Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO4.9 - Data and System Ownership

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO4.9 - Data and System Ownership is contained within Process Popup Define the IT Processes, Organisation and Relationships

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
6 Members
0 Online
2495 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!


Data and System Ownership

Provide the business with procedures and tools, enabling it to address its responsibilities for ownership of data and information systems. Owners should make decisions about classifying information and systems and protecting them in line with this classification.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Users controlling their data and systems
  • Defined accountability for the maintenance of data and system security measures
  • Effective and timely information management processes
  • Reduced financial losses caused by theft of assets
  Risk Drivers
  • Improperly secured business data
  • Improper protection of information assets
  • Requirements for protecting business data not in line with the business requirements
  • Inadequate security measures for data and systems
  • Business process owners not taking responsibility for data

View Control Practices  help

Hide Control Practices  help

  1. Provide policies and guidelines to ensure appropriate and consistent enterprisewide classification of data.
  2. Define, maintain and provide appropriate tools, techniques and guidelines to provide effective security and controls over information assets in collaboration with the owner.
  3. Create and maintain an inventory of information assets (systems and data) that includes a listing of owners, custodians and asset classifications. Include assets that are outsourced and those for which ownership should stay within the organisation.

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 61 total

Must be a Topic member to contribute
View All »
Downloads
Posted by ISACA 710 days ago
Downloads
Posted by ISACA 763 days ago
Downloads
Experienced business and IT professionals know that optimizing their use of big data as a resource will deliver real business value to the enterprise stakeholders.
Posted by ISACA 66 days ago
Books
Posted by ISACA 134 days ago

Events & Online Learning: 6 total

22 Apr 2013
ISACA International Event
Chicago, IL, USA
10 Jun 2013
ISACA International Event
Berlin, Germany
Early bird deadline has been extended: save over US $350 when you register by 1 May. Learn from industry-leading IT experts at Insights 2013. This is a unique opportunity to discover revolutionary new ideas at the world’s premier business event.
16 Sep 2013
ISACA International Event
London, England
Stay on top of the trends and opportunities of the dynamic technology industry at EuroCACS/ISRM 2013 in Berlin—the leading European conference for IT audit, assurance, security and risk professionals. Save over US $200 when you register by 22 July!
30 Sep 2013
ISACA International Event
Medellín, Colombia
La Conferencia Latinoamericana CACS/ISRM 2013 en Medellín, Colombia es la conferencia principal latinoamericana para los profesionales de auditoría, riesgo y seguridad de la información. Ahorre más de EE.UU. $ 100 si se inscribe antes del 7 de agosto!
6 Nov 2013
ISACA International Event
Las Vegas, NV, USA
North America ISRM is a multidimensional event featuring security and risk content, and the security programs, tools and the resources you need to be responsive to industry changes.

Journal Articles: 147 total

Volume 3, 2013
by Kumar Setty, CISA, and Rohit Bakhshi
Big data not only encompasses the classic world of transactions, but also includes the new world of interactions and observations.
Volume 3, 2013
by Dan Bogdanov, Ph.D., and Aivo Kalu, Ph.D., CISA
A cloud is a remote-access platform; thus, technical controls that remotely enforce a particular security policy are especially efficient.
Volume 3, 2013
by Jacqueline Medina, CIPP-IT, Ryan Morrell, CISSP, Dennis Pickett, CISSP, John Lumpkin, Timothy McCain, CISM, Dina Drankus Pekelnicky, Alex Bengoa, MCSE, and David Songco
The National Children’s Study is the largest, most data-intensive study of children’s health ever planned in the US.
Volume 2, 2013
by Joanne Joseph, CISA
This article explores the threats as well as the policy measures that are universally applied to protect users’ data from privacy infringement.
Volume 2, 2013
by Rajesh Bhatia, CISA, CGEIT, PMP, MDP
This article discusses the benefits of using the framework of the five IT governance focus areas.
Volume 6, 2012
by Mukul Pareek, CISA, ACA, AICWA, PRM
In the world of market and credit risk, scenario analysis is used as a part of stress testing.

Wikis: 2 total

Blog Posts: 68 total

A recent publication in a local newspaper, indicated that an employee was charged with fraud with regards to claims of insurance payments that were lodged with the company were paid out to people who were not entitled to receive such payments. What po...
Posted By : Paulina.PNI | 1 comments
Grupos de Estudio para Acreditaciones de JUNIO, SEPTIEMBRE Y DICIEMBRE 2013. Para los que esten interesados en la presentación del exámen de certificación CISA y CISM  o para cualquiera que desee comenzar a prepararse para estas o las próximas pruebas, pu...
Posted By : Alexander Osorio | 0 comments
DISCLAIMER :- Below information is just for knowledge sharing purpose and reference. Personally or on behalf of any organization; I do not recommend any specific / particular tool listed below. These are the ones which I have come across. there may be t...
Posted By : prathameshkarekar | 0 comments
(By: William Darío Ávila Díaz, PhD) During the National Forum on National Security and Defence held on August 30, 2011 in Barranquilla, Teatro José Consuegra Higgins, the head of the Joint Chiefs, General Luis Felipe Paredes, spoke about the advances in ...
Posted By : William733 | 0 comments
Information security has been and remains a very specialized subject. Its early beginnings can be traced to the study of advanced mathematics and cryptography. even today the real theoretical advances happen in University Research Departments, Computer La...
Posted By : Dr Vishnu | 1 comments
5 Feb 2013
Physical Security Fire safety and equipment information: www.usfa.fema.gov/safety Halon alternatives: https://www.denix.osd.mil/denix/Public/News/DLA/Halon/hal1.html Biometric systems used by U.S. Homeland Security: http://tinyurl.com/564lzt Alarm a...
Posted By : Jermaine800 | 0 comments