Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

DS1.3 - Service Level Agreements

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective DS1.3 - Service Level Agreements is contained within Process Popup Define and Manage Service Levels.

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
2 Members
0 Online
808 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Points: 3


Service Level Agreements

Define and agree to SLAs for all critical IT services based on customer requirements and IT capabilities. This should cover customer commitments; service support requirements; quantitative and qualitative metrics for measuring the service signed off on by the stakeholders; funding and commercial arrangements, if applicable; and roles and responsibilities, including oversight of the SLA. Consider items such as availability, reliability, performance, capacity for growth, levels of support, continuity planning, security and demand constraints.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Service responsibilities and IT objectives aligned with business objectives
  • Service quality enhanced due to proper understanding and alignment of service delivery
  • Service efficiency increased and costs reduced due to efficient deployment of IT services based on real needs and priorities
  Risk Drivers
  • Failure to meet customer service requirements
  • Inefficient and ineffective use of service delivery resources
  • Failure to identify and respond to critical service incidents

View Control Practices  help

Hide Control Practices  help

  1. Ensure that the stakeholders from IT and the business negotiate, agree to and approve service requirements, and document and communicate their SLA as appropriate. The format and contents include exclusions, commercial arrangements and OLAs.
  2. Confirm that the SLA management process promotes, promulgates, measures (qualitative and quantitative) and monitors the SLA objectives.
  3. Perform periodic reviews of the SLA objectives, effectiveness and efficiency, and report to the SLA stakeholders.
  4. Improve or adjust SLAs based on performance feedback and changes to customer and business requirements.

 

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 123 total

Must be a Topic member to contribute
View All »
Downloads
Posted by ISACA 343 days ago
Downloads
Posted by ISACA 397 days ago
Books
Posted by ISACA 11 days ago
Books
Posted by ISACA 19 days ago
ICQs and Audit Programs
Posted by ISACA 26 days ago
ICQs and Audit Programs
Posted by ISACA 26 days ago

Events & Online Learning: 7 total

7 May 2012
ISACA International Event
Orlando, Florida, USA
Get the knowledge you need to stay one step ahead of the competition and keep up with changing professional trends at ISACA’s North America CACS Conference.
12 Jun 2012
ISACA International Event
Dallas, Texas, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
7 Aug 2012
ISACA International Event
Chicago, Illinois, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
11 Sep 2012
ISACA International Event
San Francisco, California, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
2 Oct 2012
ISACA International Event
Orlando, Florida, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
6 Nov 2012
ISACA International Event
New York, New York, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.

Journal Articles: 222 total

Volume 2, 2019
by ISACA Member and Certification Holder Compliance
Volume 3, 2012
by Ookeditse Kamau, CISA, CIA
Quality evidence collected during the audit process enhances the overall quality of the work performed and significantly reduces audit risk.
Volume 3, 2012
by Kai-Uwe Ruhse, CISA, PCI QSA, and Maria Baturova
This article describes real cloud computing project case studies, which show that moving to the cloud is an important strategic decision for IT managers.
Volume 3, 2012
by Tommie W. Singleton, Ph.D., CISA, CGEIT, CITP, CPA
This two-part article describes one framework for performing effective audits of applications.
Volume 3, 2012
by Brian Vazzana, CISA, CITP, CPA
SOC reports examine the controls present at the service organizations and consider how those controls are designed and operate.
Volume 3, 2012
by ISACA Member and Certification Holder Compliance
An up-to-date listing of the current IT Audit and Assurance Standards, Guidelines, and Tools and Techniques

Wikis: 2 total

Blog Posts: 49 total

Gone are the days of check list auditing (Tick and bash audit). To add value to business auditors need to go beyond check listing. Be it an application control review (ACR), IT General Controls Review (ITGCR), A project review or an integrated audit, i...
Posted By : Tichaona Zororo CISA, CISM, CRISC, CGEIT | 0 comments
During my audits, training & teaching sessions one of the frequent queries I came across is 'Sir, How do I become an IT Auditor? What are the qualification criteria?' The best answer for this to quote from the famous book, Information Systems Control and ...
Posted By : KvR | 0 comments
So two things happened today. While talking about the need to get the business folks excited about IT Risk Management I used a simple analogy trying to relate to the usual perception, perhaps justifiably so, the business folks have, and that is, IT securi...
Posted By : Umesh391 | 0 comments
7 Mar 2012
To share various espects in cloud computing viz; history, availability, deployment, integrity, availability, confidentiality, security, cloud sharing etc.
Posted By : MoizB583519 | 2 comments
On March 1st,  I was invited to speak at the CampIT conference on Enterprise Risk/Security Management at Rosemont Convention Center. Before me there were two speakers. The first presenter spent an hour presenting the story from the trenches of technolog...
Posted By : Umesh391 | 0 comments
Hola, se les informa a todos los interesados para los cursos de CISM en JUNIO 2.011, que los mismos comenzarán los siguientes días: 06FEB - 40 Hrs Grupo A 13FEB - 40 Hrs Grupo B 20FEB - 40 Hrs Grupo C Modalidad 16 Hrs intensivas y Presenciales (09:00 a...
Posted By : Alexander Osorio | 0 comments