SlideShare une entreprise Scribd logo
1  sur  7
COBIT 5 & 4.1 Comparison




      ANTHONY DEHNASHI
      (PARSYSTECH.COM)
            2013
Overview

 A brief overview of changes in COBIT 5 vs. COBIT 4.1
 COBIT 5 now covers:
   The governance for the enterprise as a whole and not just IT.

   It includes RISK-IT and VAL-IT which were introduced before
    as separate frameworks to cover the risk management and
    value management/delivery of IT work.
   It has been shaped as an integrated framework where provides
    the simple and easy way for integration with other
    frameworks such as ITIL, TOGAF, ISO 27000, ….
   It separates governance from management.
Improvements

                                     Improvements

     Considerable             COBIT 5 now          The improvements to       The most significant
improvements to make        introduced as an         COBIT 5 include        change to COBIT is the
COBIT 5 a model for the   integrated solution in     restructuring the       reorganization of the
corporate ® governance    order to easily glued     description of the      framework from being
    of information        and work with other      individual processes,     an IT process model
 technology. Unlike its       frameworks.          identifying the actual   into an IT governance
predecessor, the COBIT                             base practices within    framework with a set of
 5 addresses/covers all                              each process and       governance practices
  three levels of an IT                             describing the key      for IT, a management
governance framework.                              activities within each       system for the
                                                      base practice.              continuous
                                                                              improvement of IT
                                                                            activities and a process
                                                                             model with baseline
                                                                                   practices.
Process Change Log Summary


 Merged
                               Reassigned                 Relocated                       Net New
Processes
                                                                                            EDM1 Set and Maintain
   DS7 is merged with PO7                                                                Governance Framework  APO1
   (Education and Human                                                                     Define the Management
         Resources)                                                                               Framework


                                                            PO1 to APO2 (Strategic         APO4 Manage Innovation
   PO6 is merged with PO1                                         Planning)                     (partly PO3)
(Management 
Communications
      and Management)

                                                                                          APO8 Manage Relationships
    PO2 is merged with PO3
  (Information and Technical    ME4 to EDM1, 2, 3, 4, 5
                                   (Governance)
        
Architectures)
                                                                                         BAI8 Knowledge Management

    AI2 is merged with AI3
   (Application Software and
 
Infrastructure Components)                                                              DSS2 Manage Assets (partly
                                                          PO4 to APO1 (Organization,
                                                          Relationships and Processes)             DS9)


   DS12 is merged with DS5
 (Physical Environment 
and                                                              DSS8 Manage Business Process
    Information Security)                                                                        Controls.
COBIT 5 Implementation

                                      Implementing COBIT 5


  COBIT 5 comprises an          The COBIT 5 framework          The COBIT 5 process         Implementing COBIT 5
 operational model and a            includes a process         model is a complete,        starts with determining
common language for all            reference model and       comprehensive model that         which stakeholder
   parts of the business        defines and describes the    an enterprise must tailor     interests have priority,
involved in IT activities. It       management and            to its own specific needs         what are their
also provides a framework       governance processes. The    after taking into account     expectations, what is the
    for measuring and            process reference model       the internal business      IT functions capability to
      monitoring IT             includes all the processes      needs, the external       satisfy these expectations
performance, integrating          normally found in an        business pressures and      and who is accountable for
    best management              enterprise relating to IT   the various stakeholders’    doing so. This will require
practices, governance and         activities, providing a        expectation of the         knowledge about the
   communicating with           common reference model,       organization and the IT     underlying processes and
       stakeholders.                understandable to                function.            management system that
                                   operational IT and                                      supports the IT function
                                   business managers.                                      deliver the services and
                                                                                           performance expected.
Upgrading

                                               Upgrade from 4.1 to 5


COBIT 5 builds on the process        Organizations already at a         Where an organization has        Completely new for most
 model previously defined in         COBIT maturity level of at            made considerable              organizations will be the
earlier releases of COBIT. It is    least 2 (measured using ISO       investments in implementing      introduction of a management
 an evolutionary change that        15504) will find the upgrade      the COBIT 4.1 processes it may     system and a governance
 has rationalized the existing        relatively easy. However        be desirable to first complete   framework. This will require
processes through combining         organizations at a maturity       this initiative before merging       managers to develop a
  and reassigning practices          level 1 are likely to find the     the COBIT 4.1 processes to      structured approach to how
within the existing processes       upgrade from COBIT 4.1 to            align with the COBIT 5        they plan, organize, direct and
   and including additional          COBIT 5 to be challenging.                 processes.             control resources and deliver
processes and practices for the       Organizations currently                                            the performance required.
management and governance          operating at a maturity level of
  of information technology.       1 or below (i.e. without defined
                                   processes in place) may find it
                                   easier and more cost efficient
                                     to adopt COBIT 5 and start
                                   afresh using the new COBIT 5
                                             framework.
Resources & References

 To get a full comparison of COBIT 5 and 4.1 please
 refer to the following links on ISACA site.
    http://www.isaca.org/COBIT/Documents/Compare-with-
     4.1.pdf
    http://www.isaca.org/COBIT/Documents/Comparing-
     COBIT.pdf
 References & Sources
   ISACA

   IT governance

   COBIT 5 & 4.1

Contenu connexe

Tendances

COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise ITCOBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
Mark Constable
 

Tendances (20)

CISA Training - Chapter 5 - 2016
CISA Training - Chapter 5 - 2016CISA Training - Chapter 5 - 2016
CISA Training - Chapter 5 - 2016
 
Itil,cobit and ıso27001
Itil,cobit and ıso27001Itil,cobit and ıso27001
Itil,cobit and ıso27001
 
IT Governance - COBIT 5 Capability Assessment
IT Governance - COBIT 5 Capability AssessmentIT Governance - COBIT 5 Capability Assessment
IT Governance - COBIT 5 Capability Assessment
 
Basics in IT Audit and Application Control Testing
Basics in IT Audit and Application Control Testing Basics in IT Audit and Application Control Testing
Basics in IT Audit and Application Control Testing
 
COBIT5 Introduction
COBIT5 IntroductionCOBIT5 Introduction
COBIT5 Introduction
 
It governance & cobit 5
It governance & cobit 5It governance & cobit 5
It governance & cobit 5
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit Club
 
Introduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT managementIntroduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT management
 
Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
 
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise ITCOBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
COBIT 2019 webinar Use Cases: Tailoring Governance of Your Enterprise IT
 
What is Cobit
What is CobitWhat is Cobit
What is Cobit
 
Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)
 
Auditing SOX ITGC Compliance
Auditing SOX ITGC ComplianceAuditing SOX ITGC Compliance
Auditing SOX ITGC Compliance
 
Qap cobit2019-20181111
Qap cobit2019-20181111Qap cobit2019-20181111
Qap cobit2019-20181111
 
It governance
It governanceIt governance
It governance
 
COBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdfCOBIT 2019 Overview_v1.1.pdf
COBIT 2019 Overview_v1.1.pdf
 
Itil v4-mindmap
Itil v4-mindmapItil v4-mindmap
Itil v4-mindmap
 
Comprehending Information Technology Governance
Comprehending Information Technology GovernanceComprehending Information Technology Governance
Comprehending Information Technology Governance
 
IT Audit For Non-IT Auditors
IT Audit For Non-IT AuditorsIT Audit For Non-IT Auditors
IT Audit For Non-IT Auditors
 

Similaire à COBIT 5 & 4.1 Comparison

Comparación de CobiT 5 con CobiT 4.1
Comparación de CobiT 5 con  CobiT 4.1Comparación de CobiT 5 con  CobiT 4.1
Comparación de CobiT 5 con CobiT 4.1
Slime Argentina
 

Similaire à COBIT 5 & 4.1 Comparison (20)

Cobit® 5 Comparação com Cobit® 4
Cobit® 5 Comparação com Cobit® 4Cobit® 5 Comparação com Cobit® 4
Cobit® 5 Comparação com Cobit® 4
 
Cobit5 compare-with-4.1
Cobit5 compare-with-4.1Cobit5 compare-with-4.1
Cobit5 compare-with-4.1
 
Tatakelola Teknologi Informasi
Tatakelola Teknologi InformasiTatakelola Teknologi Informasi
Tatakelola Teknologi Informasi
 
Cobit 4.1 Highlights
Cobit 4.1 HighlightsCobit 4.1 Highlights
Cobit 4.1 Highlights
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
Cobit 4.1 ivooktavianti
Cobit 4.1 ivooktaviantiCobit 4.1 ivooktavianti
Cobit 4.1 ivooktavianti
 
Cobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktaviantiCobit 4.1 ivo oktavianti
Cobit 4.1 ivo oktavianti
 
COBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-EndCOBIT 5 Principal 2 Covering the Enterprise End-To-End
COBIT 5 Principal 2 Covering the Enterprise End-To-End
 
Uas dwi widiastuti
Uas dwi widiastutiUas dwi widiastuti
Uas dwi widiastuti
 
COBIT 2019 - DIGITAL TRUST FRAMEWORK
COBIT 2019 - DIGITAL TRUST FRAMEWORKCOBIT 2019 - DIGITAL TRUST FRAMEWORK
COBIT 2019 - DIGITAL TRUST FRAMEWORK
 
Comparación de CobiT 5 con CobiT 4.1
Comparación de CobiT 5 con  CobiT 4.1Comparación de CobiT 5 con  CobiT 4.1
Comparación de CobiT 5 con CobiT 4.1
 
The Room | Innotrain systematization
The Room | Innotrain systematization The Room | Innotrain systematization
The Room | Innotrain systematization
 
Darmin ritonga 11353205418
Darmin ritonga 11353205418Darmin ritonga 11353205418
Darmin ritonga 11353205418
 
PPT-UEU-Topik-dalam-IT-Resources-Management-13.pptx
PPT-UEU-Topik-dalam-IT-Resources-Management-13.pptxPPT-UEU-Topik-dalam-IT-Resources-Management-13.pptx
PPT-UEU-Topik-dalam-IT-Resources-Management-13.pptx
 
Cobit5 introduction
Cobit5 introductionCobit5 introduction
Cobit5 introduction
 
Cobit 4.1 indri
Cobit 4.1 indriCobit 4.1 indri
Cobit 4.1 indri
 
IT Management Toolkit - ITIL Is Not Enough
IT Management Toolkit - ITIL Is Not EnoughIT Management Toolkit - ITIL Is Not Enough
IT Management Toolkit - ITIL Is Not Enough
 
Cobit5
Cobit5Cobit5
Cobit5
 
Dit yvol3iss28
Dit yvol3iss28Dit yvol3iss28
Dit yvol3iss28
 
ITIL , DevOps and IT4IT
ITIL , DevOps and IT4ITITIL , DevOps and IT4IT
ITIL , DevOps and IT4IT
 

Dernier

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Dernier (20)

FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 

COBIT 5 & 4.1 Comparison

  • 1. COBIT 5 & 4.1 Comparison ANTHONY DEHNASHI (PARSYSTECH.COM) 2013
  • 2. Overview  A brief overview of changes in COBIT 5 vs. COBIT 4.1  COBIT 5 now covers:  The governance for the enterprise as a whole and not just IT.  It includes RISK-IT and VAL-IT which were introduced before as separate frameworks to cover the risk management and value management/delivery of IT work.  It has been shaped as an integrated framework where provides the simple and easy way for integration with other frameworks such as ITIL, TOGAF, ISO 27000, ….  It separates governance from management.
  • 3. Improvements Improvements Considerable COBIT 5 now The improvements to The most significant improvements to make introduced as an COBIT 5 include change to COBIT is the COBIT 5 a model for the integrated solution in restructuring the reorganization of the corporate ® governance order to easily glued description of the framework from being of information and work with other individual processes, an IT process model technology. Unlike its frameworks. identifying the actual into an IT governance predecessor, the COBIT base practices within framework with a set of 5 addresses/covers all each process and governance practices three levels of an IT describing the key for IT, a management governance framework. activities within each system for the base practice. continuous improvement of IT activities and a process model with baseline practices.
  • 4. Process Change Log Summary Merged Reassigned Relocated Net New Processes EDM1 Set and Maintain DS7 is merged with PO7 Governance Framework  APO1 (Education and Human Define the Management Resources) Framework PO1 to APO2 (Strategic APO4 Manage Innovation PO6 is merged with PO1 Planning) (partly PO3) (Management 
Communications and Management) APO8 Manage Relationships PO2 is merged with PO3 (Information and Technical ME4 to EDM1, 2, 3, 4, 5 (Governance) 
Architectures) BAI8 Knowledge Management AI2 is merged with AI3 (Application Software and 
Infrastructure Components) DSS2 Manage Assets (partly PO4 to APO1 (Organization, Relationships and Processes) DS9) DS12 is merged with DS5 (Physical Environment 
and DSS8 Manage Business Process Information Security) Controls.
  • 5. COBIT 5 Implementation Implementing COBIT 5 COBIT 5 comprises an The COBIT 5 framework The COBIT 5 process Implementing COBIT 5 operational model and a includes a process model is a complete, starts with determining common language for all reference model and comprehensive model that which stakeholder parts of the business defines and describes the an enterprise must tailor interests have priority, involved in IT activities. It management and to its own specific needs what are their also provides a framework governance processes. The after taking into account expectations, what is the for measuring and process reference model the internal business IT functions capability to monitoring IT includes all the processes needs, the external satisfy these expectations performance, integrating normally found in an business pressures and and who is accountable for best management enterprise relating to IT the various stakeholders’ doing so. This will require practices, governance and activities, providing a expectation of the knowledge about the communicating with common reference model, organization and the IT underlying processes and stakeholders. understandable to function. management system that operational IT and supports the IT function business managers. deliver the services and performance expected.
  • 6. Upgrading Upgrade from 4.1 to 5 COBIT 5 builds on the process Organizations already at a Where an organization has Completely new for most model previously defined in COBIT maturity level of at made considerable organizations will be the earlier releases of COBIT. It is least 2 (measured using ISO investments in implementing introduction of a management an evolutionary change that 15504) will find the upgrade the COBIT 4.1 processes it may system and a governance has rationalized the existing relatively easy. However be desirable to first complete framework. This will require processes through combining organizations at a maturity this initiative before merging managers to develop a and reassigning practices level 1 are likely to find the the COBIT 4.1 processes to structured approach to how within the existing processes upgrade from COBIT 4.1 to align with the COBIT 5 they plan, organize, direct and and including additional COBIT 5 to be challenging. processes. control resources and deliver processes and practices for the Organizations currently the performance required. management and governance operating at a maturity level of of information technology. 1 or below (i.e. without defined processes in place) may find it easier and more cost efficient to adopt COBIT 5 and start afresh using the new COBIT 5 framework.
  • 7. Resources & References  To get a full comparison of COBIT 5 and 4.1 please refer to the following links on ISACA site.  http://www.isaca.org/COBIT/Documents/Compare-with- 4.1.pdf  http://www.isaca.org/COBIT/Documents/Comparing- COBIT.pdf  References & Sources  ISACA  IT governance  COBIT 5 & 4.1