SlideShare a Scribd company logo
®
COBIT 4.1 Highlights
    Dr Geoff Harmer
      Maat Consulting Ltd
         Reading, UK
    www.maatconsulting.com




                             1
Copyright Notice

 COBIT and Val IT are registered trade marks of ISACA and the IT
 Governance Institute (ITGI).
 COBIT is ©1996, 1998, 2000, 2005 IT Governance Institute. All
 rights reserved.
 ISO and the ISO logo are registered trademarks of the International
 Organisation for Standards.
 ITIL and PRINCE2 are registered trademarks of the Office of
 Government Commerce (OGC).
 This is not an official ISACA/ITGI presentation and neither ISACA
 nor ITGI endorse, sponsor, or are otherwise affiliated with this
 presentation and they do not warrant or guarantee its accuracy.
 Maat Consulting Ltd is always seeking improvements and welcomes
 comments on these materials to feedback@maatconsulting.com


                                                                       2
®
What is COBIT ?

  Best practice framework for:
    IT Governance = Performance + Conformance
    IT Audit = Conformance
  De facto framework for Compliance with:
    Sarbanes Oxley Act (2002)
    Basel II


                                                3
®                                        ®
   How COBIT developed into COBIT 4.1
                                            ®                          ®
         COBIT® 2                     COBIT 3                 COBIT 4


                                  IT Audit
          IT Audit

                               IT Governance                  IT Audit

1996                      2000                       2005                  2007
                                        WHAT
Based on a               Management               Alignment   Linking of   COBIT®
range of                 guidelines               with        Business     4.1
International            developed                ITIL &      &
                                        HOW
Standards                                         ISO 17799   IT Goals
                               Implementation
                               Guidance for
                                                                  VAL-IT™
                               Large businesses
                               & SMEs
                                                                  Framework
                                                                  Mappings          4
®
COBIT Framework - Overview

  34 high level processes in 4 process domains
    Plan and Organise (PO)
    Acquire and Implement (AI)
    Deliver and Support (DS)
    Monitor and Evaluate (ME)
  Recommends for each process:
    Control objectives
    Goals & Metrics
    RACI Chart
    Inputs and Outputs
    Maturity Model


                                                 5
What is Val IT ™?

   An ITSM framework based on COBIT®
   Extends and complements COBIT®
     From business & financial perspectives
     Right investments?
     Optimizing returns?
   Governance of IT-enabled business investments
   Processes for:
     Value delivery
     Portfolio management
     Investment management


                                                   6
®
 Basic COBIT Principle
                                             Business Objectives
                                             Governance Objectives
                                                    Integrity
                                  Confidentiality               Availability
                                 Efficiency
                                                  Business            Compliance
                             Effectiveness      Requirements
                                                                   Reliability (of information)

             Plan & Organise
                   (PO)

 Acquire &                                                               Applications
Implement          IT Processes                                                         Information
   (AI)

             Deliver &       Monitor &                          IT Resources
             Support         Evaluate
               (DS)            (ME)                                               Infrastructure
                                                                     People
                                                                                                      7
®
COBIT 4.1 Processes

                           Business
                        Requirements
                        “Information”

   Monitor and     ME
    Evaluate                             Plan and      PO
                                         Organise




                   DS
     Deliver and                    Acquire and   AI
      Support                        Implement


                                                            8
®
COBIT 4.1 Processes - PO

PO1 Define a strategic plan
PO2 Define the information architecture
PO3 Determine technological direction
PO4 Define the IT processes, organisations & relationships
PO5 Manage the IT investment
PO6 Communicate management aims and direction
PO7 Manage IT human resources
PO8 Manage quality
PO9 Assess and manage IT risks
PO10 Manage Projects


                                                             9
®
COBIT 4.1 Processes - AI

AI1   Identify automated solutions
AI2   Acquire and maintain application software
AI3   Acquire and maintain technology infrastructure
AI4   Enable operation and use
AI5   Procure IT resources
AI6   Manage changes
AI7   Install and accredit solutions and changes




                                                       10
®
COBIT 4.1 Processes - DS

DS1 Define and manage service levels
DS2 Manage third-party services
DS3 Manage performance and capacity
DS4 Ensure continuous service
DS5 Ensure systems security
DS6 Identify and allocate costs
DS7 Educate and train users
DS8 Manage service desk and incidents
DS9 Manage the configuration
DS10 Manage problems
DS11 Manage data
DS12 Manage the physical environment
DS13 Manage operations


                                        11
®
COBIT 4.1 Proceses - ME

ME1   Monitor and evaluate IT performance
ME2   Monitor and evaluate internal controls
ME3   Ensure compliance with external requirements
ME4   Provide IT governance




                                                     12
®
COBIT 4.1 uses Cascading Goals

  Business Goal

  Compliance with
  internal policies

                           IT Goal
                          Respond to
   Drives                 governance
                      requirements in line
                      with board direction Process Goal


                        Drives          Define a
                                        Strategic IT Plan




                                                            13
®
Business Goals and IT Goals in COBIT

  17 Generic Business Goals are defined
                                     Balanced
  In 4 perspectives                  Score
    Financial Perspective (3)             Card !

    Customer Perspective (6)
    Internal Perspective (6)
    Learning and Growth Perspective (2)
  A more detailed basis for Business Requirements
  Mapped to 28 IT Goals
                               ®
  In turn, mapped to 34 COBIT processes

                                                       14
Wish to learn more?
                                  ®
  Attend: 2 day ISACA COBIT Foundation Course
                          ®
    Includes ISACA COBIT Foundation Exam

                          ®
  Gain an ISACA COBIT Foundation Certificate
    40 multiple-choice questions in final hour of course
    70% to pass




                                                           15
COBIT® Training Courses

Official ISACA curriculum
            ®
     COBIT Foundation
       2 days, classroom
                                                             ™
     Implementing Governance using COBIT® & Val IT
       2 days, classroom
                                  ®
       Delegates should hold COBIT Foundation Certificate




                                                            16
Last Words on Frameworks…

  Guides not recipes
  Frameworks complement one another
        ®
  COBIT is built using ideas from >40 frameworks.
        ®
  COBIT tells you “What to do”
  The other frameworks tell you “How to do it”
        ®      ®                         ®
  COBIT , ITIL , ISO 27001 and PRINCE2 form an
 implementable group




                                                17
More Information?

  Need advice, guidance, training or consultancy on:
    COBIT
    ISO 20000
    ITIL?

  Contact us at
  info@maatconsulting.com

 View COBIT course descriptions, course schedules and
 free materials like this on our website
 www.maatconsulting.com




                                                        18
Education and Consultancy
   for IT Best Practices




                            19
Why the name Maat Consulting Ltd?

 Ma’at was the Ancient Egyptian goddess of
 order and balance.
 The main responsibility of the pharaoh was
 to preserve ma’at (order and balance) and
 prevent isfet (chaos).
 Maat Consulting Ltd helps businesses to
 achieve order and balance in their IT Service
 provision through training and consultancy
 on best practices for IT Service Management
 using ITIL®, COBIT® and ISO/IEC 20000.



                                                 20

More Related Content

PPSX
IT Governance - COBIT Perspective
PDF
What is Cobit
PDF
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
PDF
COBIT 2019 Overview_v1.1.pdf
PPTX
COBIT 5 & 4.1 Comparison
PPT
Overview of ISO 27001 ISMS
IT Governance - COBIT Perspective
What is Cobit
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
COBIT 2019 Overview_v1.1.pdf
COBIT 5 & 4.1 Comparison
Overview of ISO 27001 ISMS

What's hot (20)

PDF
cobit 2019 presentation.pdf
PPTX
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...
PDF
What is iso iec 20000
PPT
It governance
PDF
ISO27001: Implementation & Certification Process Overview
PDF
Control and audit of information System (hendri eka saputra)
PDF
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSM
PPTX
What is iso 27001 isms
PDF
What is ISO 27001 ISMS
PPTX
Introduction to COBIT 2019 and IT management
PPT
IT System & Security Audit
PDF
What is iso iec 20000
PPTX
ISO_ 27001:2022 Controls & Clauses.pptx
PPTX
Auditing SOX ITGC Compliance
PPTX
CISA Training - Chapter 5 - 2016
PPT
ISO 27001 - Information Security Management System
PPS
ISO 27001 2013 isms final overview
PPTX
IT Governance Framework
PDF
2022 Webinar - ISO 27001 Certification.pdf
PDF
Why ISO27001 For My Organisation
cobit 2019 presentation.pdf
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...
What is iso iec 20000
It governance
ISO27001: Implementation & Certification Process Overview
Control and audit of information System (hendri eka saputra)
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSM
What is iso 27001 isms
What is ISO 27001 ISMS
Introduction to COBIT 2019 and IT management
IT System & Security Audit
What is iso iec 20000
ISO_ 27001:2022 Controls & Clauses.pptx
Auditing SOX ITGC Compliance
CISA Training - Chapter 5 - 2016
ISO 27001 - Information Security Management System
ISO 27001 2013 isms final overview
IT Governance Framework
2022 Webinar - ISO 27001 Certification.pdf
Why ISO27001 For My Organisation
Ad

Viewers also liked (11)

PPT
Cobit presentation
PPT
Perbedaan cobit 4.1 dan cobit 5
PDF
Top-Down Approach to Monitoring
PPT
EFFECTIVE IT GOVERNANCE presentation
 
PPT
IT Governance Concept
PDF
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon Nam
PDF
What is IT Governance?
PPTX
Tatakelola Teknologi Informasi
PPTX
Comparison of it governance framework-COBIT, ITIL, BS7799
DOCX
Compte-rendu du panel d'experts sur COBIT - ISACA Québec (2013-11-07)
Cobit presentation
Perbedaan cobit 4.1 dan cobit 5
Top-Down Approach to Monitoring
EFFECTIVE IT GOVERNANCE presentation
 
IT Governance Concept
COBIT 5 as an IT Management Best Practices Framework - by Goh Boon Nam
What is IT Governance?
Tatakelola Teknologi Informasi
Comparison of it governance framework-COBIT, ITIL, BS7799
Compte-rendu du panel d'experts sur COBIT - ISACA Québec (2013-11-07)
Ad

Similar to Cobit 4.1 Highlights (20)

PPT
Joburg cobit assurance
PPTX
Frameworks For Predictability
PDF
Cobit as IT Management Best Practice Framework
PPTX
SUIT Showdown 2010
PDF
E-Mail Compliance Frameworks in the Real World
PDF
Valuendo cyberwar and security (jan 2012) handout
PPTX
COBIT Approach to Maintain Healthy Cyber Security Status Using NIST - CSF
PDF
EGMP - Next Practice Service
PPT
Thierry Brunet - IT best practices & frameworks overview
ODP
CobiT, Val IT & Balanced Scorecards
PPT
Cobit5 introduction
PDF
Fussion Middleware
PPT
IT frameworks
PPT
Use COBIT for IT SAVINGS
PDF
Community IT Innovators - IT Governance 083012
PPT
Information systems audit and control
PDF
Cobi T Top Down Bottom Up
PDF
Using the IVI (Innovation Value Institute) IT CMF (IT Capability Maturity Fra...
PPTX
Frameworks detail
PDF
The Enterprise Reference Architecture and Tools
Joburg cobit assurance
Frameworks For Predictability
Cobit as IT Management Best Practice Framework
SUIT Showdown 2010
E-Mail Compliance Frameworks in the Real World
Valuendo cyberwar and security (jan 2012) handout
COBIT Approach to Maintain Healthy Cyber Security Status Using NIST - CSF
EGMP - Next Practice Service
Thierry Brunet - IT best practices & frameworks overview
CobiT, Val IT & Balanced Scorecards
Cobit5 introduction
Fussion Middleware
IT frameworks
Use COBIT for IT SAVINGS
Community IT Innovators - IT Governance 083012
Information systems audit and control
Cobi T Top Down Bottom Up
Using the IVI (Innovation Value Institute) IT CMF (IT Capability Maturity Fra...
Frameworks detail
The Enterprise Reference Architecture and Tools

Recently uploaded (20)

PDF
MSPs in 10 Words - Created by US MSP Network
PDF
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
PPTX
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
PDF
A Brief Introduction About Julia Allison
PPTX
HR Introduction Slide (1).pptx on hr intro
PDF
Unit 1 Cost Accounting - Cost sheet
PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PDF
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
DOCX
unit 1 COST ACCOUNTING AND COST SHEET
PDF
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
PPTX
Lecture (1)-Introduction.pptx business communication
PDF
Training And Development of Employee .pdf
PDF
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
PPTX
Business Ethics - An introduction and its overview.pptx
PDF
Chapter 5_Foreign Exchange Market in .pdf
PPTX
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PDF
IFRS Notes in your pocket for study all the time
PPT
Data mining for business intelligence ch04 sharda
PPTX
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
MSPs in 10 Words - Created by US MSP Network
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
A Brief Introduction About Julia Allison
HR Introduction Slide (1).pptx on hr intro
Unit 1 Cost Accounting - Cost sheet
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
unit 1 COST ACCOUNTING AND COST SHEET
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
Lecture (1)-Introduction.pptx business communication
Training And Development of Employee .pdf
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
Business Ethics - An introduction and its overview.pptx
Chapter 5_Foreign Exchange Market in .pdf
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
Power and position in leadershipDOC-20250808-WA0011..pdf
IFRS Notes in your pocket for study all the time
Data mining for business intelligence ch04 sharda
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...

Cobit 4.1 Highlights

  • 1. ® COBIT 4.1 Highlights Dr Geoff Harmer Maat Consulting Ltd Reading, UK www.maatconsulting.com 1
  • 2. Copyright Notice COBIT and Val IT are registered trade marks of ISACA and the IT Governance Institute (ITGI). COBIT is ©1996, 1998, 2000, 2005 IT Governance Institute. All rights reserved. ISO and the ISO logo are registered trademarks of the International Organisation for Standards. ITIL and PRINCE2 are registered trademarks of the Office of Government Commerce (OGC). This is not an official ISACA/ITGI presentation and neither ISACA nor ITGI endorse, sponsor, or are otherwise affiliated with this presentation and they do not warrant or guarantee its accuracy. Maat Consulting Ltd is always seeking improvements and welcomes comments on these materials to feedback@maatconsulting.com 2
  • 3. ® What is COBIT ? Best practice framework for: IT Governance = Performance + Conformance IT Audit = Conformance De facto framework for Compliance with: Sarbanes Oxley Act (2002) Basel II 3
  • 4. ® ® How COBIT developed into COBIT 4.1 ® ® COBIT® 2 COBIT 3 COBIT 4 IT Audit IT Audit IT Governance IT Audit 1996 2000 2005 2007 WHAT Based on a Management Alignment Linking of COBIT® range of guidelines with Business 4.1 International developed ITIL & & HOW Standards ISO 17799 IT Goals Implementation Guidance for VAL-IT™ Large businesses & SMEs Framework Mappings 4
  • 5. ® COBIT Framework - Overview 34 high level processes in 4 process domains Plan and Organise (PO) Acquire and Implement (AI) Deliver and Support (DS) Monitor and Evaluate (ME) Recommends for each process: Control objectives Goals & Metrics RACI Chart Inputs and Outputs Maturity Model 5
  • 6. What is Val IT ™? An ITSM framework based on COBIT® Extends and complements COBIT® From business & financial perspectives Right investments? Optimizing returns? Governance of IT-enabled business investments Processes for: Value delivery Portfolio management Investment management 6
  • 7. ® Basic COBIT Principle Business Objectives Governance Objectives Integrity Confidentiality Availability Efficiency Business Compliance Effectiveness Requirements Reliability (of information) Plan & Organise (PO) Acquire & Applications Implement IT Processes Information (AI) Deliver & Monitor & IT Resources Support Evaluate (DS) (ME) Infrastructure People 7
  • 8. ® COBIT 4.1 Processes Business Requirements “Information” Monitor and ME Evaluate Plan and PO Organise DS Deliver and Acquire and AI Support Implement 8
  • 9. ® COBIT 4.1 Processes - PO PO1 Define a strategic plan PO2 Define the information architecture PO3 Determine technological direction PO4 Define the IT processes, organisations & relationships PO5 Manage the IT investment PO6 Communicate management aims and direction PO7 Manage IT human resources PO8 Manage quality PO9 Assess and manage IT risks PO10 Manage Projects 9
  • 10. ® COBIT 4.1 Processes - AI AI1 Identify automated solutions AI2 Acquire and maintain application software AI3 Acquire and maintain technology infrastructure AI4 Enable operation and use AI5 Procure IT resources AI6 Manage changes AI7 Install and accredit solutions and changes 10
  • 11. ® COBIT 4.1 Processes - DS DS1 Define and manage service levels DS2 Manage third-party services DS3 Manage performance and capacity DS4 Ensure continuous service DS5 Ensure systems security DS6 Identify and allocate costs DS7 Educate and train users DS8 Manage service desk and incidents DS9 Manage the configuration DS10 Manage problems DS11 Manage data DS12 Manage the physical environment DS13 Manage operations 11
  • 12. ® COBIT 4.1 Proceses - ME ME1 Monitor and evaluate IT performance ME2 Monitor and evaluate internal controls ME3 Ensure compliance with external requirements ME4 Provide IT governance 12
  • 13. ® COBIT 4.1 uses Cascading Goals Business Goal Compliance with internal policies IT Goal Respond to Drives governance requirements in line with board direction Process Goal Drives Define a Strategic IT Plan 13
  • 14. ® Business Goals and IT Goals in COBIT 17 Generic Business Goals are defined Balanced In 4 perspectives Score Financial Perspective (3) Card ! Customer Perspective (6) Internal Perspective (6) Learning and Growth Perspective (2) A more detailed basis for Business Requirements Mapped to 28 IT Goals ® In turn, mapped to 34 COBIT processes 14
  • 15. Wish to learn more? ® Attend: 2 day ISACA COBIT Foundation Course ® Includes ISACA COBIT Foundation Exam ® Gain an ISACA COBIT Foundation Certificate 40 multiple-choice questions in final hour of course 70% to pass 15
  • 16. COBIT® Training Courses Official ISACA curriculum ® COBIT Foundation 2 days, classroom ™ Implementing Governance using COBIT® & Val IT 2 days, classroom ® Delegates should hold COBIT Foundation Certificate 16
  • 17. Last Words on Frameworks… Guides not recipes Frameworks complement one another ® COBIT is built using ideas from >40 frameworks. ® COBIT tells you “What to do” The other frameworks tell you “How to do it” ® ® ® COBIT , ITIL , ISO 27001 and PRINCE2 form an implementable group 17
  • 18. More Information? Need advice, guidance, training or consultancy on: COBIT ISO 20000 ITIL? Contact us at info@maatconsulting.com View COBIT course descriptions, course schedules and free materials like this on our website www.maatconsulting.com 18
  • 19. Education and Consultancy for IT Best Practices 19
  • 20. Why the name Maat Consulting Ltd? Ma’at was the Ancient Egyptian goddess of order and balance. The main responsibility of the pharaoh was to preserve ma’at (order and balance) and prevent isfet (chaos). Maat Consulting Ltd helps businesses to achieve order and balance in their IT Service provision through training and consultancy on best practices for IT Service Management using ITIL®, COBIT® and ISO/IEC 20000. 20