SlideShare a Scribd company logo
6
Most read
19
Most read
22
Most read
IT Governance
Capability Assessment using COBIT 5 PAM
Eryk Budi Pratama
Presented for Information System Faculty– Universitas Bakrie
Objectives
IT Governance
Governance of Enterprise IT
Domain, Product Family, Coverage
COBIT 5 Framework
PAM using COBIT 5
Process Assessment Model (PAM)
Self Assessment Guide using COBIT 5
Self Assessment
Methodology for IT Governance Engagement
Engagement Delivery Approach
IT Governance
Governance of Enterprise IT
IT Governance
Old Way
COBIT 4.1
Val ITRisk IT
Corporate Governance of IT
Based on ISO 38500
Source: http://www.qaiglobalservices.com/wp-content/uploads/2016/05/Fig-4.jpg
Governance of Enterprise IT
COBIT 5 - Principles and Area
Risk Management
Focus
Area
COBIT 5 Framework
COBIT 5
Domain
❑ Evaluate, Direct, Monitor (EDM)
❑ Align, Plan, Organize (APO)
❑ Build, Acquire, Implement (BAI)
❑ Deliver, Service, Support (DSS)
A Business Framework for the
Governance and Management
of Enterprise IT
COBIT 5
COBIT 5 Product Family
COBIT 5
COBIT 5 Coverage of Other Standards and Frameworks
Standard Description
ISO 38500 Governance of IT for the organization
ISO 31000 Enterprise Risk Management
ISO 27000 Information Security Management
ISO 20000 IT Service Management
Framework Description
TOGAF Enterprise Architecture by OpenGroup
PMBOK Project Management by PMI
PRINCE2 Project Management by APMG
ITIL IT Service Management by AXELOS
CMMI Capability Maturity Model Integration
Process Assessment Model
(PAM)
COBIT 5 PAM
COBIT Process Assessment Model (PAM) Workflow
Source: This figure is reproduced from ISO/IEC 15504-2, with the permission of ISO/IEC at www.iso.org. Copyright remains with ISO/IEC.
COBIT 5 PAM
COBIT Process Assessment Model (PAM) Workflow
COBIT 5 PAM
Process Capability Level and Attributes
Rating Levels
Levels and Necessary Ratings
COBIT 5 PAM
Assessment Process
Self Assessment
Self Assessment
Step 1 – Scoping (Process Step)
Identify relevant business drivers for the assessment of IT processes
•On the basis of these business drivers, define the objective of the assessment.
•The prioritisation and selection of one or more COBIT 5 processes for inclusion in the process assessment should be based on the business drivers
for the assessment.
Identify and prioritise the enterprise’s IT processes that should be included within the scope of the assessment
•Utilise the business drivers and assessment objectives identified previously, along with, as appropriate, the COBIT 5 process mappings contained
in the scoping tool kit.
•For example, if the objective of the assessment is to assist IT management in identifying and prioritising improvement initiatives related to one or
more specified goals identified, the COBIT process mappings may be useful to identify the processes most closely related to those IT goals.
Perform a preliminary scoping selection of target processes for inclusion in the assessment, based on the previous
prioritisation
•Ensure that they will satisfy the identified business drivers and meet the objectives of the assessment.
Confirm the preliminary selection of target COBIT 5 processes with the project sponsor and key stakeholders of the
process assessment
Finalise the COBIT 5 processes to be included in the assessment
Self Assessment
Step 1 – Scoping (Process Step)
Enterprise Goal Hierarchy IT-related Goals Hierarchy Self-Diagnostic
Mapping of COBIT 5 Processes to IT Goals
to Business Goals to IT Balanced
Scorecard
Mapping COBIT 5 Processes to IT Goals
(subset of information contained in item
above)
Self-diagnostic Tool
Self Assessment
Step 2 – Perform Self Assessment
Self Assessment
Step 2 – Perform Self Assessment
Engagement Delivery
Approach
Engagement Delivery Approach
General Delivery Approach
Process mapping of
current IT process to
COBIT 5
Working Group
& Discussion
Report
Assessment
IT Capabilities
Operational
Effectiveness &
Workshop
IT Goals, IT Framework risk
IT Issues, and
Remediation Roadmap
based on COBIT 5
Maturity Level based on
COBIT 5
Strategy and recommendation
report for IT process
improvement
Output
Engagement Delivery Approach
General Delivery Approach
Working Group
& Discussion
Report
Assessment
IT Capabilities
Operational
Effectiveness &
Workshop
▪ Determine the organizational
structure and the members
involved in the project as well
as the duties and responsibiliti
es of each party
▪ Create detailed work plans
and activities to be performed
▪ Determine communication
methods and information
paths
▪ Defines a list of required infor
mation
▪ Conducting a Kick-Off meeting
with all related parties to
assign key business process
owner over 37 sub-areas of
COBIT 5
▪ Determining the target and the
schedule of the interview
▪ Collect data / documents and
information on current state of
existing IT processes based
on 37 major sub-areas in
COBIT 5
▪ Review relevant documents
and information
▪ Discuss with key parties in the
IT process
▪ Determine the level of IT
capabilities with COBIT 5 tools
▪ Determine the level of IT
capability for 37 major sub
areas of COBIT 5 in the client
▪ Discussions with client’s mana
gement are related to IT
capability level reports that
have been assessed by
consultant
▪ Provide monitoring tools
related to improvements that
will be done by the client
▪ Organize workshop schedules
to report the result of IT
governance capability level
assessments
▪ Describes the review
methodology used
▪ Displays observations
regarding existing IT processes
and gaps based on COBIT 5
▪ Exposure to the results of
Operational Effectiveness i
mplementation
▪ Presentation of
recommendations for
improvement of client’s IT
process
Thank you

More Related Content

PPTX
Introduction to COBIT 2019 and IT management
PDF
PPTX
COBIT 5 IT Governance Model: an Introduction
PDF
COBIT 2019 Overview_v1.1.pdf
PDF
Personal Data Protection in Indonesia
PDF
Мэдээлэлийн технологийн хөгжлийн өнөөгийн байдал цаашдын зорилт
PPTX
IT Governance Vs IT Management Presentation V0.1
PPTX
Identity & access management
Introduction to COBIT 2019 and IT management
COBIT 5 IT Governance Model: an Introduction
COBIT 2019 Overview_v1.1.pdf
Personal Data Protection in Indonesia
Мэдээлэлийн технологийн хөгжлийн өнөөгийн байдал цаашдын зорилт
IT Governance Vs IT Management Presentation V0.1
Identity & access management

What's hot (20)

PDF
An Introduction to IT Management with COBIT 2019
PPTX
Cobit 2019 framework by ISACA
PDF
cobit 2019 presentation.pdf
PPTX
IT Governance Framework
PDF
IT Governance
PDF
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
PDF
IT Governance - Governing IT: Do or Die?
PPSX
IT Governance - COBIT Perspective
PPTX
Introduction to COBIT 5 and IT management
PDF
IT Strategy Assessment & Optimization - Catallysts Approach
PPTX
IT Governance Made Easy
PPTX
Cobit 5 - An Overview
PPTX
IT General Controls
PPTX
IT4IT - The Full Story for Digital Transformation - Part 1
PPTX
SOC 2 Compliance and Certification
PDF
IT4IT™ - Managing the Business of IT
PDF
Integrating It Frameworks, Methodologies And Best Practices Into It Delivery ...
PDF
Enterprise Architecture Implementation And The Open Group Architecture Framew...
An Introduction to IT Management with COBIT 2019
Cobit 2019 framework by ISACA
cobit 2019 presentation.pdf
IT Governance Framework
IT Governance
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
IT Governance - Governing IT: Do or Die?
IT Governance - COBIT Perspective
Introduction to COBIT 5 and IT management
IT Strategy Assessment & Optimization - Catallysts Approach
IT Governance Made Easy
Cobit 5 - An Overview
IT General Controls
IT4IT - The Full Story for Digital Transformation - Part 1
SOC 2 Compliance and Certification
IT4IT™ - Managing the Business of IT
Integrating It Frameworks, Methodologies And Best Practices Into It Delivery ...
Enterprise Architecture Implementation And The Open Group Architecture Framew...
Ad

Similar to IT Governance - Capability Assessment using COBIT 5 (20)

PDF
IT Governance - COBIT 5 Capability Assessment
PDF
Roadmap methodology
PPT
IT Process Strategy
PPTX
Darmin ritonga 11353205418
PDF
Cobit5 brochure
PPTX
Cobit 4.1 indri
PPT
Training on ASAP Methodology.ppt
PPT
SixSigma Training Course homework in 2016
PDF
SixSigma 【Continuous Study】
PPTX
eCIO PPT Roles for a SAP and Systems Integration Project
PPTX
Frameworks For Predictability
PPTX
Course 1 Requirements Definition Overview.pptx
PPTX
Donna Febriani
PDF
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
PPTX
IT NPI Process
PPT
Pmi, Opm3 And Cmmi Assessment Overview
PDF
80262886-SAP-Implementation-Methodology.pdf
PDF
IT (GRC based) Transformation case - Algosaibi Group
PPTX
Isaca presentation
PPTX
Co5bit
IT Governance - COBIT 5 Capability Assessment
Roadmap methodology
IT Process Strategy
Darmin ritonga 11353205418
Cobit5 brochure
Cobit 4.1 indri
Training on ASAP Methodology.ppt
SixSigma Training Course homework in 2016
SixSigma 【Continuous Study】
eCIO PPT Roles for a SAP and Systems Integration Project
Frameworks For Predictability
Course 1 Requirements Definition Overview.pptx
Donna Febriani
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
IT NPI Process
Pmi, Opm3 And Cmmi Assessment Overview
80262886-SAP-Implementation-Methodology.pdf
IT (GRC based) Transformation case - Algosaibi Group
Isaca presentation
Co5bit
Ad

More from Eryk Budi Pratama (20)

PDF
How Current Advanced Cyber Threats Transform Business Operation
PDF
ICDCC 2025: Securing Agentic AI - Eryk Budi Pratama.pdf
PDF
Digital Leadership: How to Build Valuable Connection
PDF
AI Solutions for Sustainable Developmentpment_public.pdf
PPTX
AI Governance: Responsible and Trustworthy AI
PDF
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
PDF
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...
PDF
Privacy-ready Data Protection Program Implementation
PDF
Cybersecurity 101 - Auditing Cyber Security
PDF
Urgensi RUU Perlindungan Data Pribadi
PDF
Modern IT Service Management Transformation - ITIL Indonesia
PDF
Common Practice in Data Privacy Program Management
PDF
The Rise of Data Ethics and Security - AIDI Webinar
PDF
Data Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
PDF
Data Loss Prevention (DLP) - Fundamental Concept - Eryk
PDF
Cyber Resilience - Welcoming New Normal - Eryk
PDF
Enabling Data Governance - Data Trust, Data Ethics, Data Quality
PDF
Enterprise Cybersecurity: From Strategy to Operating Model
PDF
Blockchain for Accounting & Assurance
PDF
Guardians of Trust: Building Trust in Data & Analytics
How Current Advanced Cyber Threats Transform Business Operation
ICDCC 2025: Securing Agentic AI - Eryk Budi Pratama.pdf
Digital Leadership: How to Build Valuable Connection
AI Solutions for Sustainable Developmentpment_public.pdf
AI Governance: Responsible and Trustworthy AI
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...
Privacy-ready Data Protection Program Implementation
Cybersecurity 101 - Auditing Cyber Security
Urgensi RUU Perlindungan Data Pribadi
Modern IT Service Management Transformation - ITIL Indonesia
Common Practice in Data Privacy Program Management
The Rise of Data Ethics and Security - AIDI Webinar
Data Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
Data Loss Prevention (DLP) - Fundamental Concept - Eryk
Cyber Resilience - Welcoming New Normal - Eryk
Enabling Data Governance - Data Trust, Data Ethics, Data Quality
Enterprise Cybersecurity: From Strategy to Operating Model
Blockchain for Accounting & Assurance
Guardians of Trust: Building Trust in Data & Analytics

Recently uploaded (20)

PDF
Empathic Computing: Creating Shared Understanding
PPTX
Spectroscopy.pptx food analysis technology
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
cuic standard and advanced reporting.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
Cloud computing and distributed systems.
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPT
Teaching material agriculture food technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
KodekX | Application Modernization Development
Empathic Computing: Creating Shared Understanding
Spectroscopy.pptx food analysis technology
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Electronic commerce courselecture one. Pdf
Review of recent advances in non-invasive hemoglobin estimation
cuic standard and advanced reporting.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
Spectral efficient network and resource selection model in 5G networks
Cloud computing and distributed systems.
Per capita expenditure prediction using model stacking based on satellite ima...
Building Integrated photovoltaic BIPV_UPV.pdf
20250228 LYD VKU AI Blended-Learning.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Teaching material agriculture food technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
sap open course for s4hana steps from ECC to s4
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
KodekX | Application Modernization Development

IT Governance - Capability Assessment using COBIT 5

  • 1. IT Governance Capability Assessment using COBIT 5 PAM Eryk Budi Pratama Presented for Information System Faculty– Universitas Bakrie
  • 2. Objectives IT Governance Governance of Enterprise IT Domain, Product Family, Coverage COBIT 5 Framework PAM using COBIT 5 Process Assessment Model (PAM) Self Assessment Guide using COBIT 5 Self Assessment Methodology for IT Governance Engagement Engagement Delivery Approach
  • 4. IT Governance Old Way COBIT 4.1 Val ITRisk IT
  • 5. Corporate Governance of IT Based on ISO 38500 Source: http://www.qaiglobalservices.com/wp-content/uploads/2016/05/Fig-4.jpg
  • 6. Governance of Enterprise IT COBIT 5 - Principles and Area Risk Management Focus Area
  • 8. COBIT 5 Domain ❑ Evaluate, Direct, Monitor (EDM) ❑ Align, Plan, Organize (APO) ❑ Build, Acquire, Implement (BAI) ❑ Deliver, Service, Support (DSS) A Business Framework for the Governance and Management of Enterprise IT
  • 9. COBIT 5 COBIT 5 Product Family
  • 10. COBIT 5 COBIT 5 Coverage of Other Standards and Frameworks Standard Description ISO 38500 Governance of IT for the organization ISO 31000 Enterprise Risk Management ISO 27000 Information Security Management ISO 20000 IT Service Management Framework Description TOGAF Enterprise Architecture by OpenGroup PMBOK Project Management by PMI PRINCE2 Project Management by APMG ITIL IT Service Management by AXELOS CMMI Capability Maturity Model Integration
  • 12. COBIT 5 PAM COBIT Process Assessment Model (PAM) Workflow Source: This figure is reproduced from ISO/IEC 15504-2, with the permission of ISO/IEC at www.iso.org. Copyright remains with ISO/IEC.
  • 13. COBIT 5 PAM COBIT Process Assessment Model (PAM) Workflow
  • 14. COBIT 5 PAM Process Capability Level and Attributes Rating Levels Levels and Necessary Ratings
  • 17. Self Assessment Step 1 – Scoping (Process Step) Identify relevant business drivers for the assessment of IT processes •On the basis of these business drivers, define the objective of the assessment. •The prioritisation and selection of one or more COBIT 5 processes for inclusion in the process assessment should be based on the business drivers for the assessment. Identify and prioritise the enterprise’s IT processes that should be included within the scope of the assessment •Utilise the business drivers and assessment objectives identified previously, along with, as appropriate, the COBIT 5 process mappings contained in the scoping tool kit. •For example, if the objective of the assessment is to assist IT management in identifying and prioritising improvement initiatives related to one or more specified goals identified, the COBIT process mappings may be useful to identify the processes most closely related to those IT goals. Perform a preliminary scoping selection of target processes for inclusion in the assessment, based on the previous prioritisation •Ensure that they will satisfy the identified business drivers and meet the objectives of the assessment. Confirm the preliminary selection of target COBIT 5 processes with the project sponsor and key stakeholders of the process assessment Finalise the COBIT 5 processes to be included in the assessment
  • 18. Self Assessment Step 1 – Scoping (Process Step) Enterprise Goal Hierarchy IT-related Goals Hierarchy Self-Diagnostic Mapping of COBIT 5 Processes to IT Goals to Business Goals to IT Balanced Scorecard Mapping COBIT 5 Processes to IT Goals (subset of information contained in item above) Self-diagnostic Tool
  • 19. Self Assessment Step 2 – Perform Self Assessment
  • 20. Self Assessment Step 2 – Perform Self Assessment
  • 22. Engagement Delivery Approach General Delivery Approach Process mapping of current IT process to COBIT 5 Working Group & Discussion Report Assessment IT Capabilities Operational Effectiveness & Workshop IT Goals, IT Framework risk IT Issues, and Remediation Roadmap based on COBIT 5 Maturity Level based on COBIT 5 Strategy and recommendation report for IT process improvement Output
  • 23. Engagement Delivery Approach General Delivery Approach Working Group & Discussion Report Assessment IT Capabilities Operational Effectiveness & Workshop ▪ Determine the organizational structure and the members involved in the project as well as the duties and responsibiliti es of each party ▪ Create detailed work plans and activities to be performed ▪ Determine communication methods and information paths ▪ Defines a list of required infor mation ▪ Conducting a Kick-Off meeting with all related parties to assign key business process owner over 37 sub-areas of COBIT 5 ▪ Determining the target and the schedule of the interview ▪ Collect data / documents and information on current state of existing IT processes based on 37 major sub-areas in COBIT 5 ▪ Review relevant documents and information ▪ Discuss with key parties in the IT process ▪ Determine the level of IT capabilities with COBIT 5 tools ▪ Determine the level of IT capability for 37 major sub areas of COBIT 5 in the client ▪ Discussions with client’s mana gement are related to IT capability level reports that have been assessed by consultant ▪ Provide monitoring tools related to improvements that will be done by the client ▪ Organize workshop schedules to report the result of IT governance capability level assessments ▪ Describes the review methodology used ▪ Displays observations regarding existing IT processes and gaps based on COBIT 5 ▪ Exposure to the results of Operational Effectiveness i mplementation ▪ Presentation of recommendations for improvement of client’s IT process