Jump to content

COBIT: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
No edit summary
Line 2: Line 2:
'''COBIT''' ('''Control Objectives for Information and Related Technologies''') is a [[Software framework|framework]] created by [[ISACA]] for [[Information technology management|information technology (IT) management]] and [[Corporate governance of information technology|IT governance]]. <ref name="HaesCOBIT15">{{cite book |chapter-url=https://books.google.com/books?id=zNgRBwAAQBAJ&pg=PA102 |chapter=Chapter 5: COBIT as a Framework for Enterprise Governance of IT |title=Enterprise Governance of Information Technology: Achieving Alignment and Value, Featuring COBIT 5 |author1=Haes, S.D. |author2=Grembergen, W.V. |publisher=Springer |edition=2nd |year=2015 |pages=103–128 |isbn=9783319145471 |access-date=24 June 2016}}</ref>
'''COBIT''' ('''Control Objectives for Information and Related Technologies''') is a [[Software framework|framework]] created by [[ISACA]] for [[Information technology management|information technology (IT) management]] and [[Corporate governance of information technology|IT governance]]. <ref name="HaesCOBIT15">{{cite book |chapter-url=https://books.google.com/books?id=zNgRBwAAQBAJ&pg=PA102 |chapter=Chapter 5: COBIT as a Framework for Enterprise Governance of IT |title=Enterprise Governance of Information Technology: Achieving Alignment and Value, Featuring COBIT 5 |author1=Haes, S.D. |author2=Grembergen, W.V. |publisher=Springer |edition=2nd |year=2015 |pages=103–128 |isbn=9783319145471 |access-date=24 June 2016}}</ref>


The framework defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process-activities, process objectives, performance measures and an elementary [[Capability Maturity Model|maturity model]].<ref name="HaesCOBIT15" />
The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process-activities, process objectives, performance measures and an elementary [[Capability Maturity Model|maturity model]].<ref name="HaesCOBIT15" />


== Framework and components ==
== Framework and components ==

Revision as of 01:33, 4 June 2021

COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. [1]

The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process-activities, process objectives, performance measures and an elementary maturity model.[1]

Framework and components

Business and IT goals are linked and measured to create responsibilities of business and IT teams.

Five processes are identified: Evaluate, Direct and Monitor (EDM); Align, Plan and Organize (APO); Build, Acquire and Implement (BAI); Deliver, Service and Support (DSS); and Monitor, Evaluate and Assess (MEA).[2]

The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK.[1]

The framework helps companies follow law, be more agile and earn more.[3]

Below are COBIT components:

  • Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements.
  • Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor.
  • Control objectives: Provides a complete set of high-level requirements to be considered by management for effective control of each IT process.
  • Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes.
  • Maturity models: Assesses maturity and capability per process and helps to address gaps.

History

COBIT was initially "Control Objectives for Information and Related Technologies," though before the release of the framework people talked of "CobiT" as "Control Objectives for IT"[4] or "Control Objectives for Information and Related Technology."[5]

ISACA first released COBIT in 1996, originally as a set of control objectives[clarification needed] to help the financial audit community better maneuver in IT-related environments.[1][6] Seeing value in expanding the framework beyond just the auditing realm, ISACA released a broader version 2 in 1998 and expanded it even further by adding management guidelines in 2000's version 3. The development of both the AS 8015: Australian Standard for Corporate Governance of Information and Communication Technology in January 2005[7] and the more international draft standard ISO/IEC DIS 29382 (which soon after became ISO/IEC 38500) in January 2007[8] increased awareness of the need for more information and communication technology (ICT) governance components. ISACA inevitably added related components/frameworks with versions 4 and 4.1 in 2005 and 2007 respectively, "addressing the IT-related business processes and responsibilities in value creation (Val IT) and risk management (Risk IT)."[1][6]

COBIT 5 (2012) is based on COBIT 4.1, Val IT 2.0 and Risk IT frameworks, and draws on ISACA's IT Assurance Framework (ITAF) and the Business Model for Information Security (BMIS).[9][10]

ISACA currently offers certification tracks on both COBIT 2019 (COBIT Foundations, COBIT Design & Implementation, and Implementing the NIST Cybersecurity Framework Using COBIT 2019)[11] as well as certification in the previous version (COBIT 5).[12].

See also

References

  1. ^ a b c d e Haes, S.D.; Grembergen, W.V. (2015). "Chapter 5: COBIT as a Framework for Enterprise Governance of IT". Enterprise Governance of Information Technology: Achieving Alignment and Value, Featuring COBIT 5 (2nd ed.). Springer. pp. 103–128. ISBN 9783319145471. Retrieved 24 June 2016.
  2. ^ COBIT 2019 Framework: Introduction and Methodology from ISACA
  3. ^ Luellig, L.; Frazier, J. (2013). "A COBIT Approach to Regulatory Compliance and Defensible Disposal". ISACA Journal. 5. Retrieved 24 June 2016.
  4. ^ Katsikas, S.; Gritzalis, D., eds. (1996). Information Systems Security: Facing the Information Society of the 21st Century. IFIP Advances in Information and Communication Technology. Springer. p. 358. ISBN 9780412781209. The McCumber model has great similarities with the CobiT - Control Objectives for IT - framework (CobiT 1995).
  5. ^ "Welcome to the ISACA/F". ISACA. 18 October 1996. Archived from the original on 7 November 1996. Retrieved 24 June 2016.
  6. ^ a b Stroud, R.E. (2012). "Introduction to COBIT 5" (PDF). ISACA. Retrieved 24 June 2016.
  7. ^ da Cruz, M. (2006). "10: AS 8015-2005 - Australian Standard for Corporate Governance of ICT". In van Bon, J.; Verheijen, T. (eds.). Frameworks for IT Management. Van Haren Publishing. pp. 95–102. ISBN 9789077212905. Retrieved 23 June 2016.
  8. ^ "ISO/IEC DIS 29382: 2007 Edition, February 1, 2007". IHS Standards Store. IHS, Inc. Archived from the original on 23 June 2016. Retrieved 23 June 2016.
  9. ^ "COBIT 5 for Information Security". ISACA. Retrieved 24 June 2016.
  10. ^ "COBIT 5 for Assurance". ISACA. Retrieved 24 June 2016.
  11. ^ https://www.isaca.org/credentialing/cobit
  12. ^ https://www.isaca.org/credentialing/cobit/cobit-5-certifcates