|

PEDERIVA, 2003

Título: The COBIT Maturity Model in a Vendor Evaluation Case.

In: Information Systems Control Journal, Volume 3

Tipo documento: Artigo

Autor(es): PEDERIVA, Andrea

Ano: 2003

Local: http://www.isaca.org/Template.cfm?Section=Home&CONTENTID=16253&TEMPLATE=/ContentManagement/ContentDisplay.cfm

Palavras-Chave:
Resumo:

The COBIT Maturity Model is an IT governance tool used to measure how well developed the management processes are with respect to internal controls.

A fundamental feature of the maturity model is that it allows an organization to measure as-is maturity levels, and define to-be maturity levels as well as gaps to fill. As a result, an organization can discover practical improvements to the system of internal controls of IT. However, maturity levels are not a goal, but rather they are a means to evaluate the adequacy of the internal controls with respect to company business objectives.

Lessons Learned

Because of its construction criteria, the questionnaire is aligned completely with the maturity model and fairly detailed with respect to the maturity requirements. This has proven to be useful to support subsequent discussions aimed at identifying the key points that were enabling or preventing the organization to reach a given maturity level.

As a suggestion, in performing a benchmarking effort, first discuss the maturity requirements without showing the maturity level in which the questions belong. This will reduce any bias by the respondents that can be present when they know the effects of the answers on the final result.

To make the method applicable beyond comparison, as with planning improvements (as-is, to-be, gap analysis), it must manage partial compliance at lower levels. That is not an issue in the method presented here, but for improvements one wants to see consistency at the lower levels before evaluating the contributions at the higher levels.

Posts Similares

  • |

    MCGINNIS ET AL., 2004

    Título: Sustaining and Extending Organization Strategy via Information Technology Governance. In: 37th Hawaii International Conference on System Sciences. Tipo documento: Artigo Autor(es): MCGINNIS, Sheila et al. Ano: 2004 Local: http://csdl2.computer.org/comp/proceedings/hicss/2004/2056/06/205660158.pdf Palavras-Chave: Resumo: This paper summarizes commonly accepted theories of corporate governance and extends them to information technology governance in United States (US) hospitals. It goes…

  • REZENDE, 2002

    Título: Alinhamento do planejamento estratégico da tecnologia da informação ao planejamento empresarial: proposta de um modelo e verificação da prática em grandes empresas brasileiras. In: Programa de Pós-Graduação em Engenharia de Produção, Universidade Federal de Santa Catarina Tipo documento: Tese de Doutorado Autor(es): REZENDE, Denis Alcides Ano: 2002 Local: Palavras-Chave: Planejamento da Tecnologia da Informação,…

  • ALI; GREEN, 2007

    Título: IT Governance Mechanisms in Public Sector Organisations: An Australian Context. In: Journal of Global Information Management, Vol. 15, Issue 4 Tipo documento: Artigo Autor(es): ALI, Syaiful; GREEN, Peter Ano: 2007 Local: http://www.igi-pub.com Palavras-Chave: IS perfomance; IT governance; IT governance mechanisms; public sector organisations; steering committees Resumo: Information technology plays a significant role enabling organisations…

  • SETHIBE; CAMPBELL; MCDONALD, 2007

    Título: IT Governance in Public and Private Sector Organisations: Examining the Differences and Defining Future Research Directions. In: 18th Australasian Conference on Information Systems. Toowoomba. Tipo documento: Artigo Autor(es): SETHIBE, Tsholofelo; CAMPBELL, John; MCDONALD, Craig Ano: 2007 Local: http://www.acis2007.usq.edu.au/assets/papers/137.pdf Palavras-Chave: IT Governance, Public and Private sector organisations Resumo: Government agencies constitute a significant component of…

  • Agilidade e Planejamento – Um Novo Olhar para TI

    No mundo ágil, o foco não é apenas na rapidez, mas na entrega contínua de valor adaptável às mudanças, destaca a Professora Diana Santos. O que isso significa para a TI? Adotar práticas que permitam revisões frequentes do planejamento estratégico. Estabelecer ciclos curtos de entrega, onde feedbacks possam ser rapidamente incorporados. Garantir que a TI…

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *