Subscribe
  • Home
  • /
  • Business
  • /
  • ISACA helps enterprises manage vendors using the COBIT 5 framework

ISACA helps enterprises manage vendors using the COBIT 5 framework

New guide provides sample SLAs, case studies and mappings.


Rolling Meadows, Illinois, USA, 29 Jul 2013

As enterprises increasingly rely on cloud service providers and other vendors to provide fundamental services, the related risk becomes more significant. Global IT association ISACA has released a new guide applying the internationally accepted COBIT 5 governance framework to help enterprises effectively manage vendors.

Vendor Management: Using COBIT 5 provides practical action items for all stakeholders involved in the vendor-management process, from the board and C-level executives, to the legal department and IT. It outlines:

* Life cycle stages and stakeholders
* Good practices to manage threats and risk
* How to manage a cloud service provider
* Practical service level agreement (SLA) templates, checklists and examples (available for download in an online toolkit)
* A case study outlining the consequences of ineffective vendor management
* A high-level mapping of COBIT 5 and ITIL V3 for vendor management

"Recent research from the IT Policy Compliance Group reveals that approximately one out of five enterprises do not invest sufficient effort to manage vendors and vendor-provided services effectively," said Nikolaos Zacharopoulos, CISA, CISSP, senior IT auditor at DeutschePost-DHL, and member of ISACA's Guidance and Practices Committee. "This means enterprise requirements and standards are not properly incorporated into vendor contracts, ownership of information being handled by vendors remains unclear, and access to information is not guaranteed if the vendors go out of business."

The ISACA publication emphasises that IT vendor management is not solely IT's responsibility, and clarifies the responsibilities of stakeholders within the enterprise.

"As companies worldwide are turning toward fewer - but much more integrated - vendors, they are benefiting from a single point of contact. However, they are simultaneously increasing risk to the enterprise, and that risk needs to be managed rigorously by all stakeholders," said Zacharopoulos. "The COBIT 5 framework provides tested guidance to help them effectively govern these relationships so they deliver maximum value with minimum risk."

Vendor Management: Using COBIT 5 and a related online toolkit are available at www.isaca.org/vendor-management. ISACA members can download the ebook and toolkit free of charge. The COBIT 5 framework publication is available as a free download at www.isaca.org/cobit.

ISACA South Africa will provide deeper insight into using Cobit 5 across the enterprise at the ISACA Annual Conference, to be held at Emperors Palace, on 26and 27 August. Further, a one-day, post-conference workshop on "COBIT 5 insights" will be presented by COBIT guru Gary Hardy on 28 August.

Share

ISACA

With more than 110 000 constituents in 180 countries, ISACA (www.isaca.org) helps business and IT leaders maximise value and manage risk related to information and technology. Founded in 1969, the non-profit, independent ISACA is an advocate for professionals involved in information security, assurance, risk management and governance. These professionals rely on ISACA as the trusted source for information and technology knowledge, community, standards and certification. The association, which has 200 chapters worldwide, advances and validates business-critical skills and knowledge through the globally respected Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in the Governance of Enterprise IT (CGEIT) and Certified in Risk and Information Systems Control (CRISC) credentials. ISACA also developed and continually updates COBIT, a business framework that helps enterprises in all industries and geographies govern and manage their information and technology.

Participate in the ISACA Knowledge Center: www.isaca.org/knowledge-center
Follow ISACA South Africa on Twitter: https://twitter.com/ISACAZA
Join ISACA on LinkedIn: ISACA (Official), http://linkd.in/ISACAOff
Like ISACA on Facebook: www.facebook.com/ISACAZA

Contact ISACA South Africa:
E-mail: admin@isaca.org.za

www.isaca.org.za
Phone: (+27) 11 582 9622
Facsimile: 086 684 2979

Editorial contacts

Winston Hayden
ISACA
president@isaca.org.za