18.01.2013 Views

Enabling Processes

Enabling Processes

Enabling Processes

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

APO07 Process Practices, Inputs/Outputs and Activities (cont.)<br />

CHAPTER 5<br />

COBIT 5 PROCESS REFERENCE GUIDE CONTENTS<br />

Management Practice Inputs Outputs<br />

APO07.06 Manage contract staff.<br />

Ensure that consultants and contract personnel who<br />

support the enterprise with IT skills know and comply<br />

���� ��� �������������� �������� ��� ���� ���������<br />

contractual requirements.<br />

From Description Description To<br />

BAI01.04 Resource requirements<br />

and roles<br />

Contract staff policies Internal<br />

BAI01.12 ������� ��������<br />

requirements<br />

Contract agreements Internal<br />

BAI01.14 Communication of<br />

programme retirement and<br />

ongoing accountabilities<br />

Contract agreement<br />

reviews<br />

Activities<br />

�� ��������� �������� ��� ���������� ���� �������� ����� ��� ��� ���� ���� �� ���� ��� �� ��������� �� ��������� �� ����������� ������<br />

������������ �� ���������� ���� ��� �������������� �������������� �� ����������� ������ ��� ��� �� ������� ����������<br />

�� ������ ������ ��������� ���� ����������� �� ��� ������������ �� ��� �������� ���� ���� ��� �������� �� ������ ���� ��� ������������ �� �������<br />

framework, such as policies for security clearance, physical and logical access control, use of facilities, information confidentiality requirements, and<br />

non-disclosure agreements.<br />

3. Advise contractors that management reserves the right to monitor and inspect all usage of IT resources, including email, voice communications, and<br />

all programs and data files.<br />

4. Provide contractors with a clear definition of their roles and responsibilities as part of their contracts, including explicit requirements to document their<br />

work to agreed-on standards and formats.<br />

�� ������ ������������ ���� ��� ���� ��� �������� �� �������� �� ��� ��������<br />

6. Define all work performed by external parties in formal and unambiguous contracts.<br />

7. Conduct periodic reviews to ensure that contract staff have signed and agreed on all necessary agreements.<br />

�� ������� �������� ������� �� ������ ���� ������������ ����� ��� ������ ������ ��� ����������� ��� �� ���� ���� �����������<br />

APO07 Related Guidance<br />

Related Standard Detailed Reference<br />

������� ����� 8. Human Resources Security<br />

SFIA Skills reference<br />

Personal Copy of: Mr. Dong Hong Wang<br />

Internal<br />

87<br />

Align, Plan and Organise

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!