COBITI
Nkhani iyi yina masuzgo ghangapo. Chonde vwilani pakusazgilapo vinyake panji dumbizganani masuzgo ghake na nthowa izo mungainozgela pa jani lake lakudumbizgilana. (Sambililani umo mungauskilapo uthenga uwu)
|
Template:Information technology management COBIT (Control Objectives for Information and Related Technologies) ni framework iyo yakupangika na ISACA ya information technology (IT) management na IT governance.[1]
Framework iyi njakuyang'ana pa business ndipo yikulongosora mndandanda wa ma generic processes gha management ya IT, apo process yiliyose njakulongosoleka pamoza na process inputs na outputs, key process-activities, process objectives, performance measures na elementary maturity model.[1]
Framework and components
[lemba | kulemba source]Vilato vya business na IT vyakolelaneskeka na kupimika kuti vipange milimo ya magulu gha business na IT teams.
Ma process ghankhondi ghasangika:[2]
- Evaluate, Direct and Monitor (EDM)
- Align, Plan and Organize (APO)
- Build, Acquire and Implement (BAI)
- Deliver, Service and Support (DSS)
- Monitor, Evaluate and Assess (MEA)
COBIT framework iyi yikukolerana na COSO, ITIL,[3] BiSL, ISO 27000, CMMI, TOGAF na PMBOK.[1]
Framework iyi yikovwira makampani kulondezga dango, kuŵa agile na kusanga ndalama zinandi.[4]
Pasi apa pali COBIT components:
- Framework: Yikunozga IT governance objectives na good practices kwizira mwa IT domains na processes ndipo yikuzikoleranya na business requirements.
- Process descriptions: Ndondomeko ya reference process model na chiyowoyero chamoza kwa waliyose mu organization. Ma process agha ghakulunjikana na responsibility areas gha plan, build, run, na monitor.
- Control objectives: Yikupeleka mndandanda wamsuma wa high-level requirements ghakuti ghawolembeeke na management kwa control yiwemi ya process yiliyose ya IT.
- Management guidelines: Yikovwira kugaŵa milimo, kukolerana pa objectives, kupima performance, na kulongora kukolerana na ma process ghanyake.
- Maturity models: Yikupima maturity na capability pa process yiliyose ndipo yikovwira kumala mipata gha gaps.
Standard iyi yikufiska vyakukhumbikwa vyose vya practice, uku yikusunga independence kufuma ku specific manufacturers, technologies na platforms. Pakupanga standard iyi, vikaŵa machitiko kuyigwiliskira ntchito pa auditing ya IT system ya kampani na pa designing ya IT system. Pa nkhani yakwamba, COBIT yikuzomerezgani kusanga degree of conformity ya system iyo yikupendeka kwenda ku vyelezgero viwemi chomene, ndipo pa nkhani yachiŵiri, ku-design system iyo njakufikapo mu makhaliro ghake.
Information criteria
[lemba | kulemba source]Information criteria ni core component ya COBIT framework iyo yikulongosora chilato cha objectives. Vinthu veneko ni control ya:[5]
Effectiveness yikuyowoya za information kuŵa relevant na pertinent ku business process ndipo yikwiza mu nyengo yakwenelera, yakunyoloka, consistent na mu nthowa yiwemi yakugwiliskira ntchito.
Efficiency yikukhwaskana na kupeleka kwa information kwizira mu optimal (most productive na economical) use of resources.
Confidentiality yikukhwaskana na kuvikilirika kwa sensitive information kufuma ku unauthorised disclosure.
Integrity yikukolerana na accuracy na completeness ya information pamoza na validity yake kwenda pa business values na expectations.
Availability yikukolerana na kuŵapo kwa information para yikukhumbikwa na business process pa sasa na munthazi. Yikukhwaskana so na kuvikilira resources zakukhumbikwa na associated capabilities.
Compliance yikukhwaskana na kulondezga malango, regulations na contractual arrangements ivyo business process yili pasi pake, monga externally imposed business criteria pamoza na internal policies.
Reliability yikukolerana na kupeleka kwa information yakwenelera ya management kuti yiyendeske entity na kuchita milimo yake ya fiduciary na governance responsibilities.
History
[lemba | kulemba source]COBIT pakwamba yikaŵa "Control Objectives for Information and Related Technologies," nangauli pambere framework iyi yindafumiskike ŵanthu ŵakayowoyanga za "CobiT" monga "Control Objectives for IT"[6] panji "Control Objectives for Information and Related Technology."[7]
ISACA yikafumiska kakwamba COBIT mu chaka cha 1996, pakwamba monga mndandanda wa control objectives[longosolani makola] wakovwira financial audit community kuti ŵende makora mu ma-environment ghakukhwaskana na IT.[1][8] Wati wawona kuzirwa kwa kusazgirako framework iyi kuluska waka charu cha auditing, ISACA yikafumiska version 2 yisani mu chaka cha 1998 ndipo yikayisazgirako chomene pakusazgapo management guidelines mu version 3 ya chaka cha 2000. Kupangika kwa AS 8015: Australian Standard for Corporate Governance of Information and Communication Technology mu January 2005[9] na international draft standard ISO/IEC DIS 29382 (iyo pakolwera yikazgoka ISO/IEC 38500) mu January 2007[10] kukasazgirako kumanya za kukhumbikwa kwa components zanyake za information and communication technology (ICT) governance. Mwa nthowa yambura kutondeka, ISACA ikasazgapo components/frameworks zakukolerana nazo mu ma-version 4 na 4.1 mu vyaka vya 2005 na 2007 mndandanda wake, yikalazganga pa IT-related business processes na responsibilities mu value creation (Val IT) na risk management (Risk IT)."[1][8]
COBIT 5 (2012) yilikuzikika pa COBIT 4.1, Val IT 2.0 na Risk IT frameworks, ndipo yikutora kufuma mu ISACA's IT Assurance Framework (ITAF) na Business Model for Information Security (BMIS).[11][12]
Pa sasa apa ISACA yikupeleka ma-certification track pa COBIT 2019 (COBIT Foundations, COBIT Design & Implementation, na Implementing the NIST Cybersecurity Framework Using COBIT 2019)[13] pamoza na certification mu version yakale (COBIT 5).[14][15]
Wonani so
[lemba | kulemba source]References
[lemba | kulemba source]- 1 2 3 4 5 Haes, S.D.; Grembergen, W.V. (2015). "Chapter 5: COBIT as a Framework for Enterprise Governance of IT". Enterprise Governance of Information Technology: Achieving Alignment and Value, Featuring COBIT 5 (2nd ed.). Springer. pp. 103–128. ISBN 9783319145471. Retrieved 24 June 2016.
- ↑ COBIT 2019 Framework: Introduction and Methodology from ISACA
- ↑ ITIL Foundation: 4th edition. AXELOS. 2019. ISBN 9780113316076.
- ↑ Luellig, Lorrie; Frazier, J. (2013). "A COBIT Approach to Regulatory Compliance and Defensible Disposal". ISACA Journal. 5. Retrieved 24 June 2016.
- ↑ Sheikhpour, R.; Modiri, N. (1 January 2012). "(PDF) An approach to map COBIT processes to ISO/IEC 27001 information security management controls". International Journal of Security and Its Applications. 6 (2). NADIA: 13–28. ISSN 1738-9976. Retrieved 19 February 2026.
- ↑ Katsikas, S.; Gritzalis, D., eds. (1996). Information Systems Security: Facing the Information Society of the 21st Century. IFIP Advances in Information and Communication Technology. Springer. p. 358. ISBN 9780412781209.
The McCumber model has great similarities with the CobiT - Control Objectives for IT - framework (CobiT 1995).
- ↑ "Welcome to the ISACA/F". ISACA. 18 October 1996. Archived from the original on 7 November 1996. Retrieved 24 June 2016.
- 1 2 Stroud, R.E. (2012). "Introduction to COBIT 5" (PDF). ISACA. Retrieved 24 June 2016.
- ↑ da Cruz, M. (2006). "10: AS 8015-2005 - Australian Standard for Corporate Governance of ICT". In van Bon, J.; Verheijen, T. (eds.). Frameworks for IT Management. Van Haren Publishing. pp. 95–102. ISBN 9789077212905. Retrieved 23 June 2016.
- ↑ "ISO/IEC DIS 29382: 2007 Edition, February 1, 2007". IHS Standards Store. IHS, Inc. Archived from the original on 23 June 2016. Retrieved 23 June 2016.
- ↑ "COBIT 5 for Information Security". ISACA. Retrieved 24 June 2016.
- ↑ "COBIT 5 for Assurance". ISACA. Retrieved 24 June 2016.
- ↑ "COBIT Certifications | Get Your COBIT Certificate | ISACA".
- ↑ "COBIT 5 Certification | Get COBIT 5 Certified | ISACA".
- ↑ "Home". knowyourprivacyrights.org.
External links
[lemba | kulemba source]
- Articles lacking reliable references from April 2017
- All articles lacking reliable references
- Articles needing additional references from September 2024
- Articles lacking reliable references from September 2024
- Articles with multiple maintenance issues
- Wikipedia articles needing clarification from June 2018
- Information technology governance
- Information technology management
- Information technology audit
- Privacy