Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

ME1.1 - Monitoring Approach

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective ME1.1 - Monitoring Approach is contained within Process Popup Monitor and Evaluate IT Performance.

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
5 Members
0 Online
2689 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!


Monitoring Approach

Establish a general monitoring framework and approach to define the scope, methodology and process to be followed for measuring IT’s solution and service delivery, and monitor IT’s contribution to the business. Integrate the framework with the corporate performance management system.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • A transparent view of IT’s performance, based on reliable information
  • Opportunities for improvement identified
  • Facilitated achievement of business and governance requirements
  • Cost-efficient IT services
  • More informed IT investment decisions, improving value delivery
  • Consistent use and integrity of performance indicators
  Risk Drivers
  • Performance reports based on out-of-date, inaccurate or unreliable data
  • Performance metrics not aligned with business and governance requirements
  • Lack of timely identification of issues related to IT and business alignment
  • Customer expectations and business needs not adequately identified
  • Monitored data failing to support the analysis of the overall process performance

View Control Practices  help

Hide Control Practices  help

  1. Identify the relevant IT processes that support mission-critical business processes, strategic initiatives and the portfolio of IT-enabled investments. Categorise these IT processes in terms of impact to the business.
  2. Define a monitoring approach that uses metrics based on IT’s performance and that, when monitored, will indicate IT-driven business outcomes for the enterprise.
  3. Establish and maintain an IT monitoring system that is tied to business strategies and facilitates effective monitoring of IT’s support of business objectives. Integrate the IT monitoring approach within the enterprise’s performance management approach.
  4. Identify relationships and dependencies amongst the IT processes (e.g., expectation gaps, undefined interfaces, omissions, duplication of effort, inefficiencies) when monitoring IT performance.
  5. Ensure that performance metrics cover:
    • Business contribution including, but not limited to, financials
    • Performance against the strategic business and IT plan
    • Risk and compliance with regulations
    • Internal and external user satisfaction with service levels
    • Key IT processes, including solution and service delivery
    • Future-oriented activities, e.g., emerging technology, reusable infrastructure, business and IT personnel skill sets Set performance metrics so they:
    • Represent IT’s goals and objectives
    • Are based on accepted good practices
    • Focus on the most important practices
    • Are useful for internal and external comparison
    • Can be measured in terms of business impact
    • Are meaningful to IT’s customers and sponsors
  6. Agree with enterprise management on the key performance metrics that need to be reported. Agree on the key performance metrics with business management so the metrics are meaningful to the business. Obtain IT and business management approval of how IT’s performance will be measured, and communicate the approach to all process stakeholders. Get process owners’ commitment to regularly report on process performance in terms of the defined metrics.
  7. Conduct regular reviews of the performance measurement approach, and revise or update the approach in accordance with management feedback or changing business needs.

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 159 total

Must be a Topic member to contribute
View All »
Downloads
Experienced business and IT professionals know that optimizing their use of big data as a resource will deliver real business value to the enterprise stakeholders.
Posted by ISACA 66 days ago
Downloads
Advanced persistent threat (APT) has been a term used frequently during security threat discussion; however, confusion exists as to what an APT is and how to manage the risk associated with it.
Posted by ISACA 91 days ago
Cobit Related
Posted by ISACA 91 days ago

Events & Online Learning: 4 total

16 Sep 2013
ISACA International Event
London, England
Stay on top of the trends and opportunities of the dynamic technology industry at EuroCACS/ISRM 2013 in Berlin—the leading European conference for IT audit, assurance, security and risk professionals. Save over US $200 when you register by 22 July!
30 Sep 2013
ISACA International Event
Medellín, Colombia
La Conferencia Latinoamericana CACS/ISRM 2013 en Medellín, Colombia es la conferencia principal latinoamericana para los profesionales de auditoría, riesgo y seguridad de la información. Ahorre más de EE.UU. $ 100 si se inscribe antes del 7 de agosto!
14 Oct 2013
ISACA International Event
Boston, MA, USA
6 Nov 2013
ISACA International Event
Las Vegas, NV, USA
North America ISRM is a multidimensional event featuring security and risk content, and the security programs, tools and the resources you need to be responsive to industry changes.

Journal Articles: 340 total

Volume 3, 2013
by Santhosh Patil
Health care spending is a key component of any industrialized nation’s economy.
Volume 3, 2013
by Larry G. Wlosinski, CISA, CISM, CRISC, CAP, CDP, CISSP, ITIL
How will an organization’s information security staff be affected if the organization’s computer systems are moved to a cloud environment?
Volume 3, 2013
by Kumar Setty, CISA, and Rohit Bakhshi
Big data not only encompasses the classic world of transactions, but also includes the new world of interactions and observations.
Volume 3, 2013
by Christopher A. Moturi and Fredrick O. Bitta, CISA
One of the prime concerns in any audit for management is the logical access to computer systems and data.
Volume 2, 2013
by Nurudeen Odeshina, CISA, CISM, CRISC, ISO 27001 LI, ITSM
As is often said, “information security is not a destination, it is a journey,” and for the organization it means continuous improvement.
Volume 2, 2013
by Darlene Tester
Not performing a full risk assessment before determining what security controls should be implemented is equivalent to not “looking before you leap.”

Wikis: 2 total

Blog Posts: 129 total

A recent publication in a local newspaper, indicated that an employee was charged with fraud with regards to claims of insurance payments that were lodged with the company were paid out to people who were not entitled to receive such payments. What po...
Posted By : Paulina.PNI | 1 comments
მოგესალმებით და ამ პოსტში შევეცდები სტანდარტებზე გესაუბროთ. სტანდარტები... მაშ ასე, ინფორმაციული უსაფრთხოების სტანდარტებზე სანამ გადავალთ, გლობალურად არის 2-3 სტანდარტების ტერიტორიები.
Posted By : David190 | 0 comments
Grupos de Estudio para Acreditaciones de JUNIO, SEPTIEMBRE Y DICIEMBRE 2013. Para los que esten interesados en la presentación del exámen de certificación CISA y CISM  o para cualquiera que desee comenzar a prepararse para estas o las próximas pruebas, pu...
Posted By : Alexander Osorio | 0 comments
DISCLAIMER :- Below information is just for knowledge sharing purpose and reference. Personally or on behalf of any organization; I do not recommend any specific / particular tool listed below. These are the ones which I have come across. there may be t...
Posted By : prathameshkarekar | 0 comments
Hoy les comentaré de OpenSSL que es una herramienta muy flexible, que proporciona muchos módulos cada uno de los cuales realiza una tarea específica. Cada módulo no es un ejecutable separado sin embargo se selecciona con el primer parámetro del ejecut...
Posted By : ArthurHuamani | 0 comments
on developerWorks, we've just published How To Guides for Five Common Privileged Identity Management Scenarios https://ibm.biz/Bdxnxe
Posted By : Calvin Powers | 0 comments