The COBIT Model of IT Governance and Management Flashcards
What is the COBIT Model? What is the purpose the framework?
The purpose is to align IT with business goals/strategies
Link business risks, control needs, and IT
Common language for users, auditors, management, and business process owners in identifying risks and structuring controls
Purpose:
- How much should we invest?
What is the basic COBIT framework?
- To provide information that the organization needs to achieve its objectives, IT resources need to be managed by a set of naturally grouped processes.
The framework is an ongoing process that repeats starting with:
1) Business requirements
2) IT Resources
3) IT Processes
What do COSO and COBIT have in common?
Monitoring and evaluation
What are the seven desired attributes of COBIT?
Information (seven desired attributes)
1) Effective
2) Efficient
3) Confidential
4) Integrity
5) Available
6) Complaint
7) Reliable
According to COBIT there are five IT Resources…?
1) Data
2) Application systems
3) Technology
4) Facilities
5) People
COSO is bigger focused than COBIT, what is the COSO focus?
organizational controls and processes.
COBIT (BIT SMALLER): IT controls and processes
What is the monitor and evaluate processes ob COBIT? What are the topics?
includes:
- Regularly assess IT Processes for quality and compliance
- Includes management oversight of controls and independent assurance
Topcis:
- Assessment over time, delivering assurance
- Management oversight of the control system
- Performance measurement
Questions to think about?
- Can IT performance be measured and corrected?
- Need independent assurance in critical areas?
What are the four processes of monitor and evaluation?
Monitor the processes
Access internal control adequacy
Obtain independent assurance
Provide for independent audit