|
Abstract: . . . completeness is classified using two dimensions: · Vertical - How detailed are the guidelines in terms of technical or operational profundity? · Horizontal - How complete is the guidance? How much of COBIT is addressed with the guidance? What is more comprehensively addressed than in COBIT? What is missing compared to COBIT? Source: COBIT Mapping, IT Governance Institute, . . . . . . /IEC 17799 :2000 – Security requirements Source: Whitepaper ITIL i samverkan med Cobit och 17799 , Av John Walllhoff, Scillani Information AB (2004), www.scillani.com Page 28 TO CHOOSE? ITIL COBIT ISO /IEC 17799 :2000 How can I deliver efficient IT-services? How can I enhance security in processes? What shall I do to deliver efficient IT-services and what controls shall . . . . . . Cobit och 17799 , Av John Walllhoff, Scillani Information AB (2004), www.scillani.com Page 28 TO CHOOSE? ITIL COBIT ISO /IEC 17799 :2000 How can I deliver efficient IT-services? How can I enhance security in processes? What shall I do to deliver efficient IT-services and what controls shall I implement? Page 29 Other standards/models • Six Sigma • Balanced Scorecard . . . . . . mechanism, where it describes how COBIT Provides IT controls and IT metrics, but not strong in security To be used as the delivery mechanism, where it describes what Page 21 What can be combined? ITIL COBIT ISO /IEC 17799 :2000 Concept/Process Critical Success Factors Information Security Activities Metrics (CSF, KPI) Cost/Benefit Benchmarking (CMM) Planning for implementation . . . . . . dimensions: · Vertical - How detailed are the guidelines in terms of technical or operational profundity? · Horizontal - How complete is the guidance? How much of COBIT is addressed with the guidance? What is more comprehensively addressed than in COBIT? What is missing compared to COBIT? Source: COBIT Mapping, IT Governance Institute, 2004 Page 31 -The needto know- . . . . . . shall I do to deliver efficient IT-services and what controls shall I implement? Page 29 Other standards/models • Six Sigma • Balanced Scorecard • EFQM • CMM • Uncle Tom Cobbleigh • ISO /IEC TR 13335 • TickIT • NIST 800-14 • COSO • … Page 30 Other standards/models The completeness is classified using two dimensions: · Vertical - How detailed are the guidelines in . . . --2197,6,183,2621,10985
|