Module 3: Governance System and Components Flashcards
Which are the 3 Basic Concepts as they related to Governance and Management Objectives
- A governance or management objective always relates to one process and a series of related components of other types to help to achieve the objective
- A governance objective relates to a governance process, A management objective relates to a management process
- Governance processes are typically under the accountability of boards and executive management, management processes are the domain of senior and middle management
Describe the COBIT2019 Core
COBIT2019 Core consists of 40 governance and management objectives, which are organized into five domains - 1 Governance domain and 4 Management domains. Each of the governance and management objectives relates to a process
Name the 5 domains for Governance and Management Objectives
Governance Objective: 1. EDM = Evaluate, Direct and Monitor Management Objective: 2. APO = Align, Plan and Organize 3. BAI = Build, Acquire and Implement 4. DSS = Deliver, Service and Support 5. MEA = Monitor, Evaluate and Assess
What does the Governance and Management domain names represent
The names are verbs, that express the key purpose and areas of activity of the objective
What is addressed in EDM?
EDM - Governance Objective: The governing body evaluates strategic options, directs senior managment on the chosen strategic options and monitors achievement of the strategy
What is addressed in APO?
APO - Management Objective: Addresses overall organizational strategy and supporting activities of IandT
What is addressed in BAI?
BAI- Management Objective: Definition, acquisition and implementation of IandT solutions, and integration into business processes
What is addressed in DSS?
DSS- Management Objective: Operational Delivery and Support of IandT services, including security
What is addressed in MEA?
MEA- Management Objective: Performance Monitoring and conformance of IandT with internal performance targets, control objectives and external requirements.
What is the breakdown of the 40 objectives and their processes
Governance Objective: 1 Domain - EDM - 5 governance objectives Management Objectives: 4 Domains APO: 14 management objectives BAI: 11 management objectives DSS: 6 management objectives MEA: 4 management objectives
What is required to satisfy the Governance and Management Objectives
Each enterprise must establish, tailor and sustain a governance system build from components
What are Governance system Components?
Components are factors that individually and collectively contribute to the good of the operations of the enterprise’s governance system over IandT
Name the 7 Components of a Governance System
- Processes: Describe set of practices and activities to achieve objectives and produce outputs to achieve IandT goals
- Organizational Structures: Key decision making entities within the enterpise
- Information: All information used and produced within the enterpise - COBIT focuses on the information required for effective functioning of the governance system of the enterprise
- People, skills and competencies: Required for decisions, corrective actions and completion of activities
- Culture, ethics and behavior: Factors contributing the the success of the enterprise governance and management activities
- Principles, policies and frameworks: translation into practical activities and processes for guidance for day-to-day management
- Services, infrastructure and applications: All services, technology and infrastructure required to provide the enterprise with governance system for IandT
What are FOCUS areas?
FOCUS areas are specific areas of focus or importance for the enterprise. Focus area is a specific governance topic, domain or issue. Examples - Security, SME, Cloud Computing
What are DESIGN factors?
Design factors can guide the design of an enterprise’s governance system. These are parameters that assist in tailoring the governance system to align with enterprise specific needs.
Examples: Enterprise Strategy, Enterprise goals, Risk profile, threat landscape (PESTLE), Role of IT, IT sourcing model
Name the 11 Design Factors
- Enterprise Strategy
- Enterprise Goals
- Risk Profile
- IandT related Issues
- Threat Landscape
- Compliance Requirements
- Role of IT
- Sourcing Model of IT
- IT implementation methods
- IT Technology Adoption Strategy
- Enterprise Size