Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

MEASUREMENT OF INFORMATION TECHNOLOGY GOVERNANCE CAPABILITY LEVEL USING COBIT 2019 FRAMEWORK

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

The company, which is engaged in information technology services and solutions, is facing several issues. The first problem is the absence of Standard Operating Procedures (SOPs) for documenting IT risks. Additionally, there have been instances of system downtime on the local servers, affecting both company and client data. Furthermore, data loss has occurred for employee records, financial data, inventory data, and purchasing data from the on-premises company server. To assess the capability level of the company's IT governance, the COBIT 2019 framework was implemented, focusing on operational and security areas. An approach was undertaken to enhance services and operations within the company. The results of the capability level measurement for process objective APO12 indicated that it has reached level 2, with a target capability level of level 3. On the other hand, process DSS01 successfully achieved level 3, meeting its target capability level, while process DSS02 reached level 2 with a target capability of level 3. This suggests that there is a 1-level gap in the APO12 and DSS02 processes. The recommendation given to the company is to concentrate on risk management, finding a balance between the costs and benefits of managing IT-related risks. Moreover, it is advised to minimize disruptions by resolving user incidents promptly.

Similar Papers
  • PDF Download Icon
  • Research Article
  • Cite Count Icon 6
  • 10.33379/gtech.v7i4.3141
Assessment of Capability Levels and Improvement Recommendations Using COBIT 2019 for the IT Consulting Industry
  • Oct 3, 2023
  • G-Tech: Jurnal Teknologi Terapan
  • Saul Carlos Immanuel Simatupang + 1 more

The company engaged in services and information technology solutions is facing issues with Standard Operating Procedures (SOPs) to document IT risks. Additionally, there has been system downtime on the local server, resulting in data loss for employee records, financial data, inventory data, and purchase data. An assessment of the company's IT governance capability is conducted using the COBIT 2019 framework, focusing on operational and security areas. The results of the capability assessment for the APO12 process indicate that it has reached level 2, with a target of level 3. The DSS01 process has already achieved level 3, meeting the target capability level, while the DSS02 process has reached level 2 with a target of level 3. This demonstrates a 1-level gap within the APO12 and DSS02 processes. The recommendation provided to the company is to concentrate on risk management, finding a balance between the costs and benefits of managing IT-related risks.

  • Research Article
  • Cite Count Icon 2
  • 10.54660/ijmor.2024.3.1.25-35
Optimizing IT Governance and Risk Management for Enhanced Business Analytics and Data Integrity in the United States
  • Jan 1, 2024
  • International Journal of Management and Organizational Research
  • Chisom Elizabeth Alozie + 3 more

In the rapidly evolving landscape of business analytics and data management, optimizing IT governance and risk management is critical for ensuring data integrity and enhancing business decision-making processes. This paper explores innovative strategies for optimizing IT governance and risk management frameworks within the context of business analytics in the United States. Effective IT governance is essential for aligning IT strategies with business objectives, ensuring compliance with regulatory requirements, and mitigating risks associated with data management. The study emphasizes the importance of robust IT governance frameworks that incorporate clear policies, procedures, and controls to safeguard data integrity and support accurate business analytics. It highlights the role of risk management in identifying, assessing, and mitigating risks related to data security, privacy, and compliance. By integrating comprehensive risk management practices into IT governance, organizations can enhance their ability to make data-driven decisions while maintaining high standards of data integrity. Key components of effective IT governance and risk management discussed in this paper include the implementation of data governance policies, the adoption of risk assessment methodologies, and the establishment of continuous monitoring and audit mechanisms. The paper also examines the impact of emerging technologies, such as artificial intelligence and machine learning, on optimizing IT governance and risk management practices. Case studies from various U.S. organizations illustrate successful strategies for integrating IT governance and risk management with business analytics. These case studies provide practical insights into overcoming common challenges and achieving enhanced data integrity and business performance. The findings underscore the necessity for organizations to develop a cohesive IT governance framework that addresses risk management proactively and aligns with best practices in data analytics. Recommendations include adopting a holistic approach to IT governance, leveraging advanced technologies for risk mitigation, and fostering a culture of continuous improvement in data management practices.

  • Conference Article
  • Cite Count Icon 6
  • 10.1109/csr54599.2022.9850318
An Approach to Address Risk Management Challenges: Focused on IT Governance Framework
  • Jul 27, 2022
  • Razan M Boodai + 2 more

Information Technology (IT) governance crosses the organization practices, culture, and policy that support IT management in controlling five key functions, which are strategic alignment, performance management, resource management, value delivery, and risk management. The line of sight is extended from the corporate strategy to the risk management, and risk controls are assessed against operational goals. Thus, the risk management model is concerned with ensuring that the corporate risks are sufficiently controlled and managed. Many organizations rely on IT services to facilitate and sustain their operations, which mandate the existence of a risk management model in their IT governance. This paper examines prior research based on IT governance by using a risk management framework. It also proposes a new method for calculating and classifying IT-related risks. Additionally, we assessed our technique with one of the critical IT services that proves the reliability and accuracy of the implemented model.

  • Research Article
  • 10.38142/ijesss.v4i5.636
Information Technology Risks and Governance Disclosure: Evidence From Top 40 JSE Listed Companies
  • Sep 30, 2023
  • International Journal of Environmental, Sustainability, and Social Science
  • Taurayi Stephen Nyagope + 2 more

The study analyzed the extent to which information technology in the 40 JSE-listed companies discloses (IT) risks and governance. It also identified the similarities and differences between the South African King IV governance and other international IT governance and risk disclosure codes. We employed a qualitative content analysis technique and found that 32 of the top 40 JSE-listed entities (80%) completely complied with King IV and other international standards. In contrast, eight of the top forty JSE-listed businesses (20%) partly complied. Moreover, 79% (19/24) of provisions in King IV are similar to that of the international standards, while 21% (5/24) differ. The findings imply that most of the top 40 JSE-listed firms are protected from the consequences of non-compliance with IT risks and governance disclosure, such as going concern risk, fraud, and data manipulations. We also confirmed that King IV provisions regarding IT risks and governance aligned substantially with global standards, enhancing multinational firms' implementation of efficient IT risks and governance.

  • Conference Article
  • Cite Count Icon 11
  • 10.1109/hicss.2011.203
Exploring the Relationships among Corporate Entrepreneurship, IT Governance, and Risk Management
  • Jan 1, 2011
  • R V Bradley + 1 more

This study develops a more comprehensive picture of how a hospitals' entrepreneurial behavior influences its focus on IT governance and IT risk management. The key findings of this study contribute to the IT and corporate culture literatures in several ways. First, it presents corporate entrepreneurship as an antecedent to both IT governance and IT risk management. Second, it establishes a causal relationship between IT governance and IT risk management. Third, it introduces culture strength as moderator of the relationship between corporate entrepreneurship and IT risk management.

  • Conference Article
  • Cite Count Icon 4
  • 10.1109/icoris.2019.8874902
Assessing Application Portfolios of IT Services through Maturity Levels of IT Governance
  • Aug 1, 2019
  • Sandy Kosasi + 2 more

Managing application portfolios of Information Technology (IT) services are not limited to information services. There should be guarantee and integration of synchronization and interoperability of information services. Availability of information services can create risks of IT investment and hinder the effectiveness of organizational performance. The aim of this research was to find out to what extent the use of application portfolios of IT services could support IT processes of Acquire and Implement (AI) and Monitor and Evaluate (ME) Domains. This survey research applied the combination method and a convergent triangulation model through a follow-up explanatory design. Quantitative analysis was performed after online questionnaires were filled out by respondents working at 65 credit unions. These respondents have used application portfolios of IT services in West Kalimantan, Indonesia. COBIT (Control Objectives for Information and Related Technology) 4.1 Framework was in use to measure maturity levels of IT governance. Maturity values of IT governance indicate that IT processes are at the scale interval of 2.51 to 3.50. So far, the use of application portfolios of IT services has been restricted to procedure standardization and documentation system. Also, the conduct has not involved appropriateness of obvious synchronization as well as consistency of procedures and IT service implementation.

  • Research Article
  • Cite Count Icon 4
  • 10.12962/j23546026.y2015i1.1133
The Significant of Cobit Mapping Business Goal 12 and IT Goal 19 (Case Study: Stikom Surabaya)
  • Jan 28, 2016
  • IPTEK Journal of Proceedings Series
  • Siti Mukaromah + 1 more

IT Governance is a branch of the corporate governance system focused on information technology (IT) as well as performance and risk management. IT Governance is defined as the processes that ensure the effective and efficient use of IT in enabling an organization to achieve its goal. There are many different frameworks that can be used for managing the delivery of cost-effective IT services. IT managing the delivery of cost-effective IT services does not always give the advantage to the company. There are times when the IT managing the delivery of cost-effective IT services does not provide any benefit, it can cause IT Productivity Paradox. IT Productivity Paradox can be prevented, one is to analyze the processes undertaken with IT. From this analysis we will get the significance of the relationship processes with the IT Goal. The significance will be seen which one significant process and which one are not significant to the IT Goal. If the IT process there are not significant to the IT Goal, the process does not need to be repaired because it has no effect on IT Goal. Existing IT governance frameworks are COBIT, ITIL, ISO 20000, 17799/27001, Six Sigma, etc. The IT Infrastructure Library (ITIL), initially developed in the UK by the Office of Government Commerce (OGC), is gaining traction in the global IT community as a framework for IT governance. ISO 20000-focusing upon IT service management. ISO 17799 / ISO 27001 - focusing upon information. Six Sigma-focusing upon operational performance and defect identification. COBIT - framework for information IT management risks. Control Objectives for Information and related Technology (COBIT) provides good practices across a domain and process framework and presents activities in a manageable and logical structure. COBIT’s good practices represent the consensus of experts. They are strongly focused more on control, less on execution. These practices will help optimise IT-enabled investments, ensure service delivery and provide a measure against which to judge when things do go wrong. This research is intend to find out whether Cobit mapping Business Goal to IT Goal appropriate with case study. The result The results using SEM approach shows that the mapping of COBIT is not significant in the case studies of academic administration.

  • Research Article
  • 10.35335/jmi.v10i2.1
Development of Contract Management SOP with it Service Providers Supplier Based on the Framework Cobit 5 and ITIL V3 Hospital Case Study Dr Ramelan Navy
  • Sep 30, 2022
  • Jurnal Manajemen Informatika Medicom (JMI)
  • Yundha Puspadini

RSAL Dr. Ramelan is a naval hospital in Surabaya. It is currently developing its Management Information Systems (MIS) with the supplier of IT (Information Technology) service providers. Problems arose when the management change interfere with MIS development. The current management wanted to change MIS supplier before the development process is completed. This can cause financial and time losses. The process of supplier selection, negotiation, contracting and fulfillment control of supplier contracts to always fit the needs of the business is conducted at the Supplier Management. This study aims to make a reference to the management of IT service provider suppliers contracts in the form of SOP (Standard Operating Procedure) which is based on the COBIT 5 framework domain APO10 Manage Supplier and ITIL V3 Supplier Management. Formulation of IT service providers supplier contract management in RSAL Dr. Ramelan SOP document is carried out in four stages. The first stage is the observation of IT services in RSAL Dr. Ramelan. The second stage is the stage of the analysis. This stage is to identify COBIT 5 Manage Supplier and ITIL V3 Supplier Management activities and mapping the activities. Having formed a new activity, adjustments are made to the Regulation of the President of the Republic of Indonesia No. 54 of 2010 concerning the Procurement of Goods and Services. In the third stage, SOP document preparation is done by decomposition of these activities to become sequential action steps. The last stage is the stage of evaluation and improvement, which begins with the verification done in RSAL Dr. Ramelan, then the improvement is done based on the results of verification. The result of this study is an IT service providers supplier contract management SOP document that has been tailored to the condition in RSAL Dr. Ramelan. From the result of the evaluation, it is known that the SOP produced was still in need for improvement in terms of grammar, role and order activity. The SOP document that has been evaluated before has been corrected and improved based on the feedback given by RSAL Dr. Ramelan. Key Words : Supplier Management , COBIT 5 , ITIL , Standard Operating Procedure , Underpinning Contract . The SOP document that has been evaluated before has been corrected and improved based on the feedback given by RSAL Dr. Ramelan. Key Words : Supplier Management , COBIT 5 , ITIL , Standard Operating Procedure , Underpinning Contract . The SOP document that has been evaluated before has been corrected and improved based on the feedback given by RSAL Dr. Ramelan.

  • Research Article
  • 10.35335/jmi.v11i1.48
Development of Contract Management SOP with it Service Providers Supplier Based on the Framework Cobit 5 and ITIL V3 Hospital Case Study Dr Ramelan Navy
  • Mar 30, 2023
  • Jurnal Manajemen Informatika Medicom (JMI)
  • Yundha Puspadini

RSAL Dr. Ramelan is a naval hospital in Surabaya. It is currently developing its Management Information Systems (MIS) with the supplier of IT (Information Technology) service providers. Problems arose when the management change interfere with MIS development. The current management wanted to change MIS supplier before the development process is completed. This can cause financial and time losses. The process of supplier selection, negotiation, contracting and fulfillment control of supplier contracts to always fit the needs of the business is conducted at the Supplier Management. This study aims to make a reference to the management of IT service provider suppliers contracts in the form of SOP (Standard Operating Procedure) which is based on the COBIT 5 framework domain APO10 Manage Supplier and ITIL V3 Supplier Management. Formulation of IT service providers supplier contract management in RSAL Dr. Ramelan SOP document is carried out in four stages. The first stage is the observation of IT services in RSAL Dr. Ramelan. The second stage is the stage of the analysis. This stage is to identify COBIT 5 Manage Supplier and ITIL V3 Supplier Management activities and mapping the activities. Having formed a new activity, adjustments are made to the Regulation of the President of the Republic of Indonesia No. 54 of 2010 concerning the Procurement of Goods and Services. In the third stage, SOP document preparation is done by decomposition of these activities to become sequential action steps. The last stage is the stage of evaluation and improvement, which begins with the verification done in RSAL Dr. Ramelan, then the improvement is done based on the results of verification. The result of this study is an IT service providers supplier contract management SOP document that has been tailored to the condition in RSAL Dr. Ramelan. From the result of the evaluation, it is known that the SOP produced was still in need for improvement in terms of grammar, role and order activity. The SOP document that has been evaluated before has been corrected and improved based on the feedback given by RSAL Dr. Ramelan.

  • Conference Article
  • 10.1109/iccit.2007.4420444
Gap Analysis between Recognition and Implementation for IT Goverance in Korea
  • Nov 1, 2007
  • Jungwoo Lee + 3 more

The role of IT organization is shifting from a simple business supporting center to a strategic value delivery center. As technologies and environmental conditions are changing dynamically and IT risks are increasing, management of IT is becoming more critical. The main objectives of IT management are aligning business and IT by using resources effectively, reducing IT-related risks and maximizing operational efficiency. The concept of IT governance has emerged to address these objectives more systematically. IT governance reflects top-level executives' view on IT by definition. As a link between IT and business, CIO plays an important role to accomplish successful IT governance. In this regard, this study is designed and conducted to reveal Korean CIO's perception on IT governance, especially in relation to five different dimensions of IT governance: strategic alignment, value delivery, IT resource management, risk management and performance measurement. For above dimensions, a survey was conducted to measure the actual implementation level and importance. Gap analysis reveals understanding five dimensions and high expectation dimensions that need to be developed further. This paper also presents recommendations and guidelines for successful IT governance.

  • Conference Article
  • Cite Count Icon 3
  • 10.1109/iccit.2007.266
Gap Analysis between Recognition and Implementation for IT Goverance in Korea
  • Nov 1, 2007
  • Jungwoo Lee + 3 more

The role of IT organization is shifting from a simple business supporting center to a strategic value delivery center. As technologies and environmental conditions are changing dynamically and IT risks are increasing, management of IT is becoming more critical. The main objectives of IT management are aligning business and IT by using resources effectively, reducing IT-related risks and maximizing operational efficiency. The concept of IT governance has emerged to address these objectives more systematically. IT governance reflects top-level executives' view on IT by definition. As a link between IT and business, CIO plays an important role to accomplish successful IT governance. In this regard, this study is designed and conducted to reveal Korean CIO's perception on IT governance, especially in relation to five different dimensions of IT governance: strategic alignment, value delivery, IT resource management, risk management and performance measurement. For above dimensions, a survey was conducted to measure the actual implementation level and importance. Gap analysis reveals understanding five dimensions and high expectation dimensions that need to be developed further. This paper also presents recommendations and guidelines for successful IT governance.

  • Research Article
  • Cite Count Icon 58
  • 10.2308/isys-51626
Antecedents of IT Governance Effectiveness: An Empirical Examination in Brazilian Firms
  • Oct 1, 2016
  • Journal of Information Systems
  • Guilherme Lerch Lunardi + 3 more

Although some authors have stated that effective IT governance is crucial for any organization to achieve its corporate goals, little empirical research is available supporting the assumptions regarding the factors that determine the effectiveness of IT governance. This paper analyzes the main IT governance domains (i.e., IT strategic alignment, IT risk management, IT value delivery, IT resource management, and IT performance management) and the presence of several IT governance mechanisms that constitute antecedents of IT governance effectiveness. We used partial least squares (PLS) structural equation modeling to test our hypotheses based on survey data from 87 large Brazilian companies. Our results show IT strategic alignment, IT value delivery, IT risk management, and IT performance management have a positive and significant impact on the effectiveness of IT governance. Further, we found associations of structural, procedural, and relational mechanisms with the main IT governance domains suggesting their adoption can improve IT governance within organizations.

  • Book Chapter
  • Cite Count Icon 4
  • 10.3233/978-1-60750-688-1-325
Integrating IT Governance, Risk, and Compliance Management Processes
  • Jan 1, 2011
  • Frontiers in artificial intelligence and applications
  • Racz Nicolas + 2 more

Even though the field of Governance, Risk, and Compliance (GRC) has witnessed increased attention over the last years, there is a lack of research on the integrated approach to GRC. This research suggests an integrated process model for high-level IT GRC management. After a discussion of existing process models for integrated GRC, the scope of the research within GRC is defined and explained. Frameworks for the separate topics of IT governance, IT risk management, and IT compliance management are selected and discussed. Finally these frameworks are merged into a single integrated process model. The model is then validated through a comparison to IT GRC processes of three multinational companies.

  • Research Article
  • Cite Count Icon 18
  • 10.25124/ijait.v1i02.875
Proposed IT Governance at Hospital Based on COBIT 5 Framework
  • Aug 14, 2017
  • IJAIT (International Journal of Applied Information Technology)
  • Heru Nugroho

Information Technology (IT) Governance in Hospitals describe how to create an IT governance process that increases the number of IT projects that support the strategy of a hospital and are completed on-time and on- budget. Good IT governance aligns decisions about the use of IT with desired behaviors and organizational objectives. The existence of good IT governance at Hospitals is expected to provide improvement on quality,functionality, and ease of use of the service. Enablers in COBIT 5 framework can be applie in practical situations and can be used to implement effective and efficient information governance and data management of IT governance for Hospital. In this paper, we propose IT governance in Hospital base on COBIT 5 framework. In the preparation of the proposed IT governance model, the enablers that exist in COBIT 5 framework is used as a determining factor. For performing the optimization of IT services to achieve the normal vision andmission uses base on a model of IT governance for a hospital.

  • Research Article
  • Cite Count Icon 2
  • 10.12966/itar.05.02.2013
Using Big Data Analytics in Information Technology (IT) Service Delivery
  • Jan 1, 2013
  • Internet Technologies and Applications Research
  • Fung Han Ping

This paper provides some understandings on what big data analytics are, how they work, some of their applications and how big data analytics can improve the IT service delivery in typical IT organization or IT outsourcing service provider's environment. Both discussion and conclusion are also included. The applications of big data analytics include: recommendation, clustering, classification and frequent pattern matching. Examples for the application of big data analytics are categorized into: a) IT staffing and resourcing, b) IT service level and problem management, and c) IT governance and risk management. Some challenges of adopting big data analytics are also discussed which include: a) Big data analytics are not for everyone, b) Shortage of big data analytical skillset, c) Ethical consideration, and d) Careful planning on what big data to collect.

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant