Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO1.3 - Assessment of Current Capability and Performance

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO1.3 - Assessment of Current Capability and Performance is contained within Process Popup Define a Strategic IT Plan.

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
4 Members
0 Online
2687 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!


Assessment of Current Capability and Performance

Assess the current capability and performance of solution and service delivery to establish a baseline against which future requirements can be compared. Define performance in terms of IT’s contribution to business objectives, functionality, stability, complexity, costs, strengths and weaknesses.

        View value and Risk Drivers

        Hide value and Risk Drivers


Value Drivers

  • IT plans contributing transparently to the organisation’s mission and goals
  • Clarity of costs, benefits and risks of IT’s current performance
  • Technological opportunities identified and capabilities leveraged
  • IT capabilities known and operationalised effectively and efficiently to deliver the required solutions and services
  Risk Drivers
  • IT capabilities not contributing to the organisation’s mission and goals
  • Investment decisions taken too late
  • Opportunities and capabilities not leveraged
  • Ineffective use of existing resources
  • Inability to identify baselines for current, and requirements for future, system capability and performance

        View Control Practices

        Hide Control Practices

  1. Capture and report feedback from IT, organisation management and key stakeholders on the current solutions and services. Considerations include, but are not limited to, strengths and weaknesses, functionality, degree of business automation, stability, complexity, development requirements, technology alignment and direction, support and maintenance requirements, costs, and external parties’ (including business partners and vendors) input.
  2. Ensure that IT management is apprised on a timely basis of changes in the enterprise’s mission, goals and objectives, and that such changes initiate a review of the IT strategic and tactical plans and, where warranted, changes thereto.
  3. Periodically compare IT’s current state against the requirements of the IT strategic plan. The outcome of the evaluation includes, but is not restricted to, current requirements, current delivery to requirements, barriers to achieving requirements, and the steps and costs required to remove restrictions.
  4. Consider the results of the assessment of the current performance in the strategic planning process.
  5. Use internal, well-understood and reliable industry, technology or other benchmarks and good practices to assess existing solutions, services and capabilities.

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 57 total

Events & Online Learning: 1 total

30 Sep 2013
ISACA International Event
Medellín, Colombia
La Conferencia Latinoamericana CACS/ISRM 2013 en Medellín, Colombia es la conferencia principal latinoamericana para los profesionales de auditoría, riesgo y seguridad de la información. Ahorre más de EE.UU. $ 100 si se inscribe antes del 7 de agosto!

Journal Articles: 56 total

Volume 3, 2013
by Larry G. Wlosinski, CISA, CISM, CRISC, CAP, CDP, CISSP, ITIL
How will an organization’s information security staff be affected if the organization’s computer systems are moved to a cloud environment?
Volume 2, 2013
by Nurudeen Odeshina, CISA, CISM, CRISC, ISO 27001 LI, ITSM
As is often said, “information security is not a destination, it is a journey,” and for the organization it means continuous improvement.
Volume 1, 2013
by Rajesh Bhatia, CISA, CGEIT, PMP, MDP
IT governance implementation and institutionalization in enterprise business units is dependent on buy-in from the business-unit executives.
Volume 1, 2013
by Ingrid Robinson, CPA, CIA, and Margaret Jodha, CPA, CGA
Today’s IT business environment requires regulatory compliance, cost control, availability, risk management, business alignment, timely project delivery, change and continuous innovation to deliver stakeholder value.
Volume 4, 2012
by Filip Caron and Jan Vanthienen, Ph.D.
This article aims to introduce business process analytics and mining to the information systems (IS) audit and control community.
Volume 3, 2012
by Ookeditse Kamau, CISA, CIA
Quality evidence collected during the audit process enhances the overall quality of the work performed and significantly reduces audit risk.

Wikis: 2 total

Blog Posts: 8 total

A recent publication in a local newspaper, indicated that an employee was charged with fraud with regards to claims of insurance payments that were lodged with the company were paid out to people who were not entitled to receive such payments. What po...
Posted By : Paulina.PNI | 1 comments
Grupos de Estudio para Acreditaciones de JUNIO, SEPTIEMBRE Y DICIEMBRE 2013. Para los que esten interesados en la presentación del exámen de certificación CISA y CISM  o para cualquiera que desee comenzar a prepararse para estas o las próximas pruebas, pu...
Posted By : Alexander Osorio | 0 comments
DISCLAIMER :- Below information is just for knowledge sharing purpose and reference. Personally or on behalf of any organization; I do not recommend any specific / particular tool listed below. These are the ones which I have come across. there may be t...
Posted By : prathameshkarekar | 0 comments
On March 1st,  I was invited to speak at the CampIT conference on Enterprise Risk/Security Management at Rosemont Convention Center. Before me there were two speakers. The first presenter spent an hour presenting the story from the trenches of technolog...
Posted By : Umesh391 | 1 comments
Security is one of the major concerns which hold enterprises from embracing the cloud. But some think that this is manageable and as such have started adopting cloud based SaaS applications. Cloud based Enterprise solutions like Sales Force, Service Now, ...
Posted By : Kannan | 0 comments
7 Mar 2012
To share various espects in cloud computing viz; history, availability, deployment, integrity, availability, confidentiality, security, cloud sharing etc.
Posted By : MoizB583519 | 2 comments