2 : ENABLING PROCESSES ISACA ® With 95,000 constituents in 160 countries, ISACA (www.isaca.org) is a leading global provider of knowledge, certifications, community, advocacy and education on information systems (IS) assurance and security, enterprise governance and management of IT, and IT-related risk and compliance. Founded in 1969, the non-profit, independent ISACA hosts international conferences, publishes the ISACA ® Journal, and develops international IS auditing and control standards, which help its constituents ensure trust in, and value from, information systems. It also advances and attests IT skills and knowledge through the globally respected Certified Information Systems Auditor ® (CISA ® ), Certified Information Security Manager ® (CISM ® ), Certified in the Governance of Enterprise IT ® (CGEIT ® ) and Certified in Risk and Information Systems Control TM (CRISC TM ) designations. ISACA continually updates COBIT ® , which helps IT professionals and enterprise leaders fulfil their IT governance and management responsibilities, particularly in the areas of assurance, security, risk and control, and deliver value to the business. Disclaimer ISACA has designed this publication, COBIT ® 5: <strong>Enabling</strong> <strong>Processes</strong> (the ‘Work’), primarily as an educational resource for governance of enterprise IT (GEIT), assurance, risk and security professionals. ISACA makes no claim that use of any of the Work will assure a successful outcome. The Work should not be considered inclusive of all proper information, procedures and tests or exclusive of other information, procedures and tests that are reasonably directed to obtaining the same results. In determining the propriety of any specific information, procedure or test, readers should apply their own professional judgement to the specific GEIT, assurance, risk and security circumstances presented by the particular systems or information technology environment. Copyright © 2012 ISACA. All rights reserved. For usage guidelines, see www.isaca.org/COBITuse. ISACA 3701 Algonquin Road, Suite 1010 Rolling Meadows, IL 60008 USA Phone: +1.847.253.1545 Fax: +1.847.253.1443 Email: info@isaca.org Web site: www.isaca.org Feedback: www.isaca.org/cobit Participate in the ISACA Knowledge Center: www.isaca.org/knowledge-center Follow ISACA on Twitter: https://twitter.com/ISACANews Join the COBIT conversation on Twitter: #COBIT Join ISACA on LinkedIn: ISACA (Official), http://linkd.in/ISACAOfficial Like ISACA on Facebook: www.facebook.com/ISACAHQ COBIT ® 5: <strong>Enabling</strong> <strong>Processes</strong> ISBN 978-1-60420-241-0 Printed in the United States of America Personal Copy of: Mr. Dong Hong Wang
ACKNOWLEDGEMENTS ISACA wishes to recognise: COBIT 5 Task Force (2009-2011) John W. Lainhart, IV, CISA, CISM, CGEIT, IBM Global Business Services, USA, Co-chair Derek J. Oliver, Ph.D., CISA, CISM, CRISC, CITP, DBA, FBCS, FISM, MInstISP, Ravenswood Consultants Ltd., UK, Co-chair Pippa G. Andrews, CISA, ACA, CIA, KPMG, Australia Elisabeth Judit Antonsson, CISM, Nordea Bank, Sweden Steven A. Babb, CGEIT, CRISC, Betfair, UK Steven De Haes, Ph.D., University of Antwerp Management School, Belgium Peter Harrison, CGEIT, FCPA, IBM Australia Ltd., Australia Jimmy Heschl, CISA, CISM, CGEIT, ITIL Expert, bwin.party digital entertainment plc, Austria Robert D. Johnson, CISA, CISM, CGEIT, CRISC, CISSP, Bank of America, USA Erik H.J.M. Pols, CISA, CISM, Shell International-ITCI, The Netherlands Vernon Richard Poole, CISM, CGEIT, Sapphire, UK Abdul Rafeq, CISA, CGEIT, CIA, FCA, A. Rafeq and Associates, India Development Team Floris Ampe, CISA, CGEIT, CIA, ISO 27000, PwC, Belgium Gert du Preez, CGEIT, PwC, Canada Stefanie Grijp, PwC, Belgium Gary Hardy, CGEIT, IT Winners, South Africa Bart Peeters, PwC, Belgium Dirk Steuperaert, CISA, CGEIT, CRISC, IT In Balance BVBA, Belgium Workshop Participants Gary Baker, CGEIT, CA, Canada Brian Barnier, CGEIT, CRISC, ValueBridge Advisors, USA Johannes Hendrik Botha, MBCS-CITP, FSM, getITright Skills Development, South Africa Ken Buechler, CGEIT, CRISC, PMP, Great-West Life, Canada Don Caniglia, CISA, CISM, CGEIT, FLMI, USA Mark Chaplin, UK Roger Debreceny, Ph.D., CGEIT, FCPA, University of Hawaii at Manoa, USA Mike Donahue, CISA, CISM, CGEIT, CFE, CGFM, CICA, Towson University, USA Urs Fischer, CISA, CRISC, CPA (Swiss), Fischer IT GRC Consulting & Training, Switzerland Bob Frelinger, CISA, CGEIT, Oracle Corporation, USA James Golden, CISM, CGEIT, CRISC, CISSP, IBM, USA Meenu Gupta, CISA, CISM, CBP, CIPP, CISSP, Mittal Technologies, USA Gary Langham, CISA, CISM, CGEIT, CISSP, CPFA, Australia Nicole Lanza, CGEIT, IBM, USA Philip Le Grand, PRINCE2, Ideagen Plc, UK Debra Mallette, CISA, CGEIT, CSSBB, Kaiser Permanente IT, USA Stuart MacGregor, Real IRM Solutions (Pty) Ltd., South Africa Christian Nissen, CISM, CGEIT, FSM, CFN People, Denmark Jamie Pasfield, ITIL V3, MSP, PRINCE2, Pfizer, UK Eddy J. Schuermans, CGEIT, ESRAS bvba, Belgium Michael Semrau, RWE Germany, Germany Max Shanahan, CISA, CGEIT, FCPA, Max Shanahan & Associates, Australia Alan Simmonds, TOGAF9, TCSA, PreterLex, UK Cathie Skoog, CISM, CGEIT, CRISC, IBM, USA Dejan Slokar, CISA, CGEIT, CISSP, Deloitte & Touche LLP, Canada Roger Southgate, CISA, CISM, UK Nicky Tiesenga, CISA, CISM, CGEIT, CRISC, IBM, USA Wim Van Grembergen, Ph.D., University of Antwerp Management School, Belgium Greet Volders, CGEIT, Voquals N.V., Belgium Christopher Wilken, CISA, CGEIT, PwC, USA Tim M. Wright, CISA, CRISC, CBCI, GSEC, QSA, Kingston Smith Consulting LLP, UK Personal Copy of: Mr. Dong Hong Wang ACKNOWLEDGEMENTS 3
- Page 1: Enabling Processes Personal Copy of
- Page 5 and 6: ACKNOWLEDGEMENTS (CONT.) ACKNOWLEDG
- Page 7 and 8: TABLE OF CONTENTS TABLE OF CONTENTS
- Page 9 and 10: LIST OF FIGURES LIST OF FIGURES Fig
- Page 11 and 12: CHAPTER 1 INTRODUCTION CHAPTER 1 IN
- Page 13 and 14: CHAPTER 2. THE GOALS CASCADE AND ME
- Page 15 and 16: CHAPTER 2. THE GOALS CASCADE AND ME
- Page 17 and 18: CHAPTER 2. THE GOALS CASCADE AND ME
- Page 19 and 20: CHAPTER 3 THE COBIT 5 PROCESS MODEL
- Page 21 and 22: Enabler Performance Management CHAP
- Page 23 and 24: CHAPTER 4 THE COBIT 5 PROCESS REFER
- Page 25 and 26: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 27 and 28: Generic Guidance for Processes CHAP
- Page 29 and 30: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 31 and 32: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 33 and 34: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 35 and 36: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 37 and 38: EDM02 Process Practices, Inputs/Out
- Page 39 and 40: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 41 and 42: EDM03 Process Practices, Inputs/Out
- Page 43 and 44: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 45 and 46: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 47 and 48: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 49 and 50: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 51 and 52: CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 53 and 54:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 55 and 56:
APO01 Process Practices, Inputs/Out
- Page 57 and 58:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 59 and 60:
APO02 Process Practices, Inputs/Out
- Page 61 and 62:
APO02 Process Practices, Inputs/Out
- Page 63 and 64:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 65 and 66:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 67 and 68:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 69 and 70:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 71 and 72:
APO04 Manage Innovation (cont.) CHA
- Page 73 and 74:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 75 and 76:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 77 and 78:
APO05 Process Practices, Inputs/Out
- Page 79 and 80:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 81 and 82:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 83 and 84:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 85 and 86:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 87 and 88:
APO07 Process Practices, Inputs/Out
- Page 89 and 90:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 91 and 92:
APO08 Process Practices, Inputs/Out
- Page 93 and 94:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 95 and 96:
APO09 Process Practices, Inputs/Out
- Page 97 and 98:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 99 and 100:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 101 and 102:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 103 and 104:
APO11 Process Practices, Inputs/Out
- Page 105 and 106:
APO11 Process Practices, Inputs/Out
- Page 107 and 108:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 109 and 110:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 111 and 112:
APO12 Process Practices, Inputs/Out
- Page 113 and 114:
APO13 Manage Security Process Descr
- Page 115 and 116:
APO13 Process Practices, Inputs/Out
- Page 117 and 118:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 119 and 120:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 121 and 122:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 123 and 124:
BAI01 Process Practices, Inputs/Out
- Page 125 and 126:
BAI01 Process Practices, Inputs/Out
- Page 127 and 128:
BAI01 Process Practices, Inputs/Out
- Page 129 and 130:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 131 and 132:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 133 and 134:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 135 and 136:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 137 and 138:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 139 and 140:
BAI03 Process Practices, Inputs/Out
- Page 141 and 142:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 143 and 144:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 145 and 146:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 147 and 148:
BAI05 Process Practices, Inputs/Out
- Page 149 and 150:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 151 and 152:
BAI06 Process Practices, Inputs/Out
- Page 153 and 154:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 155 and 156:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 157 and 158:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 159 and 160:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 161 and 162:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 163 and 164:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 165 and 166:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 167 and 168:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 169 and 170:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 171 and 172:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 173 and 174:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 175 and 176:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 177 and 178:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 179 and 180:
DSS02 Process Practices, Inputs/Out
- Page 181 and 182:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 183 and 184:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 185 and 186:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 187 and 188:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 189 and 190:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 191 and 192:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 193 and 194:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 195 and 196:
DSS05 Process Practices, Inputs/Out
- Page 197 and 198:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 199 and 200:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 201 and 202:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 203 and 204:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 205 and 206:
MEA01 Process Practices, Inputs/Out
- Page 207 and 208:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 209 and 210:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 211 and 212:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 213 and 214:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 215 and 216:
CHAPTER 5 COBIT 5 PROCESS REFERENCE
- Page 217 and 218:
APPENDIX A MAPPING BETWEEN COBIT 5
- Page 219 and 220:
APPENDIX A MAPPING BETWEEN COBIT 5
- Page 221 and 222:
APPENDIX A MAPPING BETWEEN COBIT 5
- Page 223 and 224:
APPENDIX A MAPPING BETWEEN COBIT 5
- Page 225 and 226:
APPENDIX B DETAILED MAPPING ENTERPR
- Page 227 and 228:
APPENDIX C DETAILED MAPPING IT-RELA
- Page 229 and 230:
Deliver, Service and Support Monito