You are on page 1of 6

Governance and Management in COBIT 5

Governance Objective: Value Creation


Benefits
Realisation

Risk
Optimisation

Resource
Optimisation

Governance
Enablers

Governance
Scope

Roles, Activities and Relationships


Source: COBIT 5, figure 8

Key Roles, Activities and Relationships

Roles, Activities and Relationships


Delegate

Owners and
Stakeholders

Accountable

Set Direction

Governing
Body

Management
Monitor

Instruct and
Align

Operations
and
Execution

Report

Source: COBIT 5, figure 9

COBIT 5 Governance and Management Key Areas

Business Needs

Governance
Evaluate

Direct

Management Feedback

Monitor

Management
Plan
(APO)

Build
(BAI)

Run
(DSS)

Monitor
(MEA)

Source: COBIT 5, figure 15


2012 ISACA.

All rights reserved.

2012 ISACA.

All rights reserved.

APO10 Manage
Suppliers

APO09 Manage
Service
Agreements

APO08 Manage
Relationships

Source: COBIT 5, figure 16

DSS01 Manage
Operations

DSS02 Manage
Service Requests
and Incidents

DSS04 Manage
Continuity

BAI04 Manage
Availability
and Capacity

APO11 Manage
Quality

APO04 Manage
Innovation

EDM03 Ensure
Risk Optimisation

DSS05 Manage
Security
Services

BAI05 Manage
Organisational
Change
Enablement

APO12 Manage
Risk

APO05 Manage
Portfolio

DSS06 Manage
Business
Process Controls

BAI06 Manage
Changes

APO13 Manage
Security

APO06 Manage
Budget and Costs

EDM04 Ensure
Resource
Optimisation

Processes for Management of Enterprise IT

DSS03 Manage
Problems

BAI10 Manage
Configuration

BAI09 Manage
Assets

BAI08 Manage
Knowledge

Deliver, Service and Support

BAI03 Manage
Solutions
Identification
and Build

BAI02 Manage
Requirements
Definition

BAI01 Manage
Programmes and
Projects

Build, Acquire and Implement

APO03 Manage
Enterprise
Architecture

APO02 Manage
Strategy

EDM02 Ensure
Benefits Delivery

APO01 Manage
the IT Management
Framework

Align, Plan and Organise

EDM01 Ensure
Governance
Framework Setting
and Maintenance

Evaluate, Direct and Monitor

Processes for Governance of Enterprise IT

COBIT 5 Process Reference Model

BAI07 Manage
Change
Acceptance and
Transitioning

APO07 Manage
Human Resources

EDM05 Ensure
Stakeholder
Transparency

MEA03 Monitor,
Evaluate and Assess
Compliance With
External Requirements

MEA02 Monitor,
Evaluate and Assess
the System of Internal
Control

MEA01 Monitor,
Evaluate and Assess
Performance and
Conformance

Monitor, Evaluate
and Assess

COBIT 5 Enterprise Enablers

4. Culture, Ethics
and Behaviour

3. Organisational
Structures

2. Processes

1. Principles, Policies and Frameworks

6. Services,
Infrastructure
and Applications

5. Information

7. People,
Skills and
Competencies

Resources
Source: COBIT 5, figure 12

Enabler Performance
Management

Enabler Dimension

COBIT 5 Enablers: Generic

Stakeholders

Goals

Life Cycle

Good Practices

Internal
Stakeholders
External
Stakeholders

Intrinsic Quality
Contextual Quality
(Relevance,
Effectiveness)
Accessibility and
Security

Plan
Design
Build/Acquire/
Create/Implement
Use/Operate
Evaluate/Monitor
Update/Dispose

Practices
Work Products
(Inputs/Outputs)

Are Stakeholders
Needs Addressed?

Are Enabler
Goals Achieved?

Is Life Cycle
Managed?

Are Good Practices


Applied?

Metrics for Achievement of Goals


(Lag Indicators)

Metrics for Application of Practice


(Lead Indicators)

Source: COBIT 5, figure 13

2012 ISACA.

All rights reserved.

The Seven Phases of the Implementation Life Cycle

we
t

re ?

to b

e?

ap
fi n

ed

ge

th e

(middle ring)

ant

do

De

Change enablement

ew

te

m
Co o

dm

cu

ow

I d e n tif y r o l e
pla ye rs

oa

er

ta

B u il d
i m pro
ve m e nts

(outer ring)

Continual improvement life cycle


(inner ring)

m
ut u ni
co c a
m e te

fi
rg n e
ta e t
te

e
en n t
ts

Programme management

ow

Operate
and
measur
e

Embed n
approach ew
es

Realise ben
efits

le m
I m p o ve m
r
imp

at
er
O p d us
an

E xe

5H

De

re we now?
here a

Recog
need nise
act to

ementation
impl
rm team
Fo

r
nito
Mo and
ate
alu
ev

2W

Establ
is
to ch h des
ang ire
e

n
stai
Su

la

Initiat
e pr
ogr
am
me

ss
Asseent
curr te
sta

6 Did we get the

ive
ect
f
f
e

re th
ed
rive
rs?

ms and
probleities
ine
un
Def opport

re?

7H

ow

1 What a

m going?
mentu
e mo
h
t
eep
ek
w
viewness
do
Re

P la n p ro g ra m m e

4 W hat n eeds to be d one?

Wh

er

Source: COBIT 5, figure 17 and COBIT 5 Implementation, figure 6

Summary of the COBIT 5 Process Capability Model

Generic Process Capability Attributes


Performance
Attribute (PA) 1.1
Process
Performance

Incomplete
Process

Performed
Process

PA 2.1
Performance
Management

PA 2.2
Work
Product
Management

Managed
Process

PA 3.2
PA 4.1
Process
Process
Deployment Management

Established
Process

COBIT 5 Process Assessment


ModelPerformance Indicators

PA 3.1
Process
Definition

PA 4.2
Process
Control

Predictable
Process

PA 5.1
Process
Innovation

PA 5.2
Process
Optimisation

Optimising
Process

COBIT 5 Process Assessment


ModelCapability Indicators

Process Outcomes
Base Practices
(Management/
Governance
Practices)

Work
Products
(Inputs/
Outputs)

Generic Practices

Generic Resources

Generic Work Products

Source: COBIT 5, figure 19

2012 ISACA.

All rights reserved.

COBIT 5 Product Family

COBIT 5
COBIT 5 Enabler Guides
COBIT 5:
Enabling Processes

COBIT 5:
Enabling Information

Other Enabler
Guides

COBIT 5 Professional Guides


COBIT 5 Implementation

COBIT 5
for Information
Security

COBIT 5
for Assurance

COBIT 5
for Risk

COBIT 5 Online Collaborative Environment


Source: COBIT 5, figure 11

COBIT 5 Principles

1. Meeting
Stakeholder
Needs

5. Separating
Governance
From
Management

2. Covering the
Enterprise
End-to-end

COBIT 5
Principles

3. Applying a
Single
Integrated
Framework

4. Enabling a
Holistic
Approach

Source: COBIT 5, figure 2

3701 Algonquin Road, Suite 1010 Rolling Meadows, IL 60008 USA


Phone: +1.847.253.1545 Fax: +1.847.253.1443 Email: info@isaca.org
Web site: www.isaca.org
2012 ISACA. A

l l

r i g h t s

r e s e r v e d

Other Professional
Guides

COBIT 5 Goals Cascade Overview

Stakeholder Drivers
(Environment, Technology Evolution, )
Influence

Stakeholder Needs
Benefits
Realisation

Risk
Optimisation

Resource
Optimisation
Cascade to

Enterprise Goals

Appendix D
Figure 5

Cascade to

Appendix B

Figure 6

IT-related Goals
Cascade to

Appendix C

Enabler Goals
Source: COBIT 5, figure 4

2012 ISACA.

All Rights reserved.

You might also like