Abstract

The company, which is engaged in information technology services and solutions, is facing several issues. The first problem is the absence of Standard Operating Procedures (SOPs) for documenting IT risks. Additionally, there have been instances of system downtime on the local servers, affecting both company and client data. Furthermore, data loss has occurred for employee records, financial data, inventory data, and purchasing data from the on-premises company server. To assess the capability level of the company's IT governance, the COBIT 2019 framework was implemented, focusing on operational and security areas. An approach was undertaken to enhance services and operations within the company. The results of the capability level measurement for process objective APO12 indicated that it has reached level 2, with a target capability level of level 3. On the other hand, process DSS01 successfully achieved level 3, meeting its target capability level, while process DSS02 reached level 2 with a target capability of level 3. This suggests that there is a 1-level gap in the APO12 and DSS02 processes. The recommendation given to the company is to concentrate on risk management, finding a balance between the costs and benefits of managing IT-related risks. Moreover, it is advised to minimize disruptions by resolving user incidents promptly.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call