manage the media library, backup and recovery of data, and proper disposal of media. Effective data management helps ensure the quality, timeliness and availability of business data. Control over the IT process of Manage [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds3-manage-performance-and-capacity-245.htm' rel='bookmark' title='Permanent Link: DS3 Manage Performance and Capacity'>DS3 Manage Performance and Capacity</a> <small>CobiT definition: The need to manage performance and capacity of IT resources requires a process to periodically review current performance...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds4-ensure-continuous-service-250.htm' rel='bookmark' title='Permanent Link: DS4 Ensure Continuous Service'>DS4 Ensure Continuous Service</a> <small>CobiT definition: The need for providing continuous IT services requires developing, maintaining and testing IT continuity plans, utilising offsite backup...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds9-manage-the-configuration-277.htm' rel='bookmark' title='Permanent Link: DS9 Manage the Configuration'>DS9 Manage the Configuration</a> <small>CobiT definition: Ensuring the integrity of hardware and software configurations requires the establishment and maintenance of an accurate and complete...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective data management requires identifying data requirements. The data management process also includes the establishment of effective procedures to manage the media library, backup and recovery of data, and proper disposal of media. Effective data management helps ensure the quality, timeliness and availability of business data.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage data</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
optimising the use of information and ensuring that information is available as required</p>
<p><strong>by focusing on</strong><br />
maintaining the completeness, accuracy, availability and protection of data</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Backing up data and testing restoration</li>
<li>Managing onsite and offsite storage of data</li>
<li>Securely disposing of data and equipment</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Percent of user satisfaction with availability of data</li>
<li>Percent of successful data restorations</li>
<li>Number of incidents where sensitive data were retrieved after media were disposed</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS11 Manage Data</strong></p>
<p>DS11.1 Business Requirements for Data Management<br />
DS11.2 Storage and Retention Arrangements<br />
DS11.3 Media Library Management System<br />
DS11.4 Disposal<br />
DS11.5 Backup and Restoration<br />
DS11.6 Security Requirements for Data Management</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds3-manage-performance-and-capacity-245.htm' rel='bookmark' title='Permanent Link: DS3 Manage Performance and Capacity'>DS3 Manage Performance and Capacity</a> <small>CobiT definition: The need to manage performance and capacity of IT resources requires a process to periodically review current performance...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds4-ensure-continuous-service-250.htm' rel='bookmark' title='Permanent Link: DS4 Ensure Continuous Service'>DS4 Ensure Continuous Service</a> <small>CobiT definition: The need for providing continuous IT services requires developing, maintaining and testing IT continuity plans, utilising offsite backup...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds9-manage-the-configuration-277.htm' rel='bookmark' title='Permanent Link: DS9 Manage the Configuration'>DS9 Manage the Configuration</a> <small>CobiT definition: Ensuring the integrity of hardware and software configurations requires the establishment and maintenance of an accurate and complete...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds11-manage-data-288.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS10 Manage Problems</title>
		<link>http://www.itgovernanceblog.com/ds10-manage-problems-283.htm</link>
		<comments>http://www.itgovernanceblog.com/ds10-manage-problems-283.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 17:01:20 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS10]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[manage problems]]></category>
		<category><![CDATA[problem management]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=283</guid>
		<description><![CDATA[CobiT definition: Effective problem management requires the identification and classification of problems, root cause analysis and resolution of problems. The problem management process also includes the formulation of recommendations for improvement, maintenance of problem records and review of the status of corrective actions. An effective problem management process maximises system availability, improves service levels, reduces [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds8-manage-service-desk-and-incidents-272.htm' rel='bookmark' title='Permanent Link: DS8 Manage Service Desk and Incidents'>DS8 Manage Service Desk and Incidents</a> <small>CobiT definition: Timely and effective response to IT user queries and problems requires a well-designed and well-executed service desk and...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds1-define-and-manage-service-levels-235.htm' rel='bookmark' title='Permanent Link: DS1 Define and Manage Service Levels'>DS1 Define and Manage Service Levels</a> <small>CobiT definition: Effective communication between IT management and business customers regarding services required is enabled by a documented definition of...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds2-manage-third-party-services-240.htm' rel='bookmark' title='Permanent Link: DS2 Manage Third-party Services'>DS2 Manage Third-party Services</a> <small>CobiT definition: The need to assure that services provided by third parties (suppliers, vendors and partners) meet business requirements requires...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Effective problem management requires the identification and classification of problems, root cause analysis and resolution of problems. The problem management process also includes the formulation of recommendations for improvement, maintenance of problem records and review of the status of corrective actions. An effective problem management process maximises system availability, improves service levels, reduces costs, and improves customer convenience and satisfaction.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage problems</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
ensuring end users’ satisfaction with service offerings and service levels, and reducing solution and service delivery defects and rework</p>
<p><strong>by focusing on</strong><br />
recording, tracking and resolving operational problems; investigating the root cause of all significant problems; and defining solutions for identified operations problems</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Performing root cause analysis of reported problems</li>
<li>Analysing trends</li>
<li>Taking ownership of problems and progressing problem resolution</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Number of recurring problems with an impact on the business</li>
<li>Percent of problems resolved within the required time period</li>
<li>Frequency of reports or updates to an ongoing problem, based on the problem severity</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS10 Manage Problems</strong></p>
<p>DS10.1 Identification and Classification of Problems<br />
DS10.2 Problem Tracking and Resolution<br />
DS10.3 Problem Closure<br />
DS10.4 Integration of Configuration, Incident and Problem Management</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds8-manage-service-desk-and-incidents-272.htm' rel='bookmark' title='Permanent Link: DS8 Manage Service Desk and Incidents'>DS8 Manage Service Desk and Incidents</a> <small>CobiT definition: Timely and effective response to IT user queries and problems requires a well-designed and well-executed service desk and...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds1-define-and-manage-service-levels-235.htm' rel='bookmark' title='Permanent Link: DS1 Define and Manage Service Levels'>DS1 Define and Manage Service Levels</a> <small>CobiT definition: Effective communication between IT management and business customers regarding services required is enabled by a documented definition of...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds2-manage-third-party-services-240.htm' rel='bookmark' title='Permanent Link: DS2 Manage Third-party Services'>DS2 Manage Third-party Services</a> <small>CobiT definition: The need to assure that services provided by third parties (suppliers, vendors and partners) meet business requirements requires...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds10-manage-problems-283.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DS9 Manage the Configuration</title>
		<link>http://www.itgovernanceblog.com/ds9-manage-the-configuration-277.htm</link>
		<comments>http://www.itgovernanceblog.com/ds9-manage-the-configuration-277.htm#comments</comments>
		<pubDate>Sat, 16 Jan 2010 16:55:56 +0000</pubDate>
		<dc:creator>Bill Oxley</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[cobit DS9]]></category>
		<category><![CDATA[configuration management]]></category>
		<category><![CDATA[control objective]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[it governance]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.itgovernanceblog.com/?p=277</guid>
		<description><![CDATA[CobiT definition: Ensuring the integrity of hardware and software configurations requires the establishment and maintenance of an accurate and complete configuration repository. This process includes collecting initial configuration information, establishing baselines, verifying and auditing configuration information, and updating the configuration repository as needed. Effective configuration management facilitates greater system availability, minimises production issues and resolves [...]


Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds5-ensure-systems-security-257.htm' rel='bookmark' title='Permanent Link: DS5 Ensure Systems Security'>DS5 Ensure Systems Security</a> <small>CobiT definition: The need to maintain the integrity of information and protect IT assets requires a security management process. This...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds6-identify-and-allocate-costs-262.htm' rel='bookmark' title='Permanent Link: DS6 Identify and Allocate Costs'>DS6 Identify and Allocate Costs</a> <small>CobiT definition: The need for a fair and equitable system of allocating IT costs to the business requires accurate measurement...</small></li>
<li><a href='http://www.itgovernanceblog.com/ai6-manage-changes-224.htm' rel='bookmark' title='Permanent Link: AI6 Manage Changes'>AI6 Manage Changes</a> <small>CobiT definition: All changes, including emergency maintenance and patches, relating to infrastructure and applications within the production environment are formally...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>CobiT</strong> definition:</p>
<blockquote><p>Ensuring the integrity of hardware and software configurations requires the establishment and maintenance of an accurate and complete configuration repository. This process includes collecting initial configuration information, establishing baselines, verifying and auditing configuration information, and updating the configuration repository as needed. Effective configuration management facilitates greater system availability, minimises production issues and resolves issues more quickly.</p></blockquote>
<p><strong>Control over the IT process of</strong><br />
Manage the configuration</p>
<p><strong>that satisfies the business requirement for IT of</strong><br />
optimising the IT infrastructure, resources and capabilities, and accounting for IT assets</p>
<p><strong>by focusing on</strong><br />
establishing and maintaining an accurate and complete repository of asset configuration attributes and baselines, and comparing them against actual asset configuration</p>
<p><strong>is achieved by</strong></p>
<ul>
<li>Establishing a central repository of all configuration items</li>
<li>Identifying configuration items and maintaining them</li>
<li>Reviewing integrity of configuration data</li>
</ul>
<p><strong>and is measured by</strong></p>
<ul>
<li>Number of business compliance issues caused by improper configuration of assets</li>
<li>Number of deviations identified between the configuration repository and actual asset configurations</li>
<li>Percent of licences purchased and not accounted for in the repository</li>
</ul>
<p>Control objectives:</p>
<p><strong>DS9 Manage the Configuration</strong></p>
<p>DS9.1 Configuration Repository and Baseline<br />
DS9.2 Identification and Maintenance of Configuration Items<br />
DS9.3 Configuration Integrity Review</p>
<p>Check out the links for details on the control objectives.</p>


<p>Related posts:<ol><li><a href='http://www.itgovernanceblog.com/ds5-ensure-systems-security-257.htm' rel='bookmark' title='Permanent Link: DS5 Ensure Systems Security'>DS5 Ensure Systems Security</a> <small>CobiT definition: The need to maintain the integrity of information and protect IT assets requires a security management process. This...</small></li>
<li><a href='http://www.itgovernanceblog.com/ds6-identify-and-allocate-costs-262.htm' rel='bookmark' title='Permanent Link: DS6 Identify and Allocate Costs'>DS6 Identify and Allocate Costs</a> <small>CobiT definition: The need for a fair and equitable system of allocating IT costs to the business requires accurate measurement...</small></li>
<li><a href='http://www.itgovernanceblog.com/ai6-manage-changes-224.htm' rel='bookmark' title='Permanent Link: AI6 Manage Changes'>AI6 Manage Changes</a> <small>CobiT definition: All changes, including emergency maintenance and patches, relating to infrastructure and applications within the production environment are formally...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.itgovernanceblog.com/ds9-manage-the-configuration-277.htm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
