Design Guide Chapter 1 - 3 Flashcards
A Governance or management objective
Always relates to one objective
A governance objetive relates to a
Governance process
A management objective relates to a
Management process
Boards and executive management are typically accountable for
Governance Process
Management processes are the domain of
Senior and Middle Management
Governance Objectives are grouped in
Evaluate, Direct and Monitor (EDM)
EDM - Evaluate, Direct and Monitor
Governing body evaluates strategic options, directs senior management and monitors the achievement of the strategy
Management objectives are
APO - Align, Plan, and Organize
BAI - Build Acquire, and Implement
DSS - Deliver, Service, and Support
MEA - Monitor, Evaluate and Assess
APO
Align, Plan, and Organize - Addresses the overall organization, Strategy, and supporting activities for I&T
BAI
Build, Acquire, and Implement - treats the definition, acquisition, and implementation of I&T solutions and their integration in the business process.
DSS
Deliver, Service, and Support - Addresses operational delivery and support of I&T services, including security.
MEA
Monitor, Evaluate, and Assess - Addresses performance monitoring and conformance of I&T with internal performance targets, internal control objectives and external requirements.
EDM01
Ensured governance framework setting and maintenance
EDM02
Ensured benefits delivery
EDM03
Ensured risk optimization
EDM04
Ensured resource optimization
EDM05
Ensured stakeholder engagement
APO01
Managed I&T Management Framework
APO02
Managed Strategy
APO3
Managed Enterprise Arquitecture
APO04
Managed Innovation
APO05
Managed Portfolio
APO06
Managed Budget and Costs
APO07
Managed Human Resources
APO08
Managed Relationships
APO09
Managed Service Agreements
APO10
Managed Vendors
APO11
Managed Quality
APO12
Managed Risks
APO13
Managed Security
APO14
Managed Data
BAI01
Managed Programs
BAI02
Managed Requirement Definitions
BAI03
Managed Solution Identification and build
BAI04
Managed Availability and Capacity
BAI05
Managed Organization Change
BAI06
Managed IT Changes
BAI07
Managed IT Change Acceptance and Transitioning
BAI08
Managed Knowledge
BAI09
Managed Assets
BAI10
Managed Configuration
BAI11
Management Projects
DSS01
Managed Operations
DSS02
Managed Service Requests and Incidents
DSS03
Managed Problems
DSS04
Managed Continuity
DSS05
Managed Security Service
DSS06
Managed Business Process Control
MEA01
Managed Performance and Conforming Monitoring
MEA02
Managed System and Internal Control
MEA03
Managed Compliance with External Requirements
MEA04
Managed Assurance
Components are factors that
Individually and collectively, contribute to the good operations of the enterprises governance system over I&T
Components interact with each other
resulting in a holistic governance system for I&T
Components can be of different types:
Processes; Organizational Structures; Policies and Procedures; Information items; Culture and behavior; Skills and Competencies; and services, infrastructure, and applications.
Generic Component are
the described in the COBIT Core Model; apply in any situation, but need to be customized.
Variant Components are
based on generic components but tailored for a specific context or purpose within a focus area.
Focus Area
Describe a certain governance topic, domain or issue that can be addressed by a collection of governance and management objectives and their governance.
Examples of Focus Areas
Small and Middle Enterprises;
Cybersecurity;
Digital Transformation;
Cloud Computing;
Privacy;
DevOps.
Capability Levels (CMMI - Capability Mature Model Integration)
Measure for how well a process is implemented and performing.