If your company is looking
to establish a compliance framework,
SafeComs should be the first call
you make. Here are some of the
frameworks you may be contemplating:
|
COSO a compliance
framework that focuses on
controls for financial processes |
|
COBIT a management framework
that focuses on IT |
|
ITIL a best practices
framework that focuses on
IT service management, and
is often used to complement
the COBIT framework. |
COSO The Committee
of Sponsoring Organizations
of the Treadway Commission
Internal Control according
to COSO is a process, affected
by an entitys board of directors,
management and other personnel,
designed to provide reasonable
assurance regarding the achievement
of objectives in the following
categories:
|
Effectiveness
and efficiency of operations |
|
Reliability of financial
reporting |
|
Compliance with applicable
laws and regulations |
Key Concepts
|
Internal control
is a process. It is a means
to an end, not an end in
itself. |
|
Internal control is effected
by people. Its not merely
policy manuals and forms,
but people at every level
of an organization. |
|
Internal control can be
expected to provide only
reasonable assurance, not
absolute assurance, to an
entitys management and
board. |
|
Internal control is geared
to the achievement of objectives
in one or more separate
but overlapping categories. |
Senior executives have long
sought ways to better control
the enterprises they run. Internal
controls are put in place to
keep the company on course toward
profitability goals and achievement
of its mission, and to minimize
surprises along the way. They
enable management to deal with
rapidly changing economic and
competitive environments, shifting
customer demands and priorities,
and restructuring for future
growth. Internal controls promote
efficiency, reduce risk of asset
loss, and help ensure the reliability
of financial statements and
compliance with laws and regulations.
COBIT - Control Objectives
for Information and Related
Technologies
COBIT has been developed
as a generally applicable and
accepted standard for good Information
Technology (IT) security and
control practices that provides
a reference framework for management,
users, and IS audit, control
and security practitioners.
Its guidance enables an enterprise
to implement effective governance
over the IT that is pervasive
and intrinsic throughout the
enterprise. In particular, COBIT's
Management Guidelines component
contains a framework responding
to management's need for control
and measurability of IT by providing
tools to assess and measure
the enterprises IT capability
for the 34 COBIT IT processes.
The tools include:
|
Performance
measurement elements (outcome
measures and performance
drivers for all IT processes) |
|
A list of critical success
factors that provides succinct,
nontechnical best practices
for each IT process |
|
Maturity models to assist
in benchmarking and decision-making
for capability improvements |
ITIL - Information Technology
Infrastructure Library
ITIL has become very
popular because it is a public
domain framework which is scaleable.
Very large organizations, very
small organizations and everything
in between have implemented
ITIL processes. ITIL focuses
on best practice, and as such
can be adapted and adopted in
different ways according to
each individual organizations
needs. So what is it?
ITIL (Information Technology
Infrastructure Library) provides
a comprehensive and consistent
set of best practices for IT
Service Management, promoting
a quality approach to achieving
business effectiveness and efficiency
in the use of information systems.
The United Kingdom's Central
Computer and Telecommunications
Agency (CCTA) created ITIL to
provide guidance to UK Government
departments in response to the
growing dependence on Information
Technology to meet business
needs and goals. ITIL provides
businesses with a customizable
framework of best practices
to achieve quality service and
overcome difficulties associated
with the growth of IT systems.
IT service organizations, employees
from computing centers, suppliers,
specialist consultants and trainers
took part in the development
of ITIL. ITIL is the most widely
accepted approach to IT Service
Management in the world. With
this worldwide acceptance, a
number of software manufacturers
own methodologies are aligned
with it. ITIL is fast becoming
a de facto standard used by
some of the worlds leading
businesses.
|