YaSM and COBIT: Difference between revisions
No edit summary |
No edit summary |
||
(3 intermediate revisions by 2 users not shown) | |||
Line 5: | Line 5: | ||
<meta property="og:title" content="YaSM and COBIT® | YaSM Service Management Wiki" /> | <meta property="og:title" content="YaSM and COBIT® | YaSM Service Management Wiki" /> | ||
<meta property="og:description" content="The following tables highlight which YaSM processes are related to specific COBIT® enabling processes, to illustrate that YaSM and COBIT share many basic principles." /> | <meta property="og:description" content="The following tables highlight which YaSM processes are related to specific COBIT® enabling processes, to illustrate that YaSM and COBIT share many basic principles." /> | ||
<meta property="og:site_name" content="YaSM"> | <meta property="og:site_name" content="YaSM Service Management"> | ||
<meta property="og:type" content="article" /> | <meta property="og:type" content="article" /> | ||
<meta property="og:image" content="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/cobit-enabling-processes-and-the-YaSM-model.jpg" /> | <meta property="og:image" content="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/cobit-enabling-processes-and-the-YaSM-model.jpg" /> | ||
<meta property="og:image:width" content="1200" /> | <meta property="og:image:width" content="1200" /> | ||
<meta property="og:image:height" content="900" /> | <meta property="og:image:height" content="900" /> | ||
<link href="https://plus.google.com/104150539756444616711/posts" rel="publisher" /> | <link href="https://plus.google.com/104150539756444616711/posts" rel="publisher" /> | ||
</itpmch> | </itpmch> | ||
Line 25: | Line 16: | ||
<p> </p> | <p> </p> | ||
<p><b>Comparison:</b> YaSM and COBIT® (Control Objectives for Information and Related Technologies)</p> | <p><b>Comparison:</b> YaSM and COBIT® (Control Objectives for Information and Related Technologies)</p> | ||
<p><b>Part of</b>: <a href="https://yasm.com/wiki/en/index.php/What_is_YaSM#yasm-other-service-management-frameworks" title="YaSM and other service management frameworks and standards">YaSM vs. other service management frameworks and standards</a></p> | <p><b>Part of</b>: <a href="https://yasm.com/wiki/en/index.php/What_is_YaSM#yasm-other-service-management-frameworks" title="YaSM and other service management frameworks and standards">YaSM vs. other service management frameworks and standards</a></html> | ||
<p> </p> | |||
[[What is YaSM|YaSM]]® was developed with <b><span style="color:#465674;">COBIT® (Control Objectives for Information and Related Technologies)</span></b> [[#COBIT|[1]]] in mind, but YaSM is not a "COBIT process model". | |||
<p> </p> | <p> </p> | ||
< | <html><div itemid="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/cobit-enabling-processes-and-the-YaSM-model.jpg" itemscope itemtype="https://schema.org/ImageObject"> | ||
< | |||
<meta itemprop="caption" content="COBIT® enabling processes and how they relate to YaSM service management processes." /> | <meta itemprop="caption" content="COBIT® enabling processes and how they relate to YaSM service management processes." /> | ||
<meta itemprop="width" content="1200" /> | <meta itemprop="width" content="1200" /> | ||
<meta itemprop="height" content="900" /> | <meta itemprop="height" content="900" /> | ||
<meta itemprop="representativeOfPage" content="true"/> | |||
<span itemprop="thumbnail" itemscope itemtype="https://schema.org/ImageObject"> | |||
<meta itemprop="url" content="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/480px/cobit-enabling-processes-and-the-YaSM-model.jpg" /> | |||
<meta itemprop="width" content="480" /> | |||
<meta itemprop="height" content="360" /> | |||
<meta itemprop="dateCreated" content="2022-10-03" /> | |||
<meta itemprop="datePublished" content="2022-10-03" /> | |||
</span> | |||
<meta itemprop="keywords" content="COBIT processes" /> | <meta itemprop="keywords" content="COBIT processes" /> | ||
<meta itemprop="keywords" content="COBIT enabling processes" /> | <meta itemprop="keywords" content="COBIT enabling processes" /> | ||
<meta itemprop="keywords" content="IT governance YaSM" /> | <meta itemprop="keywords" content="IT governance YaSM" /> | ||
<img | <figure class="mw-halign-right" typeof="mw:File/Thumb"><a itemprop="contentUrl" href="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/cobit-enabling-processes-and-the-YaSM-model.jpg" title="COBIT® enabling processes and the YaSM model"><img srcset="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/480px/cobit-enabling-processes-and-the-YaSM-model.jpg 480w, https://yasm.com/wiki/en/img/yasm-frameworks/cobit/cobit-enabling-processes-and-the-YaSM-model.jpg 1200w" sizes="100vw" src="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/cobit-enabling-processes-and-the-YaSM-model.jpg" fetchpriority="high" decoding="async" width="480" height="360" class="mw-file-element" alt="COBIT® enabling processes and how they relate to YaSM service management processes - cross-reference." /></a> | ||
<figcaption><span style="font-variant:small-caps;"><b>Fig. 1: What is COBIT® (Control Objectives for Information and Related Technologies)?</b><br /><a href="https://yasm.com/wiki/en/img/yasm-frameworks/cobit/cobit-enabling-processes-and-the-YaSM-model.jpg" title="COBIT® enabling processes and the YaSM service management model">COBIT enabling processes and YaSM service management</a>.</span></figcaption></figure></div></html> | |||
__TOC__ | |||
<br style="clear:both;"/> | |||
==<span id="about-cobit">About COBIT®</span>== | ==<span id="about-cobit">About COBIT®</span>== | ||
According to its authors, COBIT is an "overarching framework" for IT governance that is "aligned with other relevant standards and frameworks at a high level" [[#ISACA-2012|[ISACA, 2012]]]. | According to its authors, [https://www.isaca.org/resources/cobit/ COBIT] is an "overarching framework" for IT governance that is "aligned with other relevant standards and frameworks at a high level" [[#ISACA-2012|[ISACA, 2012]]]. | ||
COBIT describes seven categories of "enablers" for the governance and management of enterprise IT: | COBIT describes seven categories of "enablers" for the governance and management of enterprise IT: | ||
Line 65: | Line 65: | ||
COBIT is less helpful for designing the [[Service Management Processes|service management processes of an organization]]. Although COBIT defines a process model complete with suggested process activities, its authors concede that "the activities may not be at a sufficient level of detail for implementation, and further guidance may need to be obtained from specific relevant standards and good practice such as ITIL®, ..." [[#ISACA-2012|[ISACA, 2012]]]. | COBIT is less helpful for designing the [[Service Management Processes|service management processes of an organization]]. Although COBIT defines a process model complete with suggested process activities, its authors concede that "the activities may not be at a sufficient level of detail for implementation, and further guidance may need to be obtained from specific relevant standards and good practice such as ITIL®, ..." [[#ISACA-2012|[ISACA, 2012]]]. | ||
This is where YaSM comes into the picture. [[YaSM and ITIL]] [[#ITIL|[2]]] are well aligned but YaSM is somewhat easier to implement, so using YaSM and COBIT in combination is quite conceivable when setting up a set of service management processes, including a suitable governance framework. We expect, however, that a number of enhancements to the [[Service Management Processes|YaSM processes]] will be needed, depending on which particular sets of COBIT goals an organization intends to fulfill. The ITIL® publications and other service management guidance may also be consulted if additional advice is needed for specific topics. | This is where YaSM comes into the picture. | ||
[[YaSM and ITIL]] [[#ITIL|[2]]] are well aligned but YaSM is somewhat easier to implement, so using YaSM and COBIT in combination is quite conceivable when setting up a set of service management processes, including a suitable governance framework. We expect, however, that a number of enhancements to the [[Service Management Processes|YaSM service management processes]] will be needed, depending on which particular sets of COBIT goals an organization intends to fulfill. The ITIL® publications and other service management guidance may also be consulted if additional advice is needed for specific topics. | |||
'''''Note:''''' ''YaSM is an independent framework and is not endorsed by the authors of COBIT.'' <br /> | '''''Note:''''' ''YaSM is an independent framework and is not endorsed by the authors of COBIT.'' <br /> | ||
Line 71: | Line 73: | ||
==<span id="cobit-yasm-processes">COBIT® enabling processes and how they relate to YaSM processes</span>== | ==<span id="cobit-yasm-processes">COBIT® enabling processes and how they relate to YaSM processes</span>== | ||
<span id="md-webpage-description" itemprop="description">The following tables highlight which [[Service_Management_Processes|YaSM service management processes]] are related to specific COBIT® enabling processes, to illustrate that YaSM and COBIT share many basic principles:</span> | |||
*[[#domain-edm|Domain: Evaluate, Direct and Monitor (EDM)]] | *[[#domain-edm|Domain: Evaluate, Direct and Monitor (EDM)]] | ||
*[[#domain-apo|Domain: Align, Plan and Organize (APO)]] | *[[#domain-apo|Domain: Align, Plan and Organize (APO)]] | ||
Line 79: | Line 80: | ||
*[[#domain-mea|Domain: Monitor, Evaluate and Assess (MEA)]] | *[[#domain-mea|Domain: Monitor, Evaluate and Assess (MEA)]] | ||
==<span id="domain-edm">Domain: Evaluate, Direct and Monitor (EDM)</span>== | Please note that the aim is not to provide a detailed and scientifically correct cross-reference between the two service management frameworks. | ||
===<span id="domain-edm">Domain: Evaluate, Direct and Monitor (EDM)</span>=== | |||
{| class="wikitable" style="background: white;" | {| class="wikitable" style="background: white;" | ||
| | |+style="background:#465674;"|<span style="color:#ffffff; font-size: 110%">COBIT domain 'Evaluate, Direct and Monitor (EDM)' and related YaSM processes</span> | ||
|-style="vertical-align:top" | |||
!style="background:# | !style="background:#eeeeee;"|COBIT® enabling pro­cesses | ||
!style="background:# | !style="background:#eeeeee;"|Related YaSM processes | ||
!style="background:#eeeeee;"|Notes | |||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|EDM01 Ensure | |EDM01 Ensure Gover­nance Frame­work Setting and Mainte­nance | ||
|style="vertical-align:top" rowspan="5"| | |style="vertical-align:top" rowspan="5"| | ||
*[[LP1: Set the strategic direction]] | *[[LP1: Set the strategic direction]] | ||
Line 101: | Line 105: | ||
|- | |- | ||
| | | | ||
EDM03 Ensure Risk | EDM03 Ensure Risk Optimi­sation | ||
|- | |- | ||
| | | | ||
EDM04 Ensure Resource | EDM04 Ensure Resource Optimi­sation | ||
|- | |- | ||
| | | | ||
EDM05 Ensure Stake-holder | EDM05 Ensure Stake-holder Transpa­rency | ||
|} | |} | ||
<p> </p> | <p> </p> | ||
==<span id="domain-apo">Domain: Align, Plan and Organize (APO)</span>== | ===<span id="domain-apo">Domain: Align, Plan and Organize (APO)</span>=== | ||
{| class="wikitable" style="background: white;" | {| class="wikitable" style="background: white;" | ||
| | |+style="background:#465674;"|<span style="color:#ffffff; font-size: 110%">COBIT domain 'Align, Plan and Organize (APO)' and related YaSM processes</span> | ||
|-style="vertical-align:top" | |||
!style="background:# | !style="background:#eeeeee;"|COBIT® enabling pro­cesses | ||
!style="background:# | !style="background:#eeeeee;"|Related YaSM processes | ||
!style="background:#eeeeee;"|Notes | |||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|APO01 Manage the IT | |APO01 Manage the IT Manage­ment Frame­work | ||
| | | | ||
*[[SP1: Set up and maintain the service management system|SP1: Set up and maintain the service mgmt. system]] | *[[SP1: Set up and maintain the service management system|SP1: Set up and maintain the service mgmt. system]] | ||
Line 132: | Line 137: | ||
*-/- | *-/- | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|APO03 Manage | |APO03 Manage Enter­prise Archi­tecture | ||
| | | | ||
*[[LP1: Set the strategic direction]] | *[[LP1: Set the strategic direction]] | ||
*[[SP1: Set up and maintain the service management system|SP1: Set up and maintain the service mgmt. system]] | *[[SP1: Set up and maintain the service management system|SP1: Set up and maintain the service mgmt. system]] | ||
*[[SP4: Manage configuration information|SP4: Manage config. | *[[SP4: Manage configuration information|SP4: Manage config. infor­mation]] | ||
| | | | ||
*This COBIT process cannot be related directly to specific YaSM processes. | *This COBIT process cannot be related directly to specific YaSM processes. | ||
*A number of YaSM processes maintain information which is generally under-stood to be part of the enterprise architecture, for example: | *A number of YaSM processes maintain information which is generally under-stood to be part of the enterprise architecture, for example: | ||
**The process for setting up the SMS maintains a model of the organization's processes. | **The process for setting up the SMS maintains a model of the organization's processes. | ||
**The configuration management process maintains a configuration model, which typically includes information about applications and their | **The configuration management process maintains a configuration model, which typically includes information about applications and their inter­relationships. | ||
**The strategic process contains activities to produce a roadmap for the future development of the technical infrastructure. | **The strategic process contains activities to produce a roadmap for the future development of the technical infrastructure. | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|APO04 Manage | |APO04 Manage Inno­vation | ||
| | | | ||
*[[LP1: Set the strategic direction]] | *[[LP1: Set the strategic direction]] | ||
Line 157: | Line 162: | ||
*[[LP1: Set the strategic direction]] | *[[LP1: Set the strategic direction]] | ||
*[[SP2: Maintain the service portfolio]] | *[[SP2: Maintain the service portfolio]] | ||
*[[SP4: Manage configuration information|SP4: Manage config. | *[[SP4: Manage configuration information|SP4: Manage config. infor­mation]] | ||
*[[SP12: Manage service financials]] | *[[SP12: Manage service financials]] | ||
| | | | ||
Line 182: | Line 187: | ||
*Once services and processes are implemented, tracking of human resources usage and planning of staffing levels is done as part of service and process operation. | *Once services and processes are implemented, tracking of human resources usage and planning of staffing levels is done as part of service and process operation. | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|APO08 Manage | |APO08 Manage Relation­ships | ||
| | | | ||
*[[SP3: Manage customer relationships|SP3: Manage customer relation­ships]] | *[[SP3: Manage customer relationships|SP3: Manage customer relation­ships]] | ||
Line 188: | Line 193: | ||
*-/- | *-/- | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|APO09 Manage Service | |APO09 Manage Service Agree­ments | ||
| | | | ||
*[[LP2: Design new or changed services]] | *[[LP2: Design new or changed services]] | ||
Line 222: | Line 227: | ||
*[[LP1: Set the strategic direction]] | *[[LP1: Set the strategic direction]] | ||
*[[SP7: Ensure security]] | *[[SP7: Ensure security]] | ||
*[[SP8: | *[[SP8: Ensure continuity]] | ||
| | | | ||
*Risks affecting the service provider's business model as a whole are assessed during strategic reviews. This may lead to the definition and implementation of suitable responses to the identified strategic risks. | *Risks affecting the service provider's business model as a whole are assessed during strategic reviews. This may lead to the definition and implementation of suitable responses to the identified strategic risks. | ||
*A number of other YaSM processes are tasked with managing risks of particular types, for example security risks or risks associated with | *A number of other YaSM processes are tasked with managing risks of particular types, for example security risks or risks associated with critical, disruptive events. | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|APO13 Manage Security</span> | |APO13 Manage Security</span> | ||
Line 236: | Line 241: | ||
<p> </p> | <p> </p> | ||
==<span id="domain-bai">Domain: Build, Acquire and Implement (BAI)</span>== | ===<span id="domain-bai">Domain: Build, Acquire and Implement (BAI)</span>=== | ||
{| class="wikitable" style="background: white;" | {| class="wikitable" style="background: white;" | ||
| | |+style="background:#465674;"|<span style="color:#ffffff; font-size: 110%">COBIT domain 'Build, Acquire and Implement (BAI)' and related YaSM processes</span> | ||
|-style="vertical-align:top" | |||
!style="background:# | !style="background:#eeeeee;"|COBIT® enabling pro­cesses | ||
!style="background:# | !style="background:#eeeeee;"|Related YaSM processes | ||
!style="background:#eeeeee;"|Notes | |||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|BAI01 Manage | |BAI01 Manage Pro­grammes and Projects | ||
| | | | ||
*[[SP6: Manage projects]] | *[[SP6: Manage projects]] | ||
Line 250: | Line 256: | ||
*-/- | *-/- | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|BAI02 Manage | |BAI02 Manage Require­ments Definition | ||
| | | | ||
*[[LP2: Design new or changed services]] | *[[LP2: Design new or changed services]] | ||
Line 256: | Line 262: | ||
*-/- | *-/- | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|BAI03 Manage Solutions | |BAI03 Manage Solutions Identi­fication and Build | ||
| | | | ||
*[[LP2: Design new or changed services]] | *[[LP2: Design new or changed services]] | ||
Line 267: | Line 273: | ||
*The service portfolio process is responsible for updating the service portfolio. | *The service portfolio process is responsible for updating the service portfolio. | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|<span id="Manage-Availability-and-Capacity">BAI04 Manage | |<span id="Manage-Availability-and-Capacity">BAI04 Manage Availa­bility and Capacity</span> | ||
| | | | ||
*[[LP2: Design new or changed services]] | *[[LP2: Design new or changed services]] | ||
Line 276: | Line 282: | ||
*Both YaSM and COBIT stipulate that service availability and capacity must be managed, but YaSM does not contain specific capacity and availability management processes. Rather, service capacity and availability is treated as an aspect of services to be managed through the service lifecycle processes. | *Both YaSM and COBIT stipulate that service availability and capacity must be managed, but YaSM does not contain specific capacity and availability management processes. Rather, service capacity and availability is treated as an aspect of services to be managed through the service lifecycle processes. | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|BAI05 Manage | |BAI05 Manage Organi­sational Change Enable­ment | ||
| | | | ||
*[[LP1: Set the strategic direction]] | *[[LP1: Set the strategic direction]] | ||
Line 293: | Line 299: | ||
*-/- | *-/- | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|BAI07 Manage Change | |BAI07 Manage Change Accep­tance and Transi­tioning | ||
| | | | ||
*[[LP2: Design new or changed services]] | *[[LP2: Design new or changed services]] | ||
Line 314: | Line 320: | ||
*[[LP3: Build new or changed services]] | *[[LP3: Build new or changed services]] | ||
*[[LP4: Operate the services]] | *[[LP4: Operate the services]] | ||
*[[SP4: Manage configuration information|SP4: Manage config. | *[[SP4: Manage configuration information|SP4: Manage config. infor­mation]] | ||
*[[SP11: Manage suppliers]] | *[[SP11: Manage suppliers]] | ||
*[[SP12: Manage service financials]] | *[[SP12: Manage service financials]] | ||
Line 325: | Line 331: | ||
*Licenses are managed by the supplier management process, supported by the configuration management process. | *Licenses are managed by the supplier management process, supported by the configuration management process. | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|BAI10 Manage | |BAI10 Manage Configu­ration | ||
| | | | ||
*[[SP4: Manage configuration information|SP4: Manage config. | *[[SP4: Manage configuration information|SP4: Manage config. infor­mation]] | ||
| | | | ||
*-/- | *-/- | ||
Line 334: | Line 340: | ||
<p> </p> | <p> </p> | ||
==<span id="domain-dss">Domain: Deliver, Service and Support (DSS)</span>== | ===<span id="domain-dss">Domain: Deliver, Service and Support (DSS)</span>=== | ||
{| class="wikitable" style="background: white;" | {| class="wikitable" style="background: white;" | ||
| | |+style="background:#465674;"|<span style="color:#ffffff; font-size: 110%">COBIT domain 'Deliver, Service and Support (DSS)' and related YaSM processes</span> | ||
|-style="vertical-align:top" | |||
!style="background:# | !style="background:#eeeeee;"|COBIT® enabling pro­cesses | ||
!style="background:# | !style="background:#eeeeee;"|Related YaSM processes | ||
!style="background:#eeeeee;"|Notes | |||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|DSS01 Manage Operations | |DSS01 Manage Operations | ||
Line 364: | Line 371: | ||
|DSS04 Manage Continuity | |DSS04 Manage Continuity | ||
| | | | ||
*[[SP8: | *[[SP8: Ensure continuity]] | ||
| | | | ||
*-/- | *-/- | ||
Line 389: | Line 396: | ||
<p> </p> | <p> </p> | ||
==<span id="domain-mea">Domain: Monitor, Evaluate and Assess (MEA)</span>== | ===<span id="domain-mea">Domain: Monitor, Evaluate and Assess (MEA)</span>=== | ||
{| class="wikitable" style="background: white;" | {| class="wikitable" style="background: white;" | ||
| | |+style="background:#465674;"|<span style="color:#ffffff; font-size: 110%">COBIT domain 'Monitor, Evaluate and Assess (MEA)' and related YaSM processes</span> | ||
|-style="vertical-align:top" | |||
!style="background:# | !style="background:#eeeeee;"|COBIT® enabling pro­cesses | ||
!style="background:# | !style="background:#eeeeee;"|Related YaSM processes | ||
!style="background:#eeeeee;"|Notes | |||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|MEA01 Monitor, Evaluate and Assess | |MEA01 Monitor, Evaluate and Assess Per­formance and Con­formance | ||
| | | | ||
*[[SP1: Set up and maintain the service management system|SP1: Set up and maintain the service mgmt. system]] | *[[SP1: Set up and maintain the service management system|SP1: Set up and maintain the service mgmt. system]] | ||
Line 410: | Line 418: | ||
*The system of internal control is effectively defined by specifying a number of suitable processes and policies. This means the YaSM process for maintaining the SMS is predominantly in charge of monitoring and assessing the system of internal control. | *The system of internal control is effectively defined by specifying a number of suitable processes and policies. This means the YaSM process for maintaining the SMS is predominantly in charge of monitoring and assessing the system of internal control. | ||
|-style="vertical-align:top" | |-style="vertical-align:top" | ||
|MEA03 Monitor, Evaluate and Assess | |MEA03 Monitor, Evaluate and Assess Com­pliance with External Require­ments | ||
| | | | ||
*[[LP4: Operate the services]] | *[[LP4: Operate the services]] | ||
Line 428: | Line 436: | ||
==External links== | ==External links== | ||
*[COBIT browsing page]. -- ISACA International ("ISACA"): [https:// | *[COBIT browsing page]. -- ISACA International ("ISACA"): [https://www.isaca.org/resources/cobit/ https://www.isaca.org/resources/cobit/]. -- The COBIT resource center for governance and management of enterprise IT. - ISACA; Rolling Meadows, IL 60008, USA. | ||
== Notes == | == Notes == | ||
Line 467: | Line 475: | ||
<!-- define schema.org/WebPage --> <span itemid="https://yasm.com/wiki/en/index.php/YaSM_and_COBIT" itemscope itemtype="https://schema.org/WebPage" itemref="md-webpage-description"> | <!-- define schema.org/WebPage --> <span itemid="https://yasm.com/wiki/en/index.php/YaSM_and_COBIT" itemscope itemtype="https://schema.org/WebPage" itemref="md-webpage-description"> | ||
<meta itemprop="educationalUse" content="Which YaSM processes are related to specific COBIT® enabling processes." /> | <meta itemprop="educationalUse" content="Which YaSM service management processes are related to specific COBIT® enabling processes." /> | ||
<meta itemprop="name Headline" content="YaSM and COBIT" /> | <meta itemprop="name Headline" content="YaSM and COBIT" /> | ||
<meta itemprop="alternativeHeadline" content="YaSM and COBIT® (Control Objectives for Information and Related Technologies)" /> | <meta itemprop="alternativeHeadline" content="YaSM and COBIT® (Control Objectives for Information and Related Technologies)" /> |
Latest revision as of 10:57, 10 August 2024
Comparison: YaSM and COBIT® (Control Objectives for Information and Related Technologies)
Part of: YaSM vs. other service management frameworks and standards
YaSM® was developed with COBIT® (Control Objectives for Information and Related Technologies) [1] in mind, but YaSM is not a "COBIT process model".
About COBIT®
According to its authors, COBIT is an "overarching framework" for IT governance that is "aligned with other relevant standards and frameworks at a high level" [ISACA, 2012].
COBIT describes seven categories of "enablers" for the governance and management of enterprise IT:
- Principles, policies and frameworks
- Processes
- Organizational structures
- Culture, ethics and behavior
- Information
- Services, infrastructure and applications
- People, skills and competencies.
COBIT's "enabling processes" are defined in the COBIT Process Reference Model. For each process in the reference model, COBIT specifies a number of dimensions such as a set of goals, metrics, inputs, outputs, management practices and activities. The COBIT product set also includes a process capability model which can be used to assess the maturity of an organization's IT-related processes, as well as an implementation guide.
Because of its complete set of goals and metrics for IT processes, many organizations use COBIT to improve governance of their information technology operations.
Using YaSM and COBIT® in combination
COBIT is less helpful for designing the service management processes of an organization. Although COBIT defines a process model complete with suggested process activities, its authors concede that "the activities may not be at a sufficient level of detail for implementation, and further guidance may need to be obtained from specific relevant standards and good practice such as ITIL®, ..." [ISACA, 2012].
This is where YaSM comes into the picture.
YaSM and ITIL [2] are well aligned but YaSM is somewhat easier to implement, so using YaSM and COBIT in combination is quite conceivable when setting up a set of service management processes, including a suitable governance framework. We expect, however, that a number of enhancements to the YaSM service management processes will be needed, depending on which particular sets of COBIT goals an organization intends to fulfill. The ITIL® publications and other service management guidance may also be consulted if additional advice is needed for specific topics.
Note: YaSM is an independent framework and is not endorsed by the authors of COBIT.
COBIT® enabling processes and how they relate to YaSM processes
The following tables highlight which YaSM service management processes are related to specific COBIT® enabling processes, to illustrate that YaSM and COBIT share many basic principles:
- Domain: Evaluate, Direct and Monitor (EDM)
- Domain: Align, Plan and Organize (APO)
- Domain: Build, Acquire and Implement (BAI)
- Domain: Deliver, Service and Support (DSS)
- Domain: Monitor, Evaluate and Assess (MEA)
Please note that the aim is not to provide a detailed and scientifically correct cross-reference between the two service management frameworks.
Domain: Evaluate, Direct and Monitor (EDM)
COBIT® enabling processes | Related YaSM processes | Notes |
---|---|---|
EDM01 Ensure Governance Framework Setting and Maintenance |
| |
EDM02 Ensure Benefits Delivery | ||
EDM03 Ensure Risk Optimisation | ||
EDM04 Ensure Resource Optimisation | ||
EDM05 Ensure Stake-holder Transparency |
Domain: Align, Plan and Organize (APO)
COBIT® enabling processes | Related YaSM processes | Notes |
---|---|---|
APO01 Manage the IT Management Framework |
| |
APO02 Manage Strategy |
| |
APO03 Manage Enterprise Architecture |
| |
APO04 Manage Innovation |
| |
APO05 Manage Portfolio |
| |
APO06 Manage Budget and Costs |
| |
APO07 Manage Human Resources |
| |
APO08 Manage Relationships |
| |
APO09 Manage Service Agreements |
| |
APO10 Manage Suppliers |
| |
APO11 Manage Quality |
| |
APO12 Manage Risk |
| |
APO13 Manage Security |
|
Domain: Build, Acquire and Implement (BAI)
COBIT® enabling processes | Related YaSM processes | Notes |
---|---|---|
BAI01 Manage Programmes and Projects |
| |
BAI02 Manage Requirements Definition |
| |
BAI03 Manage Solutions Identification and Build |
| |
BAI04 Manage Availability and Capacity |
| |
BAI05 Manage Organisational Change Enablement |
| |
BAI06 Manage Changes |
| |
BAI07 Manage Change Acceptance and Transitioning |
| |
BAI08 Manage Knowledge |
|
|
BAI09 Manage Assets |
| |
BAI10 Manage Configuration |
|
Domain: Deliver, Service and Support (DSS)
COBIT® enabling processes | Related YaSM processes | Notes |
---|---|---|
DSS01 Manage Operations |
| |
DSS02 Manage Service Requests and Incidents |
| |
DSS03 Manage Problems |
| |
DSS04 Manage Continuity |
| |
DSS05 Manage Security Services |
| |
DSS06 Manage Business Process Controls |
|
Domain: Monitor, Evaluate and Assess (MEA)
COBIT® enabling processes | Related YaSM processes | Notes |
---|---|---|
MEA01 Monitor, Evaluate and Assess Performance and Conformance |
| |
MEA02 Monitor, Evaluate and Assess the System of Internal Control |
| |
MEA03 Monitor, Evaluate and Assess Compliance with External Requirements |
|
References
- [ISACA, 2012]. - Information Systems Audit and Control Association (ISACA): COBIT 5: Enabling Processes. - Rolling Meadows, IL, USA, 2012.
External links
- [COBIT browsing page]. -- ISACA International ("ISACA"): https://www.isaca.org/resources/cobit/. -- The COBIT resource center for governance and management of enterprise IT. - ISACA; Rolling Meadows, IL 60008, USA.
Notes
[1] COBIT® is a registered trademark of ISACA (Information Systems Audit and Control Association).
[2] ITIL® is a registered trade mark of AXELOS Limited.
Is based on: The YaSM Process Map. - Document: "YaSM and COBIT®".
By: Stefan Kempter and Andrea Kempter , IT Process Maps.
COBIT® and related YaSM processes › Domain APO › Domain BAI › Domain DSS › Domain MEA