BS-7799/ISO-17799  
  Sarbanes-Oxley  
 
 
 
Welcome to Safecoms !!!
 
ITIL / COBIT / COSO (Compliance Frameworks)

If your company is looking to establish a compliance framework, SafeComs should be the first call you make. Here are some of the frameworks you may be contemplating:

COSO a compliance framework that focuses on controls for financial processes
COBIT a management framework that focuses on IT
ITIL a best practices framework that focuses on IT service management, and is often used to complement the COBIT framework.

COSO The Committee of Sponsoring Organizations of the Treadway Commission
Internal Control according to COSO is a process, affected by an entitys board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories:

Effectiveness and efficiency of operations
Reliability of financial reporting
Compliance with applicable laws and regulations

Key Concepts

Internal control is a process. It is a means to an end, not an end in itself.
Internal control is effected by people. Its not merely policy manuals and forms, but people at every level of an organization.
Internal control can be expected to provide only reasonable assurance, not absolute assurance, to an entitys management and board.
Internal control is geared to the achievement of objectives in one or more separate but overlapping categories.

Senior executives have long sought ways to better control the enterprises they run. Internal controls are put in place to keep the company on course toward profitability goals and achievement of its mission, and to minimize surprises along the way. They enable management to deal with rapidly changing economic and competitive environments, shifting customer demands and priorities, and restructuring for future growth. Internal controls promote efficiency, reduce risk of asset loss, and help ensure the reliability of financial statements and compliance with laws and regulations.


COBIT - Control Objectives for Information and Related Technologies
COBIT has been developed as a generally applicable and accepted standard for good Information Technology (IT) security and control practices that provides a reference framework for management, users, and IS audit, control and security practitioners.

Its guidance enables an enterprise to implement effective governance over the IT that is pervasive and intrinsic throughout the enterprise. In particular, COBIT's Management Guidelines component contains a framework responding to management's need for control and measurability of IT by providing tools to assess and measure the enterprises IT capability for the 34 COBIT IT processes. The tools include:

Performance measurement elements (outcome measures and performance drivers for all IT processes)
A list of critical success factors that provides succinct, nontechnical best practices for each IT process
Maturity models to assist in benchmarking and decision-making for capability improvements


ITIL - Information Technology Infrastructure Library
ITIL has become very popular because it is a public domain framework which is scaleable. Very large organizations, very small organizations and everything in between have implemented ITIL processes. ITIL focuses on best practice, and as such can be adapted and adopted in different ways according to each individual organizations needs. So what is it?

ITIL (Information Technology Infrastructure Library) provides a comprehensive and consistent set of best practices for IT Service Management, promoting a quality approach to achieving business effectiveness and efficiency in the use of information systems. The United Kingdom's Central Computer and Telecommunications Agency (CCTA) created ITIL to provide guidance to UK Government departments in response to the growing dependence on Information Technology to meet business needs and goals. ITIL provides businesses with a customizable framework of best practices to achieve quality service and overcome difficulties associated with the growth of IT systems.

IT service organizations, employees from computing centers, suppliers, specialist consultants and trainers took part in the development of ITIL. ITIL is the most widely accepted approach to IT Service Management in the world. With this worldwide acceptance, a number of software manufacturers own methodologies are aligned with it. ITIL is fast becoming a de facto standard used by some of the worlds leading businesses.

 
 
 
 
Copyright©2005. Safecoms Ltd.
All rights reserved.