Sie sind auf Seite 1von 7

Principles of Islam for Information Technology

Governance

Abstract— Islam and IT seems separate at the first glance. In pointed out, it can be regarded as a possible amendment in
essence, they share common points. In this paper, Islam is further versions.
regarded as an umbrella discipline to enlarge the scope of and The reason to select IT governance among the other IT
improve IT governance. In doing so, the study highlights practices in this spectrum is that IT governance is adopted to
similarities and differences between Islam and COBIT in terms manage business activities in general, unlike ITIL and ISO
of format and content. By highlighting the similarities of Islam 17799 that are technical frameworks [7]. Particularly, we
with COBIT it is impressed that they are good practices and will use COBIT as baseline in IT governance for it is an
should be maintained in further versions of COBIT. If a increasingly internationally accepted set of guidance
deficiency in COBIT is pointed out, it can be regarded as a
materials for effective IT governance throughout an
possible amendment in further versions. This study would
hopefully provide valuable insights firstly to people related to
enterprise. Also, it is not process but control based as in
COBIT. And, for Muslim this study would suggest a novel Islam.
interpretation of the Qur'an and Hadith by connecting their This study would hopefully provide valuable insights
mostly known meanings to IT related context. firstly to people related to COBIT. Secondly, for Muslim this
study would provide a novel interpretation of the Qur'an and
Keywords- COBIT, IT governance, Islam, Qur’an, Hadith Hadith by connecting their mostly known meanings to IT
related context. For non-Muslim practitioners, who are
I. INTRODUCTION managing Islamic organizations or managing Muslim
workforce this study would be informative and supportive in
Focusing only on specific rules or principles sometimes making decisions.
leads to minimalism, which is the idea: if it’s not specifically In this paper, firstly the religion of Islam is introduced.
forbidden, it is allowed [2]. This calls for a complete set of The next part is dedicated to investigation of IT governance
rules and principles. However, man-made standards can in Islam. In doing so, concepts of people, process and
change with time, in response to the environment. Therefore, technology in Islam are discussed. Then, a list of particular
it is needed a discipline or road-map which is independent on amendments for COBIT based on the Islamic principles is
time and environment. suggested.
The religion of Islam is perfect and complete [Qur'an 5:3,
30:30] and independent on time and location. Islam also II. RELATED WORKS
includes all the necessary facts, details, and issues that need A search with the key words of 'Qur'an', ‘Qur'an’ and
to be dealt with regarding to the human life [Qur'an 16:89], Hadith on the well-known e-libraries has manifested that
from what to eat [Qur'an 16:115] to how to govern people there is, at the time being, no same or similar research
[Qur'an 38:26]. Based on this, Muslims have regarded the conducted. For this generalization, studies approaching the
Qur'an as light for all areas in their lives and utilize its rules Qur'an and Hadith linguistically are excepted for they focus
and disciplines for advancement and improvement. on the structure of writing, not in the meaning. However, at
In the era of information technology, Islamic scholars least there are some studies targeting the IT related readers
have not kept pace with the IT advancements. For this that use Islamic sources as the main references such [1] and
reason, Islam and IT seems separate at the first glance. In [2]. For instance, paper [1] in its case, elaborates the
essence, they share common points. Here, it is reminded the internationally accepted ethic principles of OECD
fact that Islam is comprehensive and complete so that (Organization of Economic Co-operation and Development)
Islamic sources can support IT fields with a set of beliefs, with Islamic ethics.
ideas, and rules that are to use in IT practices.
In this paper, Islam will be regarded as an umbrella III. ISLAM
discipline to enlarge the scope of IT governance. In
In this section, the foremost features of the religion of
particular, this study highlights similarities and differences
Islam and the two main Islamic sources, the Qur'an and
between Islam and COBIT (framework version 4.1) in terms
Hadith, which Islamic knowledge is deep-rooted from are
of format and content. Thus, by highlighting the similarities
introduced.
between Islam and COBIT it is impressed that they are good
practices and should be maintained in further versions of A. Features of Islam
COBIT. On the other hand, if a deficiency in COBIT is Some of the features of Islam are stated as below. Islam:

© © 2011 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new
collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other
works
 Converts society to the best through ethics by wherein is reiteration. The verse 2:2 says :"This
guiding with justice, fairness, honest, truth, goodness Book, there is no doubt in it, is a guide to those who
[2]. guard"
 “Is comprehensive, which organize the relation  Efficiency: In the verse 6:38, Allah says: "We did not
between: mankind and Allah, mankind them self, neglect/waste in The Book from a thing (the Qur’an,
mankind and other creates of Allah, and mankind the Supreme Preserved Tablet, which is the source of
and environment” [2]. It includes what mankind all books, and the Book of Creation: We have
makes, let us technology. created everything just in its place and for a purpose,
 Associates principles with implementation through so that the universe is maintained in perfect balance
set of worshiping, ethics and dealing acts [2]. This and order) "
characteristic of Islam may contribute systems that  Confidentiality: In the verse 56:79 Allah states that:
have issues in practice. "Which (that Book with Allah) none can touch but
 Is whole life guidance starting from day of birth and the purified."
continue through all the life [2].  Integrity: The verse 18:1 says: “Praise be to Allah,
 Is international. Islam is the religion for all humans Who hath sent to His Servant the Book, and hath
over the world; regardless of their location, time, allowed therein no Crookedness.”
race, nation, religion, and skin color [Qur’an 34:28].  Availability: "We have, without doubt, sent down
 Is based on the natural instinct of humankind: In the Message; and We will assuredly guard it [15:9]"
Qur'an 30:30, it is said: “Therefore, you shall devote till the day of reckoning. And, it is only the one
yourself to the religion of strict monotheism (natural Book that is fully memorized by people.
instinct). Such is the natural instinct placed into the  Compliance: The Qur’an principles rest ultimately
people by Allah. Such creation of Allah will never on Allah, whose knowledge and authority are
change. This is the perfect religion, but most people absolute.
do not know.”  Reliability: In the verse 2:23 it is said that: “If ye are
 Is time independent: Islamic principles are stable and in doubt as to what We have revealed from time to
standard across time. time to Our servant, then produce a Sura like
thereunto; and call your witnesses or helpers (If there
B. Islam Sources are any) besides Allah, if your (doubts) are true.”
There are two main religious texts of Islam: the Qur'an  Proven: In the verse 2:111 Allah says:” They say,
and the Hadith. The Qur'an is the foremost and the main "None will enter Paradise except one who is a Jew or
criterion reference for judging all the other sources. a Christian." That is [merely] their wishful thinking,
Formally, Hadith is mainly defined by Muslim scholars as all Say, "Produce your proof, if you should be truthful."
what prophet Mohammed says, acts, or agreed on. Although  Backed up: There is only one the book that is totally
the Qur'an delivers the main principles of Islam, the Hadith backed up in minds of people.”
helps to understand the Qur’an in practice. Qur'an 33:21 Islamic sources are not limited only to the Qur'an and
says: “The messenger of Allah has set up a good example for Hadith. Written form of sources by Islam scholars extend
those among you, who seek Allah and the Last Day, and and tailor the Qur'an and Hadith to context of their time and
constantly think about Allah”. locations. Thus, the main principles remains stable, and
The Qur’an and Hadith provide people all over the world implementation of them are tailored and shaped according to
with rules (such as in the verse 4:2), standards (such as in the time and location. Surely, one who wants to conduct a study
verse 4:11), formula-like cause and result relation defined by can use these sources in their researches.
the Creator (f(x)=y in form of “if, then, else”, “if you do this,
this will happen” such as in the verse 14:7), recommendation IV. IT GOVERNANCE IN ISLAM
and example of best practices [Qur'an 24:34, 12:3, 33:21] An IT related discipline such as IT governance can, in
and guidance for the best way [Qur'an 17:9, 2:2] in basic, be defined as constitution of the three components:
,relatively, complex world. In doing so, the Qur'an delivers people, process and technology [8]. Hereby, investigation of
its content in the five main areas as following: IT governance in Islam is divided up into these three
1. Origins and fundamentals of all sciences (which subjects.
is the focus in this paper)
2. Information about the creation of the universe A. People:
3. Principles of happiness in the world In COBIT, the concept of people who implement
4. Principles of eternal happiness in the hereafter processes using technology is regarded as a type of resource
5. Essentials of striving in the cause of Allah same as application, information and infrastructure.
In the language of COBIT, the information in Qur'an has However, people have a complex, complicated,
the following information criteria. Addition to COBIT unpredictable characteristics and dynamic relationship
information criteria, the Qur'an is also proven and backed up: happening between them and their environments in their
 Effectiveness: The verse 39:23 declares that Allah roles such as manager, shareholder or stakeholder. For this
has sent down the best statement, a consistent Book
© © 2011 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new
collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other
works
reason, in human-made structures like organizations, in should comply with Islamic principles: being good,
which determining the right combination of mechanisms is a beneficial, justice and right.
complex endeavor [7], are not simple to manage control as
human transfers his complexity to what he builds. Moreover, B. Process:
human, as an asset, has the highest value in an organization The concept of process here is used to cover all around
and holds a considerable piece of risk, thus must be and in it: procedure, policy, methodology, methods,
controlled carefully. On the other hand, people may relationship mechanism, distributing role and responsibilities
potentially resist to or not obey, at least particularly, and such. The religion of Islam does not give certain orders
implementing even ideally perfect disciplines. Hence, the of activities nor mentions how to do them for the way of
concept of human (people) should be considered in a wider processing may vary time to time. Instead, Islam defines and
and deeper scope in IT context, unlike in COBIT, in which it establishes general rules and provides best practices. In this
is underestimated. manner it resembles to COBIT.
According to the Qur'an, Allah has honored human- Another common characteristic shared by Islam and
beings over the other creatures by giving them certain COBIT is being the main and basic reference for guidance
knowledge [Qur'an 17:70]. Allah Almighty said, (2:30-33): and resolving conflicts. For instance, defining roles and
“When the Angels questioned Adam’s suitability for responsibilities in COBIT and making them known by all
representation, Allah cited Adam’s knowledge to convince correspondences avoids possible conflicts. In a Qur'an verse,
them.” Why Allah says in the verses 2:30-33 as term of 2:213, it is said: “Mankind was one single nation, and Allah
knowledge is because knowledge demands action taking and sent Messengers with glad tidings and warnings; and with
must have a direction (purpose). What makes humankind them He sent the Book in truth, to judge between people in
more honorable over the rest of the creatures is its decision matters wherein they differed.” Likewise, the verse 4:59
making mechanism. While angels obey their Creator all the says: “If ye differ in anything among yourselves, refer it to
time, as they are programmed to do so, humans have Allah and His Apostle, if ye believe in Allah and the Last
selections: behaving bad or good, being just or cruel. They Day: That is the best and most suitable for final
have ability of finding the right way in their actions by their determination.”
knowledge that is inherited from the limitless knowledge of It is obvious that merely the written form of rules,
Allah. Same as the inheritance mechanism of the abilities policies, and processes are not the final destination, without
from Allah, partially, to mankind [Qur'an 32:9], man also the implementation they do not possess any value.
transfers these abilities from him to what he makes: Considering that, Allah has sent messengers as model, to
framework (such as COBIT), procedure, organization and show people how to practice what He says in Qur’an. In the
technology. Therefore, simply saying, from end to end Qur'an, 16:44, it is said: “With clear proofs and writings; and
technology and process are connected to Allah, the Creator, We have revealed unto thee the Remembrance that thou
by the bridge of human so that technology and process mayst explain to mankind that which hath been revealed for
should comply with Allah’s authority. them, and that haply they may reflect.” And, in order to
Man’s basic qualification (unique to its kind) is to underline the importance of implementation, the Qur’an
possess the abilities of distinguishing: states, in 46:19: “And to all are ranked according to their
1. Good and bad, deeds.” and in 13:11: “Surely Allah does not change the
2. Beneficial and unbeneficial, condition of a people until they change their own condition.”
3. Justice and tyranny,
C. Technology:
4. Right and wrong
In a step further, these abilities become the sources of Allah delivered scientific information (one of the five
certain disciplines as listed in Table I: main types of contents in the Qur’an) to humans via the
Qur’an and gives ability of distinguishing what is right and
TABLE I. HUMAN’S DISTINGUISHED ABILITIES AND CORRESPONDING wrong to people. This source of information and this ability
DISCIPLINES of man form the base of sciences such as mathematics,
Ability of distinguishing Sources of physics, chemistry, etc. A clear example of the Qur'an based
Good and bad Moral norms and ethics scientific knowledge can be found in the verse 57:25, in
Beneficial and unbeneficial Economics Surat Al-Ĥadīd (The Iron) that says :”..We sent down iron,
Justice and tyranny Science of law wherein is great military might and benefits for the people,
Right and wrong Science of mathematics, physics, and so that Allah may make evident those who support Him
chemistry, etc. and His messengers unseen. Indeed, Allah is Powerful and
Exalted in Might."
For a thing to be adequate, it has to bear these four Recent studies on the source of iron has manifested the
aspects. For instance, five is bigger than four; it is right. fact that iron does not come into existence in Earth in the
However, in case of that these five units of money are earned beginning, it comes from out of the Earth instead. This is
by stealing, a halal four is preferred in Islam. This mindset why in the above verse it is said: "We sent down iron" from
can be applied to all human activities and human-made space to the Earth. Some biology studies have shown the
artifacts such as technology and processes. Thus, technology crucial importance of iron for human body. When looked
© © 2011 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new
collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other
works
from chemistry point of view, Surat al-Hadid is the 57th anything in itself. On the other hand, a pattern in iris
surat in the Qur’an. The numerical value of the word “al- represents its owner's characteristics same as in the palm.
Hadid” in Arabic is 57. The numerical value of “hadid” on One more additional ability of Allah applied to ID's is
its own is 26. As can be seen from the periodic table to the that while human-made ID's can be same, unknowingly, in
side, 26 is the number of the iron atom. different points of time, the ones that Allah creates are
From another point of view, by naming a Surat with the unique across all over the time and locations. In this concern,
name of an element Allah implies the importance of science. the ability of man is limited to know relatively near past and
Apart from this example on science, many more can be predictable piece of future and a defined border of a location
found in the Qur'an such as Surat Ash-Shams (The Sun). such as country. Outside of a time or country the issues arise;
Additionally, in some other verses, humans are encouraged this is why, let us say, a SN is not valid in another county.
to use their mind and wisdom to investigate scientific facts However, it is possible for Allah to manage this in terms of
and the nature of things embedded into them by Allah. both time and location by recording all information about the
For Islam both technology and ability of having creatures, including man, in a book before the creation
information is crucial. Allah says (58:11); “Are those who started. It is stated in the Qur’an verse 35:11: “Allah has
know equal to those who know not? But only they who are created you from dust, then from a drop of semen and then
endowed with understanding keep this in mind.” Considering divided you into pairs; no female conceives or gives birth
this, Islam has manifested the importance of information without His knowledge; and no one’s life is prolonged or
technology. shortened, but it is recorded in a Book. That surely is easy
Information technology (a particular type of technology) for Allah." This Book can be regarded as a database storing
such as tool, application, system, software is an ability that is all the relevant information of what will be created from the
used in an extensive, integrated and optimized manner to first to the last one. Hence, it is easy, as mentioned in the
automate processes and provide tools to improve quality and above verse, for Allah to identify each human uniquely
effectiveness [7]. In doing so, information technology must regardless of the time of creation of the entity.
be ethical, beneficial, delivers right outcomes and complies The time dimension in this Book's records covers the
with rules. In the scope of COBIT, technology must be time of bringing humans to life on the Day of Resurrection.
reliable, right (summing 2 and 3 correctly) and complies with Similarly, as stated in COBIT control objective DS13.3, in
rules of authority. What is addition in Islam is that order a system to be reconstructed a log mechanism is
technology stealing, causing harmful results or providing recommended: “Ensure that sufficient chronological
immoral contents is prohibited. At this point, humans have information is being stored in operations logs to enable the
been informed, in the verse 4:85, that “Whoever supports reconstruction, review and examination of the time
and helps a good cause, will have a reward for it: And sequences of operations and the other activities surrounding
whoever supports and helps an evil cause, shares in its or supporting operations".
burden: And Allah has power over all things.”
Reference [6] mentions that the key to success with B. Logging
technology is not the technology per se but the ability to In COBIT logging for some circumstances is obligated.
manage it well. Again here, as mentioned before, human In DS8.2 it is stated as: “Establish a function and system to
who utilizes technology in order to implement work-flows allow logging and tracking of calls, incidents, service
take an important place and should be considered properly. requests and information needs." and in DS9.2:"Establish
configuration procedures to support management and
III. ISLAM AND COBIT logging of all changes to the configuration repository" and of
In this section some specific examples of shared subjects error logs. Similarly in DS12.3 it is obligated to log physical
between Islam and COBIT are delivered. Here, by accesses to premises, buildings and areas. Another example
highlighting the similarities of Islam with COBIT it is is in AI6 which says “changes (including those to
impressed that they are good practices and should be procedures, processes, systems and service parameters) are
maintained in further versions of COBIT. On the other hand, logged”. Definitely, the purpose of recording (logging) of
if a deficiency in COBIT is pointed out, it can be regarded as each aspect of the events is to establish a full and clear
a possible amendment in further versions. disclosure in order to prevent potential misunderstanding and
conflicts.
A. ID Angles that are entrusted with the task of logging by
Allah creates and assigns a unique ID for each creature Allah also log humans' events. There are two in numbers in
that He has created. The purpose of assigning an ID is each individual: one for recoding bad deeds, the other one
similar with COBIT control objective DS5.3. Instances for for good deeds. This fact has been delivered via the Qur'an
such an ID can be iris, patterns in a palm or in face. These verse 50:18 that says that “He utters not a word but (it is
features are unexceptionally unique in each human from the noted down by) a guardian (angel of his who) stands ready
first to last one. Unlike social numbers, designed by humans by his side (to record his words)”. Not only the word but also
in order to represent an entity, these kinds of features have every activity is recorded by these angles. It is known by the
three dimensions in appearance, in terms of shape. Apart verse 10:61: “In whatever activity you may be engaged, and
from this, a SN contains numbers, which does not mean whichever part of the Qur'an you recite, and whatever deed
© © 2011 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new
collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other
works
you do, We are witness to it when you are engaged in it. Not The same study puts forward that Islam covers the three
the smallest particle on the earth or in heaven is hidden from essential principles in corporate governance defined by the
your Lord...” Allah also knows everything that is in our OECD (Organization of Economic Co-operation and
hearts, whether we conceal or reveal it [Qur'an 3:29]. Development). While, two of the three of these principles,
These logs will be used for a further reference in the Day namely transparency (in COBIT DS2.2), accountability (in
of Judgment in order to judge for award or punishment. COBIT PI1.1 and DS4) are included, adequate disclosure is
While those who do righteous deeds will be awarded, one not contained in COBIT.
who does wrong will be punished accordingly [Qur'an 18:87-
88]. In this way, Allah makes mankind informed and aware D. RACI Chart
that by doing bad deeds, such as hacking, one will be losing When it comes to distributing roles and responsibilities in
double; one with punishment, one with not being awarded. processes, clear and unambiguous definitions of the roles and
Thus, this fact prevents people from harmful events and responsibilities from top to down is crucial and prerequisites
reinforces acting right in a proactive way. for an effective IT governance [7]. RACI charts in COBIT
On the other hand, log records in COBIT are used only framework are useful in this manner. Islam also paves the
for the reference in case of unusual and/or abnormal way with a clear definition of roles and responsibilities.
activities, not for an award for righteous deeds. Example can While the more can be found, an example is this Hadith cited
be found in control objective DS5.5 which dictates that “a in Sahih Bukhari that says: "Every one of you is a guardian
logging and monitoring function is for the early prevention and is responsible for his charges. The ruler who has
and/or detection and subsequent timely reporting of unusual authority over people, is a guardian and is responsible for
and/or abnormal activities that may need to be addressed”. It them, a man is a guardian of his family and is responsible for
is the similar case in DS10 Management guideline. them; a woman is a guardian of her husband's house and
As humankind, we all inherit our abilities from Allah. He children and is responsible for them; a slave is a guardian of
has endless power we have limited yet similar. He saw His his master's property and is responsible for it; so all of you
creatures and watch them in every single time [Qur'an 89:14, are guardians and are responsible for your charges."
57:4, 3:5], we also should watch what we form, and record While IT governance is the responsibility of executives
every transaction for a future reference. In COBIT, recording and board members, the actual governance activities must go
(logging) is for a bad case reference; however in Islamic through many levels of the enterprise [5]. For those who
beliefs it is for both good and bad bids, for punishment or assign responsibilities to roles and specific persons should
awarding. Again, something absent in the COBIT principles additionally consider the following:
is that people are to be mindful that ‘Allah is the Knower’ of  Islam forbids assignment of work that will exceed
what they do and intend [1]. the individual’s capacity. The Qur’an states, in
2:233: “No soul shall have a burden laid on it greater
C. SLA than it can bear.”
SLA is a service level agreement that is a kind of contract  Map responsibilities with the best fit individuals. A
between a service provider and a customer in that the level of Hadith indicates that “Every Muslim is shepherd
service is formally defined. It is a sort of promise that (leader) and he is responsible for that which he
guarantees a service to provide with a certain level of quality shepherds”. The Qur'an, in 28:26, says: “One of the
by the provider to the customer. At this point, the religion of two ladies said, `My dear father! Take him into your
Islam and COBIT (in DS 2.4) require fulfilling agreements service. You cannot do better than employ a man
and contracts. Islam also informs that for every agreement who is strong and trustworthy.' In the translation of
will be certainly questioned about on the Day of Reckoning the Qur'an verse 4:58 by Shabbir Ahmed in Allah
[Qur'an 17:34]. also commands us to entrust our offices to those who
SLA agreements are to be formally documented. The are capable, competent and sincere.
Qur’an also, in the verses 282 and 283of Surah al-Baqarah, And, for those who are responsible, accountable, and
makes an explicit and detailed requirement of written form consulted in their duties should consider the following verses
of agreements: “O you who believe! When you contract a and hadith:
debt for a fixed period, write it down. Let a scribe write it  Obey Allah, and those charged with authority among
down in justice between you...You should not become weary themselves [Qur'an 4:59].
to write your contract down, whether large or small, for its  The Prophet in a Hadith said “Allah love those who
fixed term, that is more just with Allah, more solid as accomplish their job in its best (perfect) manner”.
evidence, and more convenient to prevent doubts among (This highlights the importance of performing
yourselves...Take witnesses whenever you enter into a responsibilities in a perfect manner.)
commercial contract...And do not conceal any evidence for  “Consult them on affairs [of moment]. Then, when
whoever hides it, surely his heart is sinful, and Allah is you have taken a decision, put your trust in Allah”
Knower of what you do.” [Qur'an 3:159].
From another point of view, a service level agreement is  In Islam accountability is not only to authority but
a negotiated agreement between two parties that call for a also to Allah.
consensus. As stated in [1], Islam seeks consensus of parties.
© © 2011 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new
collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other
works
 The accountability in roles and responsibilities is not Hence, an IT governance framework should ensure the
limited to business only but also Islam makes people above requirements met by applying proper control
accountable to Allah, the Ultimate Authority. objectives when possible.
 Islam requires accountability of not only written
records also oral promises [1]. V. SUGGESTIONS FOR COBIT
The suggestions based on Islamic principles made
E. Continuity throughout this paper for COBIT are outlined in the Table II.
Allah calls for mastery in what we do. Thus, it is an The table lists only ones that are additions to the current
obligation for Muslims to seek knowledge diligently and version of COBIT (version 4.1).
obtain excellence in their jobs. Muslims are urged to seek
knowledge from the cradle to grave [3]. Prophet says” seek TABLE II. SUGGESTIONS FOR COBIT
knowledge from birth to death”. In another Hadith, Prophet
Subject Suggestion
says: "A ruler who, having control over the affairs of the People The concept of people should be considered in a wider and
Muslims, does not strive diligently for their betterment and deeper scope not only as an resource.
does not serve them sincerely, will not enter Jannah with Technology Technology should comply with Allah’s authority: being
them.'' (Riyadus Saleheen, 654). This great concept creates a good, beneficial, justice and right. This puts forward the
state of knowledge continuity. On the other hand, COBIT requirement of being ethical for technology.
does not give a space for continuous improvement that Process Process should comply with Allah’s authority: being good,
beneficial, justice and right.
remains as a possible amendment in further versions. ID Assigned ID’s should be unique across time and location
F. Privacy and Ethics as much as possible.
Logging Logs should be used for a further reference in order to
One of the best controls over society is ethics. People, judge not only for punishment but also for award
who engage with IT, should also consider ethics. It is SLA SLA agreements must be checked against defined
believed that security of information can be established fulfillments.
through not only by technology measures, but also with SLA agreements should be writen whether large or small.
Agreements should be relied on consensus.
people's behavior. When it comes to ethical rules, including Adequate disclosure of agreements should be provided to
ones in business, the Qur’an and Hadith use a set of ethical parties.
terms to describe the concept of goodness such as truth, RACI Accountability in roles and responsibilities should be not
goodness, righteousness, equity, equilibrium and justice, Chart limited to business only it should also makes people
truth and right, known and approved honesty, sincerity, piety accountable to Allah, the Ultimate Authority.
The mentioned considerations should be taken into account
[2], transparency, protection of minorities, and a wider by those who assign responsibilities to roles and specific
accountability, protection of confidentiality. persons and by those who are responsible, accountable,
Specific examples include the Qur’an verse 3:110 in and consulted in their duties.
which Allah describes people of the best nation as: “You are Continuity Continuous improvement should be included.
the best of peoples, evolved for mankind, enjoining what is Privacy and Privacy and ethics concerns should be covered
right, forbidding what is wrong, and believing in Allah”. Ethics Ethic principles should be facilitated as a control over risks
Also, the Qur’an requires the honest fulfillment of all
contracts (5:1) irrespective of whether these are written or
oral, explicit or implicit; it prohibits the betrayal of trusts VI. CONCLUSION
(8:27); it describes as sinful to derive any income by “Control over the process of” governing IT “that satisfies
cheating, dishonesty or fraud (4:29 [2]. Prophet Mohammed the business requirement for IT of” enlarging and improving
said “I was sent to complement the best of ethics”. Qur’an the scope of IT governance “by focusing on” similarities and
says: “Help you one another in virtue, righteousness and differences between Islam and COBIT “is achieved by”
piety; but do not help one another in sin and transgression” recommending Islamic principles to be embedded in and
[Qur’an 5:2]. Prophet in his Hadith said “those who cheat us applied to IT governing processes “and is measured by”
are not part of us”. tangible and intangible improvements and amendments in
Muslims, including professionals in IT, have to notice practice.
that Allah will reward them for goodness and punish them
for badness [Qur’an 99:7-8]. And they have to avoided bad REFERENCES
deeds whose final and exact results will be given in the [1] C. Slahudin, “OECD Principles and the Islamic Perspective on
Judgment Day. On the other side, Islam not only points out Corporate Governance”, Review of Islamic Economics, vol. 12, no. 1,
2008, pp. 29–39
these objectionable behavior but also promotes the desired
behavior through encouragement of an enabling environment [2] S. A. Hameed, “Software Engineering Ethical Principles Based on
Islamic Values”, Journal of Software, vol. 4, no. 6, August 2009, pp.
for this purpose by means of effective educational, political, 563-570
social, legal and economic reforms and the building of [3] J. Hashim, “The Quran-Based Human Resource Management and its
proper institutions [1]. Therefore, one of the best operating Effects on Organisational Justice, Job Satisfaction and Turnover
controls over the people can be established. Intention”, The Journal of International Management Studies, vol 3,
no 148 2, August 2008

© © 2011 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new
collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other
works
[4] S. Saad, N. Salim, H. Zainal and S. A. M. Noah, “A Framework for
Islamic Knowledge via Ontology Representation”, Proc. International
Conference on Information Retrieval & Knowledge Management,
(CAMP), IEEE Press, March 2010, pp. .310 – 314,
doi:10.1109/INFRKM.2010.5466897
[5] S. Schreiner, A Survey of IT Governance through COBIT, ITIL, and
ISO 17799, Report, University of Illinois at Urbana-Champaign, Dec.
2008
[6] H. C. Lucas, Information technology: Strategic decision making for
managers. John Wiley & Sons, USA, 2005.
[7] S. D. Haes and W. V. Grembergen, “IT Governance and Its
Mechanisms”, Information Systems Control Journal, vol. 1, 2004
[8] M. Simonsson and P. Johnson, “Assessment of IT Governance - A
Prioritization of COBIT", Proceedings of the Conference on Systems
Engineering Research (CSER), 2006.

© © 2011 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new
collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other
works

Das könnte Ihnen auch gefallen