Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO3.1 - Technological Direction Planning

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO3.1 - Technological Direction Planning is contained within Process Popup Determine Technological Direction

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
8 Members
0 Online
2338 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!


Technological Direction Planning

Analyse existing and emerging technologies, and plan which technological direction is appropriate to realise the IT strategy and the business systems architecture. Also identify in the plan which technologies have the potential to create business opportunities. The plan should address systems architecture, technological direction, migration strategies and contingency aspects of infrastructure components.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Improved leveraging of technology for business opportunities
  • Improved integration of infrastructure and applications via defined standards for technical direction
  • Improved use of resources and capabilities
  • Reduced costs for technological acquisitions through reduced platforms and incrementally managed investments
  Risk Drivers
  • Technological acquisitions inconsistent with strategic plans
  • IT infrastructure inappropriate for organisational requirements
  • Deviations from the approved technological direction
  • Increased costs due to unco-ordinated and unstructured acquisition plans

View Control Practices  help

Hide Control Practices  help

  1. Perform a strengths, weaknessess, opportunities and threats (SWOT) analysis of all current critical and significant IT assets on a regular basis.
  2. Follow up on market evolutions and relevant emerging technologies.
  3. Identify the latest developments in IT that could have an impact on the success of the business.
  4. Establish the appropriate technological risk appetite (e.g., pioneer, leader, early adopter, follower).
  5. Identify what is needed in terms of technological directions for business systems architecture, migration strategies and contingency aspects of infrastructure components.

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 157 total

Must be a Topic member to contribute
View All »
Downloads
Posted by ISACA 219 days ago
Downloads
Posted by ISACA 708 days ago
Downloads
Posted by ISACA 762 days ago
Downloads
Posted by ISACA 1093 days ago
Downloads
Advanced persistent threat (APT) has been a term used frequently during security threat discussion; however, confusion exists as to what an APT is and how to manage the risk associated with it.
Posted by ISACA 89 days ago

Events & Online Learning: 6 total

16 Sep 2013
ISACA International Event
London, England
Stay on top of the trends and opportunities of the dynamic technology industry at EuroCACS/ISRM 2013 in Berlin—the leading European conference for IT audit, assurance, security and risk professionals. Save over US $200 when you register by 22 July!
30 Sep 2013
ISACA International Event
Medellín, Colombia
La Conferencia Latinoamericana CACS/ISRM 2013 en Medellín, Colombia es la conferencia principal latinoamericana para los profesionales de auditoría, riesgo y seguridad de la información. Ahorre más de EE.UU. $ 100 si se inscribe antes del 7 de agosto!
14 Oct 2013
ISACA International Event
Boston, MA, USA
6 Nov 2013
ISACA International Event
Las Vegas, NV, USA
North America ISRM is a multidimensional event featuring security and risk content, and the security programs, tools and the resources you need to be responsive to industry changes.

Journal Articles: 356 total

Volume 2, 2013
by Guy Hermann Ngambeket Nd., CISA, CISM, CGEIT, ITIL V3 (F), PMP
Why are organizations instituting corporate social responsibility (CSR) programs?
Volume 2, 2013
by Brian Vazzana, CISA, CICA, CPA.CITP
This article guides the IT professional through the mind and methodology of the IS auditor with a specific focus on procedures performed by external auditors.
Volume 1, 2013
by William Emmanuel Yu, Ph.D., CISM, CRISC, CISSP, CSSLP
This article details additional BYOD security concerns that emerge when considering greater mobility and third-party cloud computing.
Volume 1, 2013
by Pascal A. Bizarro, Ph.D., CISA, Andy Garcia, Ph.D., CPA and Jacob Nix
Risk exists with the implementation of personal mobile devices in business, but with risk comes reward.
Volume 1, 2013
by Srikanth Ravindran, Rajat Sadana and Deepa Baranwal
This article provides insights on BYOD, its implication to IT and how organizations need to approach and adopt it.
Volume 6, 2012
by Mukul Pareek, CISA, ACA, AICWA, PRM
In the world of market and credit risk, scenario analysis is used as a part of stress testing.

Wikis: 2 total

Blog Posts: 41 total

A recent publication in a local newspaper, indicated that an employee was charged with fraud with regards to claims of insurance payments that were lodged with the company were paid out to people who were not entitled to receive such payments. What po...
Posted By : Paulina.PNI | 1 comments
Grupos de Estudio para Acreditaciones de JUNIO, SEPTIEMBRE Y DICIEMBRE 2013. Para los que esten interesados en la presentación del exámen de certificación CISA y CISM  o para cualquiera que desee comenzar a prepararse para estas o las próximas pruebas, pu...
Posted By : Alexander Osorio | 0 comments
DISCLAIMER :- Below information is just for knowledge sharing purpose and reference. Personally or on behalf of any organization; I do not recommend any specific / particular tool listed below. These are the ones which I have come across. there may be t...
Posted By : prathameshkarekar | 0 comments
Before we get into auditing SQL Server permissions a reminder of a few definitions might be helpful. In SQL Server anything that can be granted a right to perform an activity is called a principal. So fundamentally principals are logins, users, roles, ...
Posted By : Ian Cooke | 3 comments
www.itpp.info
Posted By : Alexei.Shindin | 0 comments
5 Nov 2012
Case Studies Based On Real World Experience All OIC Member Contractors have the option to participate in a new component of our Oracle Governance, Risk and Compliance (GRC) training called OIC GRC Reality.  You will have an opportunity to participate...
Posted By : RogerDrolet | 4 comments