60
G32 The Changing Influences of Social Media, WikiLeaks and Whistleblowers A Modest Proposal: The Future of IT Auditing by Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives

San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Embed Size (px)

Citation preview

Page 1: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

G32 The Changing Influences of Social

Media, WikiLeaks and WhistleblowersA Modest Proposal: The Future of IT Auditing

by Mapping ITIL V3 and ISO/IEC 27002 With

CobiT 4.1 Control Objectives

Page 2: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives

• AI (Acquire & Implement)• 1, 2, 3 & 4 --- 6 & 7

• DS (Deliver & Support)• 3, 4, & 5 --- 8, 9, 10, 11, 12 & 13

• ME (Monitor & Evaluate)• 1 & 2

• PO (Plan & Organize)• 1, 2, & 3 --- 5 & 6 --- 8, 9, & 10

2

Page 3: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

3

Page 4: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

4

Page 5: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

5

Page 6: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

6

Page 7: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

7

Page 8: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

8

Page 9: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

9

Page 10: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

10

Page 11: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

11

Page 12: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

12

Page 13: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

Page 14: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

Page 15: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

Page 16: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

16

Page 17: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

17

Page 18: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

18

Page 19: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

19

Page 20: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

20

Page 21: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

21

Page 22: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

22

Page 23: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

23

Page 24: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

24

Page 25: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

25

Page 26: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

26

Page 27: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

27

Page 28: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

28

Page 29: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

29

Page 30: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

30

Page 31: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

31

Page 32: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

32

Page 33: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

33

Page 34: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

34

Page 35: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

35

Page 36: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

36

Page 37: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

37

Page 38: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

38

Page 39: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

39

Page 40: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

40

Page 41: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

41

Page 42: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

42

Page 43: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

43

Page 44: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

44

Page 45: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

45

Page 46: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

46

Page 47: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

47

Page 48: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

48

Page 49: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

49

Page 50: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

50

Page 51: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

51

Page 52: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

52

Page 53: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

53

Page 54: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

54

Page 55: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

55

Page 56: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

56

Page 57: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

57

Page 58: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

58

Page 59: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Summary, Conclusions & Questions

59

Thank you all for your courteous time and attention today:

• Please Note: We’ll be open to and available for discussing any & all areas addressed during this presentation.

Respectfully yours,

Pw CareyConsultant CISA-CISSPCompliance Partners, LLC1250 Grove Avenue, Suite 200Barrington, IL [email protected]/[email protected] or 224-633-1378Fax: 847-381-2067

Page 60: San Francisco Isaca Fall Security Conference G32 A Modest Via Cobi T Proposal 4.2

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives References

60

1. Aligning Cob iT® 4.1, ITIL® V3 and ISO/IEC 27002 for Business Benefit ® A Management Briefing From ITGI and OGC

Reservation of Rights © 2008 ITGI. All rights reserved. No part of this publication may be used, copied, reproduced, modified,

distributed, displayed, stored in a retrieval system, or transmitted in any form by any means (electronic, mechanical, photocopying, recording or otherwise), without the prior written authorisation of ITGI.

Reproduction and use of all or portions of this publication are solely permitted for academic, internal and non-commercial use and for consulting/advisory engagements, and must include full attribution of the material’s source. No other right or permission is granted with respect to this work.

© Crown Copyright material 2008, published in conjunction with the Office of Government Commerce, is reproduced with the permission of the controller of HMSO and Queen’s Printer for Scotland.

ISACA and ITGI are registered trademarks of ISACA. Co b i T® is a registered trademark of ISACA and ITGI. ITIL® is a Registered Trade Mark of the Office of Government Commerce in the United Kingdom and other countries. IT Infrastructure Library® is a Registered Trade Mark of the Office of Government Commerce in the United Kingdom and other countries.

Copies of ISO/IEC 27002:2005 and all ISO standards can be purchased from the American National Standards Institute (ANSI) at http://webstore.ansi.org, phone: +1.212.642.4980; BSI in the UK (www.bsi-global.com/shop.html); and ISO (www.iso.org/iso/store.htm).