About
Subscribe

ISO 38500 and SOA seminars added to Info Sec Africa's education portfolio

Johannesburg, 21 Jul 2008

The International Organisation for Standardisation (ISO) has released its ISO 38500 standard for IT governance. Described as a standard for "corporate governance of IT" it is aligned with the 1992 definition of Corporate Governance published in the Cadbury Report in the United Kingdom.

Peter Hill, a director of Info Sec Africa, says the release of this standard brings greater clarity to the topic of IT governance.

Currently there are almost as many definitions of IT governance as there are companies implementing IT governance. Vendors have used "IT governance" to describe a wide range of tools that have little to do with IT governance.

The ISO 38500 standard describes governance as being distinct from management and defines governance as the system used by the most senior governing body (eg, board of directors) of an organisation for directing and controlling the current and future use of IT.

ISO 38500 requires that the governance of information technology includes a management system that comprises policies, processes, structures and controls necessary to support IT to achieve the organisation's business goals. These will exist at various layers within the enterprise and are influenced by the organisational structure and the leadership provided.

Info Sec Africa has introduced a two-day seminar to assist interested organisations understand, plan and implement IT governance based on the new ISO 38500 standard. Delegates will learn more about the six guiding principles for good corporate governance of IT and the model directors should use to govern IT.

This seminar will also assist organisations that have implemented CobiT to map their current IT governance initiatives to the requirements of ISO 38500.

Delegates attending this two-day seminar will learn from practical examples and come away able to assess their current level of compliance with ISO 38500.

Hill says there is a growing awareness of the need for better governance across IT and what is required is something more than just risk management and compliance (GRC). Currently, less than 15% of organisations implementing IT governance have gone beyond GRC.

The growing popularity of service-oriented architecture (SOA) is also driving a more serious approach to governance. However, a recent Software AG survey reported that few organisations have been successful at implementing SOA governance on their own. According to Software AG, many organisations will need assistance to get SOA governance right.

Info Sec Africa recently announced the release of its SOA governance services that include training, assessments and consulting. A two-day SOA Governance seminar and a two-day SOA for Technologists seminar has also been added to the education curriculum. Events start on the 28 July. Further details can be found at www.cobit.co.za.

Hill says our advantage is that the training we provide is based on practical experience gained from working with SOA, IT governance and CobiT over a number of years. We provide participants who attend our educational events with thorough, well-researched events that are conducted by trainers with the necessary practical experience and a thorough knowledge of the subject and its practical application.

Share

Editorial contacts

Peter Hill
Info Sec Africa
(082) 558 8732
peter@cobit.co.za