Subscribe
About
  • Home
  • /
  • Enterprise Solutions
  • /
  • New guide aligning Cobit 4.1, ITIL V3 and ISO 27002 helps enterprises achieve maximum governance and value i...

New guide aligning Cobit 4.1, ITIL V3 and ISO 27002 helps enterprises achieve maximum governance and value in a volatile economy

In the current economy, enterprises worldwide are struggling to achieve growth and governance at an affordable cost without compromising the business, its customers, and the integrity and security of their information systems. To help them accomplish this daunting task, the non-profit, independent IT Governance Institute (ITGI), in conjunction with the UK Office of Government Commerce (OGC), has released Aligning Control Objectives for Information and related Technology (Cobit) 4.1, IT Infrastructure Library (ITIL) V3 and ISO/IEC 27002 for Business Benefit, a complimentary guide on how to use these frameworks and standards together for maximum governance and value.

The publication is available as a free download at http://www.isaca.org/COBITmappings.

“This guidance helps enterprises implement effective and transparent governance without reinventing the wheel,” said Gary Hardy, CGEIT, a founder of the ITGI Cobit Steering Committee. “Enterprises should use Cobit as an overall control framework to focus on priority areas and quick wins and ITIL and ISO/IEC 27002 to provide more detailed guidance regarding service management and security. This will ensure both breadth and depth of governance that is efficient to deploy.”

Cobit is a globally accepted set of tools organised into a framework that executives and IT professionals at all organisations can use to ensure their information technology (IT) is helping them achieve their goals and objectives. Based on industry standards and best practices, Cobit enables enterprises to direct their IT for optimal advantage, reduce IT-related risks and increase confidence in the information provided by IT. It enables clear policy development and good practice for IT management, increases the value organisations can attain from IT and helps manage compliance. Cobit 4.1 is freely available for download from www.itgi.org.

Developed by the OGC, ITIL is the most widely accepted best practice for IT service management. Version 3 consists of 27 detailed processes organised into five high-level processes described in five core publications. ITIL V3 also introduced the concept of the service life cycle, which is described in the sixth ITIL publication.

Published by the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC), ISO/IEC 27002:2005 provides a standard for developing and maintaining security standards and management practice to improve information security management.

Aligning Cobit 4.1, ITIL V3 and ISO/IEC 27002 is of particular value for enterprises that are undergoing change or restructure.

“In merger and acquisition situations, the mappings of Cobit to other frameworks and standards, including ITIL and ISO/IEC 27002, are especially helpful,” said Robert Stroud, international vice-president of ITGI and IT governance evangelist at CA. “If the other organisation involved uses a different standard or guidance, the mapping clarifies how processes from both organisations fit together.”

Share

ITGI

The IT Governance Institute (ITGI) (www.itgi.org) is a non-profit, independent research entity that provides guidance for the global business community on issues related to the governance of IT assets. ITGI was established by the non-profit membership association Isaca in 1998 to help ensure that IT delivers value and its risks are mitigated through alignment with enterprise objectives, IT resources are properly managed, and IT performance is measured. ITGI developed Cobit and Val IT, and offers original research and case studies to help enterprise leaders and boards of directors fulfil their IT governance responsibilities and help IT professionals deliver value-adding services.

Isaca

With more than 86 000 constituents in more than 160 countries, ISACA (www.isaca.org) is a recognised worldwide leader in IT governance, control, security and assurance. Founded in 1969, ISACA sponsors international conferences, publishes the Information Systems Control Journal, and develops international information systems auditing and control standards. It also administers the globally respected Certified Information Systems Auditor designation, earned by more than 60 000 professionals since 1978; the Certified Information Security Manager designation, earned by more than 9 000 professionals since 2002; and the new Certified in the Governance of Enterprise IT designation.