Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

Control: Control Objectives For Information and Related Technologies

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 16

CONTROL

OBJECTIVES for
INFORMATION
and RELATED
TECHNOLOGIES
SLIDESMANIA.CO

IT General Controls and COBIT


HELLO! WE ARE YOUR
TODAY’S STUDENT
TEACHER.
RAPHAIE PABROA & CHRISTINE
SIGUANO
4th year BSA students.
SLIDESMANIA.CO
OBJECTIVES:

⬤ Understand what is COBIT and its brief history.

⬤ Understand major pervasive controls in controlling information

system.

⬤ Know major controls used to manage the design and

implementation of new processes, especially new IT processes.


SLIDESMANIA.CO
WHAT IS COBIT?

COBIT is an IT management framework developed by the


ISACA to help businesses develop, organize and implement
strategies around information management and
governance.
SLIDESMANIA.CO
Did you know?
● First released in 1996

● In 1998, the ISACA released version 2 ● In 2012, COBIT 5 was released and in
2013, the ISACA released an add-on to
COBIT 5
● Later, in the 2000s, the ISACA developed
version 3 ● Updated version of COBIT in 2018
ditching the version number and naming
it COBIT 2019
● COBIT 4 was released in 2005, followed
by COBIT 4.1 in 2007
SLIDESMANIA.CO
COBIT provides a framework to ensure that:

- IT is aligned with the business


- IT enables the business and maximizes benefits
- IT resources are used responsible
- IT risks are managed appropriatel
SLIDESMANIA.CO
SLIDESMANIA.CO
HOW COBIT HELPS
Here are some of the problems that the company is facing and their COBIT-provided solutions:

General problems COBIT’s aid


1. The organization of IT is inefficient, 1. The ability for business leaders to
doesn’t meet business goals and seems prioritize their IT needs and work out
outdated. corresponding plans.
2. The company frequently fails audits by 2. A clear system of benchmarks.
potential partners.
3. Long-term partners tend to stop using 3. Stability and new software.
the company’s services and prefer
working with their rivals
SLIDESMANIA.CO
IT Resources
1. Applications
Automated systems or manual procedures that process information

2. Information
Data, in all their forms, that are input, processed, and output by information
systems

3. Infrastructure
Technology and facilities that enable the processing of the applications.

4. People
SLIDESMANIA.CO

Personnel who plan, organize, acquire, deliver, support, monitor, and


evaluate information systems and services.
COBIT’s Definition for control:
The policies, procedures, practices, and organizational
structures designed to provide reasonable assurance that
business objectives will be achieved and that undesired
events will be prevented or detected and corrected.
SLIDESMANIA.CO

This is where you section ends. Duplicate this set of slides as many times you need to go over all your sections.
COBIT’s Four Broad IT
SLIDESMANIA.CO

Control Process Domains


IT Process 1 : Establish strategic vision for IT

• Summary of the organizational strategic plan’s goals and strategies, and how they relate to IT.
• IT goals and strategies, and a statement of how each will support organizational goals and strategies.

IT Process 2 : Develop tactics to plan, communicate, and manage realization of


the strategic vision.
• Manage IT resources.
• Policies consistent with the control environment established by senior management.

IT Process 3: Identify automated solutions


• Solutions should be consistent with the strategic IT plan
SLIDESMANIA.CO
IT Process 4: Develop and acquire IT Solutions

• Develop and acquire application software


• Acquire technology infrastructure

IT Process 5: Integrate IT Solutions into Operational Processes


• Provide for a planned, tested, controlled, and approved conversion to the new system.
• After installation review to determine that the new system has met users needs in a cost-effective manner.

IT Process 6: Manage changes to existing IT Systems

• Changes to the IT infrastructure must be managed via change request, impact assessment,
documentation, authorization, release and distribution policies, and procedures.
• Program change controls provide assurance that all modifications to programs are authorized, and
SLIDESMANIA.CO

that changes are completed, tested, and properly implemented.


IT Process 7: Deliver required IT Services
• Define service levels
• Manage third-party services

IT Process 8: Ensure security and continuous service


• Ensure Continuous Service
• Secure IT Assets

IT Process 9: Provide Support Services


• Identify training needs of all personnel
• Conduct timely training sessions.

IT Process 10: Monitor and Evaluate the Process


• Establish a system for defining service indicators
• Gather data about processes
SLIDESMANIA.CO
Trust Service Principles

Pervasive Control Plans are


particularly important because
they operate across all business
processes and affect a
company’s capability to meet a
multitude of control goals.
SLIDESMANIA.CO
THANK
YOU!
Do you have any questions?
And that ends our
discussion for today.
SLIDESMANIA.CO

You might also like