Введение
COBIT (Цели контроля для информационных и связанных технологий) – это структура, разработанная ISACA для управления информационными технологиями (ИТ) и ИТ-управления. Данная структура ориентирована на бизнес и определяет набор универсальных процессов управления ИТ, каждый из которых включает в себя входные и выходные данные процесса, ключевые действия, цели процесса, показатели эффективности и элементарную модель зрелости. Структура COBIT связана с COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF и PMBOK. Компоненты COBIT:
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process activities, process objectives, performance measures and an elementary maturity model. The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK. Below are COBIT components:
Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements. Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor. Control objectives: Provides a complete set of high level requirements to be considered by management for effective control of each IT process. Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes. Maturity models: Assesses maturity and capability per process and helps to address gaps. The standard meets all the needs of the practice, while maintaining independence from specific manufacturers, technologies and platforms. When developing the standard, it was possible to use it both for auditing a company's IT system and for designing an IT system. In the first case, COBIT allows you to determine the degree of conformity of the system under study to the best examples, and in the second, to design a system that is almost ideal in its characteristics.
Структура: Организует цели ИТ-управления и лучшие практики по ИТ-доменам и процессам, связывая их с бизнес-требованиями.
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process activities, process objectives, performance measures and an elementary maturity model. The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK. Below are COBIT components:
Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements. Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor. Control objectives: Provides a complete set of high level requirements to be considered by management for effective control of each IT process. Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes. Maturity models: Assesses maturity and capability per process and helps to address gaps. The standard meets all the needs of the practice, while maintaining independence from specific manufacturers, technologies and platforms. When developing the standard, it was possible to use it both for auditing a company's IT system and for designing an IT system. In the first case, COBIT allows you to determine the degree of conformity of the system under study to the best examples, and in the second, to design a system that is almost ideal in its characteristics.
Описание процессов: Эталонная модель процесса и общий язык для всех участников организации. Процессы сопоставляются с областями ответственности: планирование, разработка, эксплуатация и мониторинг.
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process activities, process objectives, performance measures and an elementary maturity model. The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK. Below are COBIT components:
Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements. Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor. Control objectives: Provides a complete set of high level requirements to be considered by management for effective control of each IT process. Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes. Maturity models: Assesses maturity and capability per process and helps to address gaps. The standard meets all the needs of the practice, while maintaining independence from specific manufacturers, technologies and platforms. When developing the standard, it was possible to use it both for auditing a company's IT system and for designing an IT system. In the first case, COBIT allows you to determine the degree of conformity of the system under study to the best examples, and in the second, to design a system that is almost ideal in its characteristics.
Цели контроля: Предоставляет полный набор высокоуровневых требований, которые руководство должно учитывать для эффективного контроля каждого ИТ-процесса.
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process activities, process objectives, performance measures and an elementary maturity model. The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK. Below are COBIT components:
Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements. Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor. Control objectives: Provides a complete set of high level requirements to be considered by management for effective control of each IT process. Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes. Maturity models: Assesses maturity and capability per process and helps to address gaps. The standard meets all the needs of the practice, while maintaining independence from specific manufacturers, technologies and platforms. When developing the standard, it was possible to use it both for auditing a company's IT system and for designing an IT system. In the first case, COBIT allows you to determine the degree of conformity of the system under study to the best examples, and in the second, to design a system that is almost ideal in its characteristics.
Руководство по управлению: Помогает распределить ответственность, согласовать цели, измерять эффективность и демонстрировать взаимосвязь с другими процессами.
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process activities, process objectives, performance measures and an elementary maturity model. The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK. Below are COBIT components:
Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements. Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor. Control objectives: Provides a complete set of high level requirements to be considered by management for effective control of each IT process. Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes. Maturity models: Assesses maturity and capability per process and helps to address gaps. The standard meets all the needs of the practice, while maintaining independence from specific manufacturers, technologies and platforms. When developing the standard, it was possible to use it both for auditing a company's IT system and for designing an IT system. In the first case, COBIT allows you to determine the degree of conformity of the system under study to the best examples, and in the second, to design a system that is almost ideal in its characteristics.
Модели зрелости: Оценивают зрелость и возможности каждого процесса и помогают выявить и устранить недостатки.
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process activities, process objectives, performance measures and an elementary maturity model. The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK. Below are COBIT components:
Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements. Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor. Control objectives: Provides a complete set of high level requirements to be considered by management for effective control of each IT process. Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes. Maturity models: Assesses maturity and capability per process and helps to address gaps. The standard meets all the needs of the practice, while maintaining independence from specific manufacturers, technologies and platforms. When developing the standard, it was possible to use it both for auditing a company's IT system and for designing an IT system. In the first case, COBIT allows you to determine the degree of conformity of the system under study to the best examples, and in the second, to design a system that is almost ideal in its characteristics.
Стандарт удовлетворяет всем практическим потребностям, сохраняя при этом независимость от конкретных производителей, технологий и платформ. При разработке стандарта его можно использовать как для аудита ИТ-системы организации, так и для проектирования ИТ-системы. В первом случае COBIT позволяет определить степень соответствия анализируемой системы лучшим практикам, а во втором – разработать систему, близкую к идеалу по своим характеристикам.
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for information technology (IT) management and IT governance. The framework is business focused and defines a set of generic processes for the management of IT, with each process defined together with process inputs and outputs, key process activities, process objectives, performance measures and an elementary maturity model. The COBIT framework ties in with COSO, ITIL, BiSL, ISO 27000, CMMI, TOGAF and PMBOK. Below are COBIT components:
Framework: Organizes IT governance objectives and good practices by IT domains and processes and links them to business requirements. Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run, and monitor. Control objectives: Provides a complete set of high level requirements to be considered by management for effective control of each IT process. Management guidelines: Helps assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes. Maturity models: Assesses maturity and capability per process and helps to address gaps. The standard meets all the needs of the practice, while maintaining independence from specific manufacturers, technologies and platforms. When developing the standard, it was possible to use it both for auditing a company's IT system and for designing an IT system. In the first case, COBIT allows you to determine the degree of conformity of the system under study to the best examples, and in the second, to design a system that is almost ideal in its characteristics.
История
COBIT изначально назывался "Цели контроля для информационных и связанных технологий", хотя до выпуска фреймворка люди говорили о "CobiT" как о "Целях контроля для ИТ" или "Целях контроля для информационных и связанных технологий". ISACA впервые выпустила COBIT в 1996 году, изначально как набор контрольных целей, чтобы помочь финансовому аудиторскому сообществу лучше ориентироваться в ИТ-средах. Увидев ценность в расширении фреймворка за пределы только аудита, ISACA выпустила более широкую версию 2 в 1998 году и еще больше расширила ее, добавив руководства по управлению в версии 3 2000 года. Разработка AS 8015: Австралийский стандарт корпоративного управления информационными и коммуникационными технологиями в январе 2005 года и более международного проекта стандарта ISO/IEC DIS 29382 (который вскоре стал ISO/IEC 38500) в январе 2007 года повысила осведомленность о необходимости большего количества компонентов управления информационными и коммуникационными технологиями (ИКТ). ISACA неизбежно добавила связанные компоненты/фреймворки с версиями 4 и 4.1 в 2005 и 2007 годах соответственно, "охватывающие бизнес-процессы и ответственность, связанные с ИТ, в создании ценности (Val IT) и управлении рисками (Risk IT)". В настоящее время ISACA предлагает сертификационные треки по COBIT 2019 (COBIT Foundations, COBIT Design & Implementation и Implementing the NIST Cybersecurity Framework Using COBIT 2019), а также сертификацию по предыдущей версии (COBIT 5).