Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

DS7.1 - Identification of Education and Training Needs

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective DS7.1 - Identification of Education and Training Needs is contained within Process Popup Educate and Train Users.

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
3 Members
0 Online
840 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Points: 3


Identification of Education and Training Needs

Establish and regularly update a curriculum for each target group of employees considering:
  • Current and future business needs and strategy
  • Value of information as an asset
  • Corporate values (ethical values, control and security culture, etc.)
  • Implementation of new IT infrastructure and software (i.e., packages, applications)
  • Current and future skills, competence profiles, and certification and/or credentialing needs as well as required reaccreditation
  • Delivery methods (e.g., classroom, web-based), target group size, accessibility and timing

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Training needs for personnel identified to fulfil business requirements
  • A baseline for the effective use of the organisation’s technology by personnel, both immediately and in the future
  • Establishment of training and education programmes that are relevant to the risks and opportunities the organisation faces currently and in the future
  • Installed application capabilities optimised to satisfy business needs
  Risk Drivers
  • Staff members inadequately trained to fulfil their job function
  • Ineffective training mechanisms
  • Training provided not appropriate for training need
  • Installed application capabilities underutilised

View Control Practices  help

Hide Control Practices  help

  1. Implement a process to identify predetermined requirements (such as for certifications) and/or create competency requirements for user roles, and use this to plan training curriculum for all target groups of users. The process ensures that training and education support compliance with business policies while providing and supporting the employee’s career path.
  2. Maintain a skills database that contains a gap analysis between the skills required by users and internal providers of technology and the skills and knowledge available.
    This database should also include competency profiles and records of any skills certifications obtained by users.
  3. Incorporate technology training needs into the users’ individual performance plans.
  4. Implement a process to compile and analyse information from the service desk and identify training requirements.

 

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 50 total

Must be a Topic member to contribute
View All »
Books
Posted by ISACA 13 days ago
ICQs and Audit Programs
Posted by ISACA 26 days ago
Books
Few businesses could function effectively without their IT systems. At the same time, they depend on IT for more than their day-to-day operations.
Posted by ISACA 57 days ago
Books
International Financial Reporting Standards have been mandatory in the EU since 2005 and are rapidly being adopted by countries throughout the world.
Posted by ISACA 57 days ago
Books
Posted by ISACA 75 days ago

Events & Online Learning: 6 total

12 Jun 2012
ISACA International Event
Dallas, Texas, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
7 Aug 2012
ISACA International Event
Chicago, Illinois, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
11 Sep 2012
ISACA International Event
San Francisco, California, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
2 Oct 2012
ISACA International Event
Orlando, Florida, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
6 Nov 2012
ISACA International Event
New York, New York, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
11 Dec 2012
ISACA International Event
Las Vegas, Nevada, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.

Journal Articles: 73 total

Volume 3, 2012
by Aarni Heiskanen, LJK
A program or project portfolio explains how an organization is implementing its strategy with projects.
Volume 2, 2012
by John P. Pironti, CISA, CISM, CGEIT, CRISC, CISSP, ISSAP, ISSMP
Risk and security will no longer be something that the organization consciously considers and instead will become integrated in business-as-usual activities.
Volume 4, 2011
by Charu Pelnekar, CISA, CISM, ACA, AICWA, BCOM, CISSP, CPA, MCSE, QSA
The goal of this article is to provide guidance on the planning and decision-making processes associated with ISO 27001 implementation.
Volume 4, 2011
by Karen Quagliata, Ph.D., PMP
Security awareness training is a vital nontechnical component to information security.
Volume 4, 2011
by Gan Subramaniam, CISA, CISM, CCNA, CCSA, CIA, CISSP, ISO 27001 LA, SSCP
Let us try to develop a checklist to audit the IT systems integration project.
Volume 4, 2010
by Thomas J. Bell III, Ph.D., CISA
This article will explore how a SAS 70 audit is improved by understanding and applying PM tools and techniques. The basic tenets of PM principles will be examined and synthesized with the SAS 70 auditing process.

Wikis: 2 total

Blog Posts: 7 total

7 Mar 2012
To share various espects in cloud computing viz; history, availability, deployment, integrity, availability, confidentiality, security, cloud sharing etc.
Posted By : MoizB583519 | 2 comments
16 Feb 2012
I wonder if you ever encountered the term the ‘BIG Question? Possibly not, and so please allow me to introduce its concepts, but first of all, a little background and build-up if I may.   We as Security Professionals research, read, and seek to continuous...
Posted By : John379 | 0 comments
17 Aug 2011
Posted By : masarker | 0 comments
These are five possible ways to discover Unstructured Processes. Regulatory and Compliance processes - People-intensive processes that are kicked off as a result of an external regulatory body and these processes tend to be ad-hoc & on-going change, but...
Posted By : Varun | 1 comments
Yesterday Apple released a pretty big update for the MacBook Pro.  As is typically the case with Apple, you have to dig a little bit for the security related stuff.  Here is the list of security vulnerabilities the update addresses. It is pretty substanti...
Posted By : Jonathan Wilson | 0 comments
Se potencia la relación mutua y se acuerda la promoción del Sector TIC de la Comunidad Valenciana. La semana  pasada se llevó a cabo la firma de un convenio de colaboración entre los capítulos valencianos de las asociaciones más importantes a nivel mundia...
Posted By : JavierPeris.Org | 0 comments