System Design and Other elements Flashcards
What is COBIT?
COBIT - Control Objectives for Information and Related Technology framework was created by the information Systems Audit and Control Association - ISACA and the IT Governance Institute (ITGI) in 1992. It has been updated several times as technology changes. COBIT 5 was released in 2012 - the most recent.
What does COBIT entails?
The framework provides managers, auditors, and IT users with a set of measures, indicators, processes and best practices to maximize the benefit of information technology.
In addition, the COBIT framework is intended to assist in the development of appropriate IT governance and IT management within an organization.
Hows if the COBIT framework is organized?
The framework is organizes as follows:
- Business Objectives
- Governance Objectives
- Information Criteria
- IT Resources
- Domains and Processes of COBIT
What are the Business Objectives of COBIT?
Might include, but not limited to:
- Effective decision support
- Efficient transaction processing
- Compliance with either reporting requirements (tax) or information security requirements.
What are the Governance Objectives of COBIT?
The framework anticipates that IT governance will reframed by the following 5 focus areas:
- STRATEGIC ALIGNMENT - linkage between business and IT plans. Includes defining, maintaining, and validating the IT value proposition, with a focus on customer satisfaction.
- VALUE DELIVERY - includes the provision by IT of promised benefits to the organization, while satisfying its customers and optimizing costs.
- RESOURCE MANAGEMENT - focuses on the optimization of knowledge and infrastructure.
- RISK MANAGEMENT - risk awareness by sr. management, characterized by understanding risk appetite and risk management responsibilities (event ID, risk assessment, and responses). Risk management begins with identification of risk, followed by determining how the company will respond to risk. The company can avoid, mitigate, share, or ignore.
- PERFORMANCE MEASUREMENT - include tracking and monitoring strategy implementation, project completion, resource usage,process performance, and service delivery. It is important to define milestones and/or deliverables trough the project so that progress toward completion can be measured.
What are the Information Criteria of COBIT?
the business requirements for information (ICE RACE) Integrity Confidentiality Efficiency Reliability Availability Compliance Effectiveness
What are the IT Resources of COBIT?
IT uses clearly defined processes to deploy people skills and technology infrastructure to run automated business applications and leverage business information. The resources and the processes are collectively referred to as enterprise architecture for IT.
- application
- Information
- Infrastructure
- People
What are the Domains and Processes of COBIT?
COBIT defines IT processes within the context of 4 domains that direct the delivery of solutions and services and ensure that directions are followed.
PO - Plan and Organize - provides direction to solution
and service delivery
AI - Acquire and Implement - provides solution of IT
needs
DS - Deliver and Support - provides svcs - translate
solution into svs received.
ME - Monitor and Evaluate - Ensure direction provided
in the planning and organizing
steps are followed in the
solution and svs processes
What are the controls in IT’s Control Monitoring?
They are:
- General and Applications controls
- Input controls
- Processing controls
- Output controls
- Managing the control activities
What are the General and Application controls in control monitoring?
GC tend to be system wide, they are designed to ensure that an organization’s control environment is stable and well-managed, and include:
a. System development standards
b. Security management controls
c. Change management procedures
d. Software acquisition, development, operations, and maintenance.
AC focus on specific application, they prevent, detect, and correct transaction errors and fraud, providing reasonable assurance as to system:
a. Accuracy
b. Completeness
c. Validity
d. Authorization
What are the Input Controls in Control Monitoring?
The following source data controls regulate the integrity of input, which crucial to accurate and complete output.
- Data validation at the field level - edit checks, meaningful error messages, input masks, etc.
- Pre numbering forms - input is accounted for, no duplicates exist.
- Well-defined source data preparation procedures