Sunteți pe pagina 1din 18

Lab 1.

Identify Enterprise Goals with Strategic Objective


( Case TURISMO Comp.)

Lab Objective
After completing this lab, you will be able to:
 Identify Enterprise Goals
 Alignment Bussines Goals
 Analysis result Enterprise Goals & Strategic Objective

Lab Procedures (masih bingung)

I. GENERAL

CASCADE 2019 TARGETS COBIT Without prioritizing objectives


NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

1.1. Strategic Alignment Business Goals vs. Corporate Goals


1. Buka file Info Company.docx, review informasi dari TURISMO Comp khususnya dibagian
GENERAL.
2. Isi tabel di bawah ini dengan strategic objective dari TURISMO Comp. dan pasangkan dengan
Enterprise Goal dari COBIT 2019 Framework. Lakukan idetifikasi yang tepat untuk masing –
masing corporate goals dan objectivenya. (include example) :

DIMENSION OF THE STRATEGIC OBJECTIVES OF THE


CORPORATE GOALS
BSC BUSINESS

Product portfolio and competitive services.


Increase profitability
(EG01)
____________
________________ ________________

________________ ________________

Client
________________ ________________

____________ ________________ ________________


Cost optimization of business processes.
Improve process effectiveness.
(EG09)

________________ ________________
Learning and growth
Generate a suitable environment for
Product and business innovation. (EG13)
innovation.

1.1.1. Corporate goals resulting COBIT 2019


1. List seluruh corporate goals yang telah diidentifikasi pada tabel sebelumya (include
example)

- Product portfolio and competitive services. (EG01)


- ________________
- ________________
- ________________
- ________________
- Cost optimization of business processes. (EG09)
- ________________
- Product and business innovation. (EG13)
-
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

1.1.2. Analysis corporate alignment resulting


Buatlah sebuah analisis sederhana dari hasil tabel 1.1 dengan melihat keterhubungan antara
strategic objective business dengan corporate goals dari cobit 2019.
_____________________________________________________________________________________________

_____________________________________________________________________________________________

_____________________________________________________________________________________________

_____________________________________________________________________________________________

_____________________________________________________________________________________________

_____________________________________________________________________________________________

____________________________________________________________________________________________
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

Lab 2. Identify COBIT IT Goals with IT Strategic Objective


( Case TURISMO Comp.)

Lab Objective
After completing this lab, you will be able to:
 Identify IT Strategic Objective
 Analysis result COBIT IT Goals & Strategic Objective

Lab Procedures (masih bingung)

II. INFORMATION CENTER (IT)


2.1.1. Alignment Targets 2019 resulting COBIT

To fulfill corporate goals will depend largely on achieving the following targets for IT (P):

REFERENCE COBIT IT TARGETS

AG01 Compliance and R & T support for trade compliance with laws and external regulations

AG02 Managed risk related to I & T

AG03 Profits from the investment portfolio and services enabled I & T

AG04 Quality of financial information related to technology.


AG05 Delivery of R & T in accordance with the requirements of the business.
AG06 Agility to convert business requirements into operational solutions

AG07 Information security, processing infrastructure and applications, and privacy.

AG08 Habilitation and support business processes by integrating applications and technology.

AG09 Program delivery on time, within budget and meeting the requirements and quality standards.

AG10 Quality of management information I & T


AG11 I & T compliance with internal policies
AG13 Knowledge, experience and initiatives for business innovation.
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

2.1.2. Aligning COBIT Goals 2019 resulting with existing IT Strategic Objectives

1. Buka file Info Company.docx, review informasi dari TURISMO Comp khususnya dibagian
INFORMATION CENTER.
2. Isi tabel di bawah ini dengan IT strategic objective dari TURISMO Comp. dan pasangkan dengan
COBIT IT Targets dari COBIT 2019 Framework yang ada di tabel 2.1.1. Lakukan idetifikasi yang
tepat untuk masing – masing COBIT IT TARGETS dann objectivenya. (hint : kosongkan jika
perlu/isi yang sesuai) :

COBIT IT
CMI IT STRATEGIC OBJECTIVES
TARGETS
AG01
AG02
FINANCIAL
AG03
AG04

AG05
CLIENT

AG06

AG07

AG08
PROCESOSINTERNOS
AG09
AG10
AG11

LEARNING AND
AG13
KNOWLEDGE

1.1.1. IT alignment analysis resulting

Customer perspective

"Reduce IT risks." It has been linked to the goal COBIT AG02 (Managed Risk related to T & I) and
that having an appropriate and current knowledge of them is easier to generate measures to
prevent recurrence.

"Increasing the budget set for you." He aligned himself with the goal COBIT AG03 (Benefits derived
from investment portfolio and IT enabled services) by the fact that IT provides benefits if properly
manage the processes to which it is intended.

financial perspective
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

Provide a pleasant experience for both internal and external customer in the use of systems of the
organization. It relates to AG05 (provision of IT services in line with business requirements) as it
focuses on satisfying the customer receiving quality service in line with what is promised.

Having adaptability of IT services to new business requirements. It relates to AG06 (Agility to


transform business requirements into operational solutions) due to the prompt response from IT
services to deliver solutions before certain adversities presented in the business.

Perspective of internal processes

Improve the reliability of information systems. It relates to AG07 (Information security, processing
infrastructure and applications and privacy) by reducing such incidents which may affect financial
loss or loss of confidence to customers.

Implement IT tools to help manage the company. It relates to AG08 (allow and support business
processes including application and technology) as it helps in reducing time; Clearly an investment
to start.

Perspective of learning and growth

Continuous training IT staff tools. It relates to AG13 (knowledge, expertise and initiatives to
innovate in business) because an understanding of it we generate ideas which usually without you,
would be difficult to perform; thus giving rise to innovation.
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

LAB 3.
(BELUM DIOLAH )

III. WATERFALL COBIT TARGETS 2019 - Prioritizing strategic objectives

3.1. Business goals COBIT Prioritized 2019

PRIORITY
Customer Cost
Scope TOTAL
satisfaction effectiveness
5 4 3
Product portfolio and competitive
services. (EG01)
4 5 5
55
Risk management business. (EG02) two 4 5 41
Compliance with laws and external
regulations. (EG03)
two 5 3
39
Culture oriented service to the
customer. (EG05)
5 two 4 Four. Five
Optimization of the internal functions
of business processes. (EG08)
4 two 5
43
Cost optimization of business
processes. (EG09) two 4 5 41
Program management digital
transformation. (EG12)
3 3 3
36
Product and business innovation.
(EG13) 3 3 3 36

Commentary:
Resulting business goals:
EG01: Competitive product portfolio and services
EG05: Culture oriented to the customer service
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

3.2. Aligning COBIT 2019 Prioritized Goals

A prioritized having COBIT business goals, we proceed to prioritize IT goals taking into account the
alignment of these strategic objectives with IT, this can be seen in the table below.

EG01 EG05
ALIGNMENT BETWEEN EG - AG Product portfolio Culture oriented
and competitive service to the
services. customer.

AG04 Quality of financial information related to technology.

Delivery of R & T in accordance with the requirements


AG05
of the business.
Agility to convert business requirements into
AG06
operational solutions
Habilitation and support business processes by
AG08
integrating applications and technology.
Program delivery on time, within budget and meeting
AG09
the requirements and quality standards.
AG10 Quality of management information I & T
Knowledge, experience and initiatives for business
AG13
innovation.

WITH RESULTING AG alignment between IT STRATEGIC OBJECTIVES

COBIT IT
CMI IT STRATEGIC OBJECTIVES
TARGETS
AG01
AG02
FINANCIAL
AG03
AG04

Provide a pleasant experience for both internal and external


AG05
customer in the use of systems of the organization.
CLIENT

AG06 Having adaptability of IT services to new business requirements.

AG07

AG08 Implement IT tools to help manage the company.


PROCESOSINTERNOS
AG09
AG10
AG11

LEARNING AND
AG13 Continuous training IT staff tools.
KNOWLEDGE

COBIT IT goals resulting:


NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

- Goal I & T COBIT 5. Delivery of R & T in accordance with the requirements of the business.
(AG05)
- Meta I & T COBIT 6. mobility to convert commercial requirements operational solutions.
(AG06)
- Meta I & T COBIT 8. Enabling and support business processes by integrating applications
and technology. (AG08)
- Goal I & T 13. COBIT knowledge, experience and initiatives for business innovation. (AG13)

3.3. With related control objectives prioritized Goals Alignment

AG RESULTING FROM THE ALIGNMENT AND OBJECTIVES OF CONTROL


REFERENCE OBJECTIVES OF CONTROL AG05 AG06 AG08 AG13
APO02 managed strategy one
APO03 managed enterprise architecture one one
APO04 managed innovation one one
APO05 Managed portfolio one
APO07 HR-managed one
APO08 Managed relationships one one one
APO09 Managed Service one
APO10 managed providers one
BAI02 Managed requirements definition one one
Identification and construction of
BAI03 one one
managed solutions
BAI04 Availability, and managed one
BAI05 managed organizational changes one
BAI06 IT changes managed one
Management acceptance of IT change
BAI07 one
and transition
BAI08 Managed knowledge one
BAI11 managed projects one
DSS01 Managed operations one
Managed service requests and
DSS02 one
incidents
DSS03 problems managed one
DSS04 continuity managed one

DSS06 Managed business process controls one

Performance Monitoring and


MEA01 one
Compliance Managed
Prioritization of control objectives
Legend:
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

Prioritization disorderly:
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

Prioritization ordinate:
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

3.4. Related initiatives COBIT Control Objectives Mapped

APO02: Management Strategies


Control target-oriented view of the business environment and the future direction to take the
necessary initiatives to achieve that direction with the formulation of a development roadmap of
activities to fill the gaps.
Initiative
- Evaluation of digital maturity of the company
- Activities
o Grassroots Development Application Analysis I & T in the business.
APO03: Enterprise Architecture Management
Control target-oriented establishment of the necessary enterprise architecture for the digital
transformation, this consists of layers of business processes, information, applications and
technological resources
Initiative
- Development of enterprise architecture required
- Activities
o Development of enterprise architecture proposal required by the institution.
APO04: Innovation managed
Control target oriented constant attention to technological changes applicable to the business,
identifying opportunities and making profits through innovation
Initiative
- Create an environment inclined towards innovation
- Exercise
o Institutionalizing brainstorming sessions to generate new opportunities in the use
of technologies.
APO05: Portfolio administered
Control target-oriented portfolio optimization company programs based on their needs and
performance obtained / expected of individual programs.
Initiative
- Evaluation and selection of programs to be financed
- Exercise
o Conduct portfolio prioritization of development projects and outstanding
APO07: Human Resources managed
Control objective aimed at optimizing the capabilities of human resources to meet business goals
Initiative
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

- Manage activities of human talent in periods of company work.


- Exercise
o Development of the system of human resource management.
APO08: Managed Relationships
Control target-oriented management of relations with stakeholders of the business ensuring
mutual trust and mutual work to achieve strategic objectives
Initiative
- Understand the expectations of the business
- Exercise
o Set up meetings between stakeholders of the business and personnel IT area.
 Objective: Close gaps between expectation and feasibility among
stakeholders and staff.
APO09: Managed Service
Control target-oriented assurance that products, services and service levels I & T meet current
and future business needs.
Initiative
- Identify services related to R & T
- Exercise
o Program reviews I & T services and their alignment with the business process
support
 Objective: To identify gaps between what happens and what should
happen in the services I & T
APO10: Suppliers managed
Control target oriented management contractors employing the company in its process
outsourcing.
Initiative
- Identify and evaluate contractor relationships and contracts
- Exercise
o Establish reviews work done by contractors
BAI02: Definition of requirements managed
Control target-oriented creation of optimal solutions to meet business needs while minimizing risk
Initiative
- Define and maintain the functional and technical requirements of the business
- Exercise
o Perform the documentation required information by the company and / or
stakeholders
 Objective: To determine the flows of information handled by the institution
for the development of technological proposals for control in the future.
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

BAI03: Identification and construction of managed solutions


Control objective aimed at ensuring scalability and agility of delivering digital products and services.
initiatives
- Standardization of a project model oriented specifications and points of interest of the
company
- Exercise
o Formulation of a project outline high level.
 Objective: To establish a model where you have clear points of interest
for the organization in formulating projects.
BAI04: availability, and managed
Control target aimed at maintaining the availability of services and efficiency of resource
management and performance optimization of systems through predictions of future performance
and capacity requirements
Initiative
- Determine availability, and current capacity plunged and create a baseline
- Exercise
o Identify incidents due to inadequate performance and capacity
 Objective: To determine performance gaps existing systems already
implemented in the company to obtain a baseline of performance.
BAI05: Organizational changes managed
Control target-oriented stakeholders prepare for changing business and reduce risks that could
lead to their failure.
Initiative
- Implant the desire for change
- Exercise
o Perform study "areas of pain" in the current processes in conjunction with the
process owners
o System performance reporting incidents of customer dissatisfaction and operator
 Objective: To have a vision of the problems facing the company today to
formulate a desired benefits and drawbacks clear to communicate to
stakeholders and promote appetite to change state.
BAI06: IT changes managed
Goal-oriented control enable delivery of updates to the business quickly and reliably. Mitigating
risks concerning stability or integrity of the environment
Initiative
- Assess, prioritize and authorize change requests
- Exercise
o Establishing processes and formats change request for process owners and IT
staff to business processes, infrastructure and applications.
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

 Objective: Formalizing change requests in the points mentioned so that


they have clear points of interest for the company.
BAI07: Managing IT acceptance of change and transition
Control target-oriented implementation of solutions safely and in accordance with expectations and
agreed outcomes
Initiative
- Identify and document implementation risks and options "rollback" and recovery process
- Exercise
o Make backup plans existing systems and processes restoration of computer
systems
 Objective: To have a first level of security in the implementation of new
computer systems should not meet agreed requirements.
BAI08: Knowledge managed
Control objective is aimed at providing required information on different functions I & T to make a
correct decision.
Initiative
- Validate information, classify and define their origin to assist in the management of R & T.
- Exercise
o Identify key sources of information and documented facts, users, social media,
etc.
 Objective: To know clearly the main sources of information and validate
whether the information provided is useful for making business sedition.
BAI11: Projects managed
You control target to improve communications in order to avoid risks cost-oriented.
Initiative
- Standardize the management about revisions and aligned activities with value creation and
business objectives.
- Exercise
o Apply a standard in project management, including the use of best practices based
on defined processes and technology that fits this approach.
 Objective: Be sure to set focus has covered aspects covered from the life
cycle of the project to the different branches of management (risk, cost,
time, etc).
DSS01: Operations managed
Control objective to ensure delivery of results in the planned time.
Initiative
- Create procedures and operational tasks reliable and consistent.
- Exercise
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

o Verify that the expected data is accurate and timely and the results delivered
provide solutions to the requirements of the company.
 Objective: To ensure that users receive correct results in a timely manner.
DSS02: Managed Service Requests and incidents
Control target oriented expedite the resolution of incidents during the process to restore service as
soon as possible.
Initiative
- Classification of incidents and service requests.
- Exercise
o Analysis of incidents within the company regarding computer systems.
o Incident classification and prioritization of response.
 Objective: To establish care priorities incidents within the normal workflow
for future action plans.
DSS03: Operations managed
Control objective to identify the source of problems and timely resolution of incidents recurring.
Initiative
- Manage availability of services and identify key issues and causes that generate it to
improve customer satisfaction.
- Exercise
o Formally handle problems accessing relevant data.
o Identify problems with the help of incident reports, error log.
 Objective: To reduce the number of operational problems identified the
root problem.

DSS04: Continuity Managed

Control objective to achieve stability and normal flow processes to any significant interruption
(incidents, demands, new opportunities).
Initiative
- Define the scope of business and politics taken into account in the project. Check that align
with the objectives of the stakeholders to enhance the resilience of the business.
- Exercise
o Identify key stakeholders, scope and policies.
o Highlight support business processes and services R & T with which it relates.
 Objective: To improve response and recovery incidents.
DSS06: Business Process Controls managed

Control objective that helps define process controls to ensure that the information received can
meet the control requirements of relevant information.
NATIONAL UNIVERSITY OF TOURISM DAY TRUJILLO SA

Initiative
- Assess and monitor the implementation of activities taking into account the business risks
that this entails.
- Exercise
o Implement automated controls.
o Verify that the information obtained is complete, valid and accurate.
o Prioritize activities according to the risk presented.
 Objective: To improve the quality of the information obtained to the
processed being and ensure that it is useful for the organization.
MEA01: Performance Monitoring and Compliance Managed

Control target oriented assessment processes through metrics monitoring processes perform the
agreed targets.
Initiative
- Providing performance transparency to boost the achievement of objectives. Engage with
stakeholders to establish monitoring.
- Exercise
o Request prioritize and allocate resources to monitor based on different aspects
(efficiency, effectiveness, confidentiality, etc.)
 Objective: To ensure that the company knows the performance of the
organization in different areas to establish training plans or process
improvement if necessary.

S-ar putea să vă placă și