47
How to get Agile IT with Smart IT Governance José Ángel PEÑA IBARRA, CGEIT, CRISC COBIT 5 Acreddited Trainer [email protected] ISACA Curacao Conference 2017

How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

  • Upload
    others

  • View
    22

  • Download
    0

Embed Size (px)

Citation preview

Page 1: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

How to get Agile ITwith Smart IT Governance

José Ángel PEÑA IBARRA, CGEIT, CRISC

COBIT 5 Acreddited Trainer

[email protected]

ISACA Curacao Conference 2017

Page 2: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

Former International Vice-President of ISACAand the IT Governance Institute,(2007-2011).

Vice-President of ISACA Monterrey Chapter(2015-2017).

Partner of CCISA México since 2002. Former

partner of PricewaterhouseCoopers in México.

35+ years of experience in IT, including 11 years

in managerial positions in IT, and about 25

years in consulting, auditing and training , with

assignments in 20+ countries.September 2017

I AM MEXICAN

I AM ISACAN

I AM IN CURACAO

José Ángel Peña Ibarra, CGEIT, CRISC,COBIT 5 Accredited Trainer.

Page 3: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

INTRODUCTION

LEVERAGE ON EXISTING TOOLS

HOLISTIC APPROACH AND PRM

01

02

03CONTINUAL IMPROVEMENT 04

Content

ENCORE: COBIT 5 FOR RISKOpt.

Page 4: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

INTRODUCTION

LEVERAGE ON EXISTING TOOLS

HOLISTIC APPROACH AND PRM

01

02

03CONTINUAL IMPROVEMENT 04

Content

Page 5: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterIntroduction

What isAgile IT?

Page 6: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

Agile IT means IT can support the

enterprise innovation capabilities andsatisfy the business´s changing needs.

Introduction

Page 7: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

What is

Smart IT Governance?

Introduction

Page 8: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

Smart IT governance meansleveraging on existing tools, asthe family of COBIT products,ISACA resources and otherframeworks and methodologies.

Introduction

Page 9: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

Key Message:

Do not try to reinvent the wheel !

Introduction

Page 10: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

EXPLORE

KNOWLEDGE VALUE

EXPLOIT

Introduction

Page 11: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

INTRODUCTION

LEVERAGE ON EXISTING TOOLS

HOLISTIC APPROACH AND PRM

01

02

03CONTINUAL IMPROVEMENT 04

Content

Page 12: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterLeverage on existing tools

ISACA Products and Resources

Page 13: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

Complement with other frameworks,

methodologies and standards

COBIT

ISO 9000

ISO 27002

ITILWHAT?

HOW?

SCOPE

SCRUM

Page 14: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterISACA Products

• COBIT 5 is an overarching framework

www.isaca.org

Page 15: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterCOBIT 5 Practical Guidance

• COBIT 5 for Business benefits realisation

• Vendor Management using COBIT 5

• IT Control Objectives for SOX using COBIT 5

• Controls and Assurance in the Cloud, using COBIT 5.

Page 16: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterCOBIT 5 Practical Guidance

• Risk Scenarios using COBIT 5 for Risk

• Securing mobile devices using COBIT 5 for Information

• Transforming Cybersecurity using COBIT 5

• Configuration Management using COBIT 5

Page 17: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterAudit Programs using COBIT 5

• Audit Programs using COBIT 5

– Evaluate, Direct and Monitor

– Align, Plan and Organize

– Build, Acquaire and Implement

– Deliver, Service and Support

Page 18: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterAudit Programs using COBIT 5

• ITAF: Professional Practices Framework for Audit/Assurance

Page 19: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

� The COBIT Assessment Program includes:

– COBIT Process Assessment Model (PAM) Using COBIT 5

– COBIT Assessor’s Guide – using COBIT 5

– COBIT Self Assessment Guide – Using COBIT 5

The Process Capability Model based on ISO

15504 replaces the Process Capability Maturity

Model used in earlier COBIT versions.

COBIT 5 Assessment Program

© 2012 ISACA® All rights reserved.

Page 20: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

• COBIT 5/CMMI Practices Pathway Tool

Page 21: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

INTRODUCTION

LEVERAGE ON EXISTING TOOLS

HOLISTIC APPROACH AND PRM

01

02

03CONTINUAL IMPROVEMENT 04

Content

Page 22: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterCOBIT 5 Principles

© 2012 ISACA. All rights reserved. 22

Page 23: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

COBIT 5 Generic Enterprise Enablers

1. Principles, Policies and Frameworks

3. Organisational

Structures

4. Culture, Ethics

and Behaviour2. Processes

5. Information

Resources

6. Services,

Infrastructure and

Applications

7. People, Skills

and Competencies

23COBIT 5© 2012 ISACA All rights reserved

Page 24: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

24

5 domains,

37 processes

© 2012 ISACA. All Rights Reserved.

Page 25: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

Management Practices

Activities

Inputs Outputs

From Description DescriptionFrom

RACI Chart:

The process supports the achievement of a set of primary IT-related goals:

IT-related Goal Related Metrics

Process Goals and Metrics

Process Goal Related Metrics

Process Name Area:Domain:

Process Purpose Statement

Process Description

Related Guidance

Related Standard Detailed Reference

COBIT 5© 2012 ISACA All rights

reserved25

Page 26: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterScenario

• A big retailer company, focused in sport shoes, recentlyhired a Marketing and Sales VP because they want toimprove their revenues and also protect its market againstnew competitors. The company has about 600 stores inseveral countries in Latin America.

• The new Marketing and Sales VP has some very innovativeideas and is working with the Operations Director to almostcompletely renovate the concept of their stores. He alsowants to initiate the sales using e-commerce, because untilnow the sales were only through their chain of stores.

Page 27: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterScenario (Cont.)

• These two business initiatives, renovated stores and e-commerce, bring important challenges to the IT department,amongst them:

– To improve the customer buying satisfaction in the store, they need tosolve some issues in the inventory management process. Until now ifsome client is asking for some product that is not in the store, it takesone or two days to know if they have this product in other store orthey need to order it. Now they want to tell the client immediatelywhen they will have the product in the store.

– They want also improve the invoicing process. At the moment, when aclient asks for an electronic invoice, they give him/her an internet linkto download the e-invoice. This is not simple and for many customersis so complicated that they prefer not to get the invoice. Now theywant to send the invoice via email at the very moment he/she ispaying the product.

Page 28: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

• Therefore, IT department needs to develop and implement a newinventory management system and a new billing system.

• The e-commerce initiative requires not only to find out a good e-commerce solution, but also to manage all the security risks inherent tothe new platform.

• Additionally they have discovered that the Disaster Recovery Plan isobsolete and not adequate for the new business continuity needs.

• To assure the success of the new initiatives, the CIO decided to use COBIT5 to improve some of the IT processes, and also decided to use RiskScenarios based in COBIT 5 to identify the main risks.

END of SCENARIO

Scenario (Cont.)

Page 29: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

29COBIT 5© 2012 ISACA All rights reserved

Delegate Activity, (Teamwork )

Using the provided scenario:

1. Define which processes the IT director needs to select from the COBIT 5 Process Reference Model

2. Explain why you selected those processes

3. Explain also the procedure you think must be followed to select the processes

Page 30: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

INTRODUCTION

LEVERAGE ON EXISTING TOOLS

HOLISTIC APPROACH AND PRM

01

02

03CONTINUAL IMPROVEMENT 04

Content

Page 31: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

31COBIT 5© 2012 ISACA All rights

reserved

Page 32: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterPhases 1 and 2

Business Goals

Generic Pain Points

Specific Pain Points

IT Goals

Procesos Seleccionados

TOP DOWN

BOTTOM UP

Next PhaseIT Risks

Phase 1

Phase2

Phase2

Phase 1

Phase2 output

Page 33: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

GRACIAS !

Page 34: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

INTRODUCTION

LEVERAGE ON EXISTING TOOLS

HOLISTIC APPROACH AND PRM

01

02

03CONTINUAL IMPROVEMENT 04

Content

05 COBIT 5 FOR RISK

Page 35: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

35

COBIT 5

JA

Page 36: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

36

COBIT 5

JA

RISK SCENARIOS

Toolkit

Page 37: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterRisk

ISO Guide 73:

• Risk is the combination of the probability of a

given event and its consequences (impact).

Page 38: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

Note about quantitative Risk Analysis

Impact x prob.=RL

1x1=1

1x2=2

1x3=3

2x1=2

2x2=4

2x3=6

3x1=3

3x2=6

3x3=9

Ris

k L

eve

ls 5

,7 y

8 a

re m

isse

d

6 8 9

3 5 7

1 2 4

Probability

Impact

1 2

1

2

3

3

[email protected]

Page 39: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

6 8 9

3 5 7

1 2 4

Probability

Impact

1 2

1

2

3

3

Imp. Prob.= RL

1 X 2 = 2

2 X 1 = 3

Note about quantitative Risk Analysis

[email protected]

Page 40: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

Page 41: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao Chapter

Page 42: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterRisk Scenarios

01 Portfolio establishment and

maintenance

02 Programme/projects life cycle

management

03 IT investment decision making

04 IT expertise and skills

05 Staff operations

06 Information

07 Architecture

08 Infrastructure

09 Software

10 Business ownership of IT

11 Suppliers

12 Regulatory compliance

13 Geopolitical

14 Infrastructure theft or

destruction

15 Malware

16 Logical attacks

17 Industrial action

18 Environmental

19 Acts of nature

20 Innovation

Page 43: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

43

Escenarios de riesgo genéricos

Page 44: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

44

Escenarios de riesgo genéricos

Page 45: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

45

Escenarios de riesgo genéricos

Page 46: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterJoin us!

Page 47: How to get Agile IT with Smart IT Governanceisacacuracao.com/wp-content/uploads/2017/09/AGILE-IT-W-SMART-GOV-V2.3.… · How to get Agile IT with Smart IT Governance José ÁngelPEÑAIBARRA,

[email protected]

Curaçao ChapterGRACIAS !

José Ángel PEÑA IBARRA, CGEIT, CRISC

COBIT 5 Acreddited Trainer

[email protected]