Sie sind auf Seite 1von 7

International Journal of Advanced Engineering Research and Science (IJAERS) [Vol-4, Issue-5, May- 2017]

https://dx.doi.org/10.22161/ijaers.4.5.8 ISSN: 2349-6495(P) | 2456-1908(O)

Combination between Cobit 5 and ITIL V3 2011


El Baz Mourad1, Motii Malik2 , Armand Collins Anong3, Belaissaoui Mustappha4
1
Department of Mathematics and Computer Science, University Dakar Bourguiba , Senegal
2
Department of Mathematics and Computer Science, University Hassan 1, Morocco
3
Department of Mathematics and Computer Science, University Dakar Bourguiba , Senegal
4
Department of Mathematics and Computer Science, University Hassan 1, Morocco

Abstract IT organizations are under increasing pressure to specifically those related to the use of IT assets and
meet the business goals of their companies. This challenge resources across the whole enterprise. ITIL describes in
can be particularly daunting because it involves complying more detail those parts of enterprise IT that are the service
with regulations, such as the SarbanesOxley Act (Sarbox) management enablers (process activities, organizational
and Basel II. Compliance requires strong corporate structures, etc.).
governance capabilities that are demonstrable to outside COBIT is broader than ITIL in its scope of coverage
auditors. Because IT plays such a major role in business (GEIT). It is based on five principles (meeting stakeholder
processes, the IT organization not only creates complexity needs; covering the enterprise end to end; applying a
for the business, but at the same time, provides the means to single, integrated framework; enabling a holistic
demonstrate this compliance. Organizations rely on approach; and separating governance from management)
guidelines such as the IT Infrastructure Library (ITIL ) and and seven enablers (principles, policies and
Control Objectives for Information and related Technology frameworks; processes; organizational structures; culture,
(COBIT) to help understand and address these challenges. ethics and behavior; information; services, infrastructure
Keywords Good practices, ITIL, process, COBIT, IT and applications; people, skills and competencies).
Governance, IT Strategy. ITIL focuses on ITSM and provides much more in -
depth guidance in this area, addressing five stages of the
I. INTRODUCTION service life cycle: service strategy, service design, service
COBIT and ITIL have been used by information transition, service operation and continual service
technology professionals in the IT service management improvement.
(ITSM) space for many years. Used together, COBIT and In addition, COBIT and ITIL are well aligned in their
ITIL provide guidance for the governance and approach to ITSM. The COBIT 5 Process Reference
management of IT-related services by enterprises, Model, as documented in COBIT 5: Enabling
whether those services are provided in-house or obtained Processes, maps closely to the ITIL v3 2011 stages.
from third parties such as service providers or business The distinction between the two is sometimes
partners. Described as COBIT provides the why; ITIL
Enterprises need to govern and manage their information provides thehow. While catchy, that view is
and related technolog y assets and resources, and those simplistic and seems to force a false one or the other
arrangements customarily include both internal and choice. It is more accurate to state that enterprises and
external services to satisfy specific stakeholder needs. IT professionals who need to address business needs in
COBIT 5 aims primarily to guide enterprises on the the ITSM area would be well served to consider using
implementation, operation and, where required, both COBIT and ITIL guidance. Leveraging the
improvement of their overall arrangements relating to strengths of both frameworks, and adapting them for
governance and management of enterprise IT (GEIT). their use as appropriate, will aid in solving business
ITIL provides guidance and good practice for IT service problems and supporting business goals achievement.
providers for the execution of IT service management Many references reflect the best practices developed
from the perspective of enabling business value. over the years. The reality is that each of them focuses on a
COBIT 5 describes the principles and enablers that specific matter: safety, quality, customer services, auditing,
support an enterprise in meeting stakeholder needs, project development, etc...

www.ijaers.com Page | 41
International Journal of Advanced Engineering Research and Science (IJAERS) [Vol-4, Issue-5, May- 2017]
https://dx.doi.org/10.22161/ijaers.4.5.8 ISSN: 2349-6495(P) | 2456-1908(O)
ITIL (Information Technology Infrastructure Library) is a III. WHY ITIL?
set of good practice structured as multiple processes ITIL provides a pragmatic approach to deal with the
communicating with each other. Each has its own role situations in which CIOs are faced, namely, among others:
so that, at the end, they can both respond to the two The IT sector is receiving more and more investment
issues, w h i c h are the continuous improvement and budget. It represents important expenses especially for
customer satisfaction. companies to whom; the main business isnt focused on
COBT Is a reference of information systems; the computing.
perimeter of COBIT governance (created by ISACA Information systems are becoming more complex. As long
Information Systems Audit and Control Association) as the IT workers are trying to meet the requirements
exceeds the one vested in the management of information and demands of their internal customers, they find
systems to all stakeholders encompass in the themselves facing an infrastructure and a large arsenal
company. Malthus, According To COBIT, "governance of application that must be managed and maintained
information systems Is The reference of leaders and the while trying to be responsive.
Board of Directors, it Consists of structures, command and With the advent of new technologies of information and
operation processes leading the IT of the communication (social medias ) , users have become
enterprise tosupport its strategies and business objectives, up to date with all high tech news.
and allow them to expand." Especially since the editors have popularized their
This article helps to highlight the completeness and pooling softwares (advent of open source) and
possible between these two references based on the telecommunications Infrastructure (mobile phone).
perspective of developing a version of COBIT that As long as companies have spent enormous sums of
includes the most used processes of ITIL. money for the IT infrastructure (hardware and software),
the leaders expect a return on investment and begin to
II. UNDERSTANDING TIL tighten the b u d g e t s . Thus, the d iff icu lt situations
To define ITIL, you must be in a context of the CIOs have to face.
continuous improvement and customer orientation needs. Globalization has played its part too. It introduced the
ITIL is a set of good practice structured as multiple practices of service between recharges its subsidiaries.
processes communicating with each other. Each has its This new situation has opened the eyes of CIOs who want
own role so that, at the end, both can respond to the two to bill their services to their internal customers.
issues which are: the continuous improvement and All this was said, made the ambiguous role of the CIO.
customer satisfaction. With the mode of outsourcing, the user begins to ask
ITIL is not a standard because it does not provide questions about the added value of CIOs as external
criteria or a requirementset defined internationally and suppliers support their claims with contracts and a
certifying the organizations. better reactivity.
ITIL is not a methodology or method. It provides and uses For companies specialized in IT, being certified or
methods to better explore the good practice. certifying their staff improve their reputation and
The good practices provide organizations a structure, trust of their internal or external customers. This
approved by years of experience in large companies certification is a label that the CIO can show to proof their
globally recognized for their professionalism and professionalism with standards recognized worldwide.
thoroughness, to formalize their processes and manage Client axis :
their information. These good practices are used primarily For this axis, ITIL will respond to the:
as guidelines to companies serving businesses wishing to Lack of mechanism structured for delivery and service
improve their quality of service. support.
However, to take advantage of the power of all good Lack of confidence in the management of IT services.
practices proposed by ITIL, and following the worldwide Management axis:
recognition of the robustness of its processes, a standard Mismanagement of resources and means.
was created in 2006 based on these good practices. This Failure of service in a frequent way.
standard called ISO20000 international came out to meet Irregularity in meeting the deadlines of requests and
the needs of companies wishing to demonstrate their Claims of customers.
alignment with the good practices recommended by ITIL. Changes or modifications not coordinated or analyzed.

www.ijaers.com Page | 42
International Journal of Advanced Engineering Research and Science (IJAERS) [Vol-4, Issue-5, May- 2017]
https://dx.doi.org/10.22161/ijaers.4.5.8 ISSN: 2349-6495(P) | 2456-1908(O)
Decision Axis: of the project and its services as well as the benefits.
Decisions are made without any pragmatic basis. This makes sure that the resources and expertise required
for the operation of services after their releases are
IV. THE BASIC CONCEPTS OF ITIL available. This involves taking into consideration the
Mainly, ITIL is based on five pillars: impact of performance, availability and budget since the
Customer focus. start of the project.
The life cycle of service. The process concept
The concept of process. The concept of life cycle brings all necessary elements for
Continuous improvement. successful projects from the specification of needs by
Communication. customers until the golive of services.
Customer focus The concept of process has demonstrated its robustness
This concept is crucial for managing IT services. It makes when quality is the matter. ITIL has adopted this approach
the customer needs the main concern of the IT specialist. to structure the philosophy of its good practices as
Thus, whats important is not focusing on multiple processes interacting between each other.
new technologies and the power of servers This concept of process provides answers to the sequence
and telecommunications but rather meeting the functional of activities while undergoing examinations and
need of the customer in the most faithful and most optimal performance indicators measuring the achievement of
way. results for which the process was designed.
Taking into consideration the business needs of the The process owner is responsible for the design of the
customer and make them the main concern of the IT process and ensures that it meets the need defined. He
management is the reason to be of the IT services. reports to company executives.
It is then necessary to fully understand the customer needs, The process manager is responsible for implementation of
follow up their development and establish an organization the process as it was defined by process owner to which
that supports them expressing and monitoring these needs. he reports.
The life cycle of service The quality of service
Before describing the life cycle of the service, we must This concept is the raison dtre of the good practices.
first explain its concept. In general, the service can be Quality service is defined as it has the ability to respond to
defined depending on the context. customer needs exactly as they were defined. The client
In a restaurant we can evaluate the service: smiles, judges their supplier, not based on their how to
atmosphere, responsiveness,... methods but rather based on their appreciation of the
In a tennis match, the service is a trigger of play result within the deadline expected, while respecting the
In an organization, a service is an entity having a function specifications defined.
and a task performed by a group of staff. In that sense, ITIL seeks to improve service in a perpetual
In the IT field, a service is defined as a benefit, help or manner based on the philosophy of Deming wheel: Plan,
assistance a user can expect from a supplier. Do, Act, Check.
In daily life of IT projects, and after the postproduction Communication
of projects, CIOs find themselves faced with two situations: One of the contributions of ITIL is the good
Whether the operations team was not involved in the Communication. It harmonizes the language between
project since its design, creating a frustration having to customers and suppliers. This language removes any
deal with tasks from which they dont understand the ambiguity when the IT s p e c i a l i s ts talk about the SLA
point in the business. agreement, incident, problem, change, ...
Or the project team, as it masters the issue, continue the The good communication is an important component of
project in the operational phase. This generates the service quality. Business Directions must understand the
organizational failures and conflicts of responsibility. issues of IT, their constraints and commitments. The
To avoid this kind of anomaly, ITIL provides the solution communication also facilitates the negotiation of budgets,
and advocates considering the management of services as projects come directly from business requirements.
from the needs study of the IT projects. Thus, the The communication also reflects the transparent aspect of
overlapping roles of the project team and operations team the CIO. This is to convey a clear picture to users, a
are avoided and the operating team is aware of the stakes picture illustrating the negative aspects and most of all the

www.ijaers.com Page | 43
International Journal of Advanced Engineering Research and Science (IJAERS) [Vol-4, Issue-5, May- 2017]
https://dx.doi.org/10.22161/ijaers.4.5.8 ISSN: 2349-6495(P) | 2456-1908(O)
positive ones of the IT management and the efforts of IT systems governance process. It concerns both huge CIOs
resources. as well as CIOs which have outsourced most of their
projects or their operations.
V. COBIT DEFINITION We can couple COBIT with other references, but the PO
COBIT (Control Objectives for Information and field will remain Essential.
related Technology) is a unifying tool that allows Processes acquire and implement (AI):
managers to bridge the gap between control The processes described in this chapter concerns the
requirements, technical issues and business risks. Since its identification, development or acquisition of IT solutions,
first version released in 1996 COBIT has evolved, version their implementation and integration with business
4.1 appeared in 2007. COBIT provides a framework for processes, modification and maintenance of existan
structured control IT operation with 34 processes divided systems systems.
into four areas: The processes of this area are the following:
Plan and organize (PO)
Acquire and implement (AI) AI2: Purchase applications and maintain them
Deliver and support (DS) AI3: Purchase a technical infrastructure and maintain it
Monitor and evaluate (ME) AI4: Facilitate the operation and use
The four fields of CobiT include coherent sets of AI5: Purchase IT resources
processes. PO represents the field of strategic dimension AI6: Manage change
of IT governance. The AI field gathers all processes that AI7: Install and validate changes and solutions
impact resources, from acquisition to implementation.
The DS field is devoted to services offered to clients of Projection of the AI process to ITIL
the CIO. Finally, the SE field covers largely the The AI field covers all of the applications and
controlling, audit and monitoring of everything. infrastructure projects as well as all patches and any kind
COBIT processes of change in the scope of information systems. It is similar
For each of the 34 process, COBIT describes the scope to the chapter Transition Service of ITIL V3.
and purposes and then list and develop: Some will find that the piloting the project itself is not
Control objectives for IT auditors, which are detailed in there. It is true that the AI2 process, which covers both the
other publications; development and maintenance of applications, should be
A management guide written in a logic of governance SI; more explained. It is on this level that we must link the
A maturity model for each process. project management methods that exist elsewhere.
Processes plan and organize (PO): However, this field has the advantage of
The processes described in this chapter discuss the describing Processes that are often ignored, such as the AI4
strategy and tactics to optimize the contribution of IS to process (Facilitate the operation and use), or Neglected,
achieve the business objectives of the company. Such as AI1 process (decision making or not) and AI6 / 7
The processes of this field are the following: (change management, testing and production).
PO1: Defining a strategic IT plan
PO2: Defining the information architecture Processes Deliver and Support (DS)
PO3: Determining technological orientation This area covers the implementation of services: computer
PO4: Defining the processes, organization and labor operations, security management, continuity management
relations service, user support, data management and equipment.
PO5: Managing IT investments The processes of this area are the following:
PO6: Communicate the goals and DS1: Define and manage service levels
management guidelines DS2: Manage thirdparty services
PO7: Managing IT human resources DS3: Manage performance and capacity
PO8: Managing Quality DS4: Ensure continuous service
PO9: Assessing and managing risks DS5: Ensure security of systems
PO10: Managing projects DS6: Identify and allocate costs
DS7: Educate and train users
The PO field describes the 10 strategic information
DS8: Manage support to clients and incidents

www.ijaers.com Page | 44
International Journal of Advanced Engineering Research and Science (IJAERS) [Vol-4, Issue-5, May- 2017]
https://dx.doi.org/10.22161/ijaers.4.5.8 ISSN: 2349-6495(P) | 2456-1908(O)
DS9: Manage configuration management of IT services.
DS10: Manage problems The figure below lists the COBIT processes that are
DS11: Manage data closest
DS12: Manage the physical environment to the ITIL processes. Note that the names of the
DS13: Manage operations process are often the same, reflecting the growing
awareness of ITIL with COBIT designers over the versions.
Projection of DS processes to ITIL
The DS field describes completely the conditions of IT
services supply. It first described the relationship with the
trades (DS1) and with third parties (DS2). This preamble
allows all contractual services.
Essentially, this field is the closest to the related ITIL
processes. Only DS7 seems not to be described in ITIL.

Processes monitor and evaluate (ME):


The processes described in this chapter deal with the
performance management, monitoring of internal control,
compliance with regulatory standards and governance.
The processes of this field are the following:
ME1: Monitor and evaluate the performance of IS
ME2: Monitor and evaluate internal control Why pooling?
ME3: Ensure compliance with external obligations The steps ITIL and COBIT are often conducted separately.
ME4: Implement a governance of IS ITIL was a response to better structure the service centers
which are, for the same reason, the only function to be
Projection of ME processes to ITIL represented as the heart of the process. The procedures of
The process of ME domain describe four levels of the service center concerning the incident management
monitoring and evaluation of the whole system (PO, AI (structuring levels, climbing, registration tickets call,
and DS). Where the process is SE1 the main role as it enrichment databases resolution, etc.) had to industrialize
controls it fully. It should be the starting point for all to meet the demands at lower cost.
deployed processes improvement (a little bit like the Simultaneously, a growing number of organizations are
"continuous improvement" in ITIL V3). outsourcing the support functions, which were not
ME2 process is more difficult to identify because it is necessarily in their core business and seem complicated to
made to monitor the well functioning of the above manage and optimize inhouse. As for tools, editors have
process. This requires an independent responsible, offered more accomplished ones, able to handle all
preferably in internal audit, should be designed. procedures and linking them to a database of resources in
ME3 process has the advantage of isolating the monitoring the broad sense (call tickets, configuration objects, but also
over compliance. Finally, ME4 provides a way to audit the job descriptions, etc.).. All this "arsenal" was built with the
implementation of the governance of IS. ITIL framework.
The key points to consider in order of pooling the two
VI. TOWARDS A POOLING OF COBIT AND approaches are as follows.
ITIL.
ITIL structures its approach of the services Reconcile two cultures
management around the relationship with stakeholders: ITIL culture is pragmatic, constantly confronted with the
daily IT service users and project managers daily issues and geared more towards the service (service
for controlling (businessmanagers, etc.).. COBIT, in continuity, performance). it often manages data objects in a
the same way, has systematically put beforehand the level of detail that only applies to players in the support,
finality of IT services, including meeting the needs of maintenance or operation. COBIT, however, may be
business and the desire to align supply with demand. Both perceived as too theoretical, not often useful nor concrete
approaches share the same values regarding the enough to be deployed easily and effectively.

www.ijaers.com Page | 45
International Journal of Advanced Engineering Research and Science (IJAERS) [Vol-4, Issue-5, May- 2017]
https://dx.doi.org/10.22161/ijaers.4.5.8 ISSN: 2349-6495(P) | 2456-1908(O)
Structuring the whole repository PO9: Assess and manage risk
Avoid duplication of processes, which inevitably occurs if PO10: Manage projects
one does not describe a mapping process to ensure overall
consistency. AI1: Find IT solutions => Management and deployment
into production (Phase transition of service)
Make the link with the studies and developments AI2: Purchase applications and maintain them
ITIL has trouble spread to the teams of studies and AI3: Purchase a technical infrastructure and maintain it
development. It is recognized neither in the management of AI4: Facilitate the operation and use
projects at the elementary level or in the overall AI5: Purchase IT resources
management of portfolios and investments. AI6: Manage change => Change Management (Phase
COBIT has the advantage of giving a comprehensive transition of service)
framework that provides a process of transition, PO10 AI7: Install and validate changes and solutions =>
between ITIL and studies. Management and deployment into production (Phase
transition of service)
Gradually build the data of the ISD model
ITIL gains are interesting but the risk of falling into the DS1: Define and manage service levels => Service
details is big. We must rely on the CMDB to create the Level Management (Design Phase)
data model of the CIO, ensuring distance themselves and DS2: Manage third party services => Supplier
define the granularity of the data relevant for control. Management (Design Phase)
DS3: Manage performance and capacity => Capacity
Management (Design Phase)
VII. TOTAL MAPPING BETWEEN ITIL AND DS4: Ensure continuous service => Continuity
COBIT Management (Design Phase)
Below reconciliation between the phases and processes of DS5: Ensure security of systems => Security
the two repositories, ITIL correspondence is in italics. Management (Design Phase)
Reconciliation of phases DS6: Identify and allocate costs => Financial
Planning and Organizing (PO) => Service strategy Management Service (Strategy service)
Acquiring And Implementing (AI) => Service DS7: Educate and train users => Management and
conception deployment into production (Phase transition of service)
Delivering and Supporting (DS ) => Transition and DS8: Manage support to clients and incidents =>
operation of service Incident Management (Operation Phase)
Monitoring and evaluating (ME) => Continuous DS9: Manage configuration => Asset management and
improvement of service configuration (phase transition)
DS10: Manage problems => Problem Management
(Operation Phase)
Reconciliation of processes DS11: Manage data
PO1: Define a strategic IT plan => Set service strategy DS12: Manage the physical environment
(Strategy service) DS13: Manage operations => (This is a phase according
PO2: Define the information architecture to ITIL)
PO3: Determine technological direction
PO4: Define the processes, organization and labor ME1: Monitor and evaluate the performance of IS =>
relations Phase of continuous improvement of service
PO5: Manage IT investment => financial Management ME2: Monitor and evaluate internal control => Phase of
of service (strategy of service) continuous improvement of service
PO6: Communicate the goals and management ME3: Ensure compliance with external obligations
guidelines ME4: Implement a governance of IS => Portfolio
PO7: Managing IT human resources Management Service (Phase service strategy)
PO8: Managing Quality

www.ijaers.com Page | 46
International Journal of Advanced Engineering Research and Science (IJAERS) [Vol-4, Issue-5, May- 2017]
https://dx.doi.org/10.22161/ijaers.4.5.8 ISSN: 2349-6495(P) | 2456-1908(O)
VIII. RECOMMENDATION FOR A SUCCESSFUL activation and motivation for change.
APPROACH FOR POOLING Make sure there is a clear understanding of objectives.
When used together, COBIT and ITIL provide a top Manage wait times. In most companies, achieving
Down approach for the IT governance and for success takes time and requires continuous
the management of services. The COBIT management improvement.
guide provides a comprehensive approach to Focus first on where it is easier to make changes and
manage objectives and priorities for IT activities. improvements and build from there, one step at a time.
When used together, the power of both approaches is
amplified, with a greater likelihood of management IX. CONCLUSIONS
support and direction, and a more efficient use of The reference of good practices was designed to meet a
resources for implementation. need of structuring the service of processes management, it
responds to this need with more details and efficiency and
Structuring the process also, ITIL remains the most deployed reference in the
The organization needs an effective action plan that suits management of IT infrastructure and service.
their particular circumstances and the needs, but some On the other hand, COBIT gives a more strategically view
recommendations are common to all businesses: of IT management for a better alignment of IT with the
Ensure that the project of setting up standards of enterprise strategy.
governance is in terms of senior management and will be Thus, managers of information systems are faced to two
sponsor of this project. interesting references. Yet each one has a terminology, its
Deficiencies and ensure that IT issues are identified and processes and methodology of implementation. This article
listed has put the focus on processes and common objectives of
Work with management in ensuring alignment of these references and the fields of possible pooling, One of
initiatives with positive impacts on business activities of the the perspective of this paper is to design a version of
company. COBIT that fully integrates common ITIL processes.
Developing dashboards to measure the performance of
IT services REFERENCES
[1] Abdelaali Himi & Samir Bahsani
Planning http://www.ijcsi.org/articles/The-IT-Service-
Establish an organizational framework (ideally as part of a Management-according-to-the-ITIL-framework-
global initiative of IT governance) with clear applied-to-the-enterprise- value-chain.php
responsibilities and objectives. [2] ITIL pour un service informatique optimal- Christan
Ensure the participation of all stakeholders. du mont Edition Eyrolles
Identify project risks [3] Pour une meilleure gouvernance des systmes
Develop strategies for improvement, and decide of the d'information - Dominique Moisand; Fabrice Garnier
highest priority projects that will improve management and de Labareyre Edition Eyrolles 2009
governance. [4] Mapping of ITIL v3 With COBIT 4.1 IT
Consider supporting COBIT control objectives using Governance Institute www.itgi.org
the most detailed ITIL guidelines. [5] C. Dumont. ITIL pour un service informatique
Measure results, establish a dashboard mechanism to optimal (2e dition).
measure current performance and monitor the results of [6] C. Dumont. Mmento ITIL.
further improvements. [7] E. Besluau. Management de la continuit dactivit.

Pitfalls to avoid
There are also some obvious rules, but pragmatic, that
management should follow to avoid the pitfalls:
Treat the initiative to implement a project activity with a
series of phase.
The implementation involves cultural change and new
processes. Therefore, a key success factor is the

www.ijaers.com Page | 47

Das könnte Ihnen auch gefallen