<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itskeptic.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The IT Skeptic - Comments for &quot;Booyaaa!!  COBIT User Guide for Service Managers now available&quot;</title>
 <link>http://www.itskeptic.org/booyaaa-cobit-user-guide-service-managers-now-avai</link>
 <description>Comments for &quot;Booyaaa!!  COBIT User Guide for Service Managers now available&quot;</description>
 <language>en</language>
<item>
 <title>Control is a force, it gets things done</title>
 <link>http://www.itskeptic.org/booyaaa-cobit-user-guide-service-managers-now-avai#comment-4428</link>
 <description>&lt;p&gt;Mitch,&lt;/p&gt;
&lt;p&gt;The audit view of the world isn&#039;t a  bolt on extra. You don&#039;t do things just because the auditors tell you to, you do things because the audit requirements make you more effective in the long run. Audit simply tells you whether or not you are doing the required things. To put it another way an effective internal audit team is all about promoting best practices. We, with my audit hat on for a moment, talk about controls, but in a positive sense. In the words of  Lawrence Sawyer, the father of modern internal auditing &quot;Control is a force; It gets things done.&quot; &lt;/p&gt;
&lt;p&gt;Trust me on this one, using COBIT  helps you get things done.&lt;/p&gt;
&lt;p&gt;COBIT is chock full of best practices that if followed lead to a more effective IT service. IMHO ITIL v3 would have been greatly enhanced if it had been explicitly aligned with COBIT. If nothing else I find COBIT far less ambiguous than ITIL. The COBIT Service Management book highlighted some of that ambiguity for me with the mapping of COBIT on to the ITIL roles of Product Manager, Service Manager and BRM.&lt;/p&gt;
&lt;p&gt;Governance is a wider issue, and I would recommend the ISO standard for IT Governance ISO 38500. I&#039;ve found it a great way of engaging with C levels.&lt;/p&gt;
&lt;p&gt;Don&#039;t trust any pronouncments  about what COBIT does and doesn&#039;t do from experts unless they&#039;ve read the Control Practices for themselves.&lt;/p&gt;
&lt;p&gt;James&lt;/p&gt;
</description>
 <pubDate>Thu, 09 Apr 2009 10:26:10 +0000</pubDate>
 <dc:creator>JamesFinister</dc:creator>
 <guid isPermaLink="false">comment 4428 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>read the books</title>
 <link>http://www.itskeptic.org/booyaaa-cobit-user-guide-service-managers-now-avai#comment-4426</link>
 <description>&lt;p&gt;Mitch&lt;/p&gt;
&lt;p&gt;never mind what anyone says, instead of repeating received wisdom I suggest you sign up for ISACA and read the books.&lt;/p&gt;
&lt;p&gt;The &lt;em&gt;Control Practices&lt;/em&gt; detail for each of the 34 COBIT processes, for each Control Objective within that process: what are the goals, objectives, value drivers, risik drivers, and practices required to achieve it.&lt;/p&gt;
&lt;p&gt;let&#039;s take an example that everyone here can relate to:&lt;br /&gt;
DS8 Manage Service Desk and Incidents&lt;br /&gt;
DS8.1 Service Desk&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Establish a service desk function, which is the user interface with IT, to register, communicate, dispatch and analyse all calls, reported incidents, service requests and information demands. There should be monitoring and escalation procedures based on agreed-upon service levels relative to the appropriate SLA that allow classification and prioritisation of any reported issue as an incident, service request or information request. Measure end users’ satisfaction with the quality of the service desk and IT services.&lt;/p&gt;
&lt;p&gt;Control Practices&lt;br /&gt;
1. Establish a service desk as a single, initial point of contact for the reporting, monitoring, escalation and resolution of customer requests and incidents. Develop business&lt;br /&gt;
requirements for the service desk, based on service definitions and SLAs, including hours of operation and expected response time to a call. Ensure that service desk&lt;br /&gt;
requirements include identifying staffing, tools and integration with other processes, such as change management and problem management.&lt;br /&gt;
2. Ensure that there are clear instructions for service desk staff when a request cannot be immediately resolved by service desk personnel. Establish time thresholds to&lt;br /&gt;
determine when escalation should occur based on the categorisation/prioritisation of the request or incident.&lt;br /&gt;
3. Implement the necessary support software and tools (e.g., incident management, knowledge management, incident escalation systems, automated call monitoring)&lt;br /&gt;
required for operation of the service desk and configured in accordance with SLA requirements, to facilitate automated prioritisation of incidents and rapid resolution.&lt;br /&gt;
4. Advise customers of the existence of the service desk and the standards of service they can expect. Obtain user feedback on a regular basis to ensure customer&lt;br /&gt;
satisfaction and confirm the effectiveness of the service desk operation.&lt;br /&gt;
5. Using the service desk software, create service desk performance reports to enable performance monitoring and continuous improvement of the service desk.
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Can&#039;t say fairer than that.&lt;/p&gt;
&lt;p&gt;The &lt;em&gt;Assurance Guide&lt;/em&gt; does, yes, have a few pages on auditing.  Then once again for each objective of each of the processes, it details each of the tests of that objective that an auditor would make, which equally serve as a checklist that you are covering off that objective.  Same example:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Enquire whether and confirm that an IT service desk exists.&lt;br /&gt;
• Enquire whether and confirm that analysis has been performed to determine the service desk model, staffing, tools and integration with other processes.&lt;br /&gt;
• Confirm that the hours of operation and expected response time to a call meet business requirements.&lt;br /&gt;
• Enquire whether and confirm that instructions exist for the handling of a query that cannot be immediately resolved by service desk staff. Queries should have priority&lt;br /&gt;
levels that determine the desired resolution time and escalation procedures.&lt;br /&gt;
• Ask relevant personnel about whether tools for the service desk are implemented in accordance with service definitions and SLA requirements.&lt;br /&gt;
• Enquire about the existence of standards of service and communication of the standards with customers.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;And I haven&#039;t quoted the value and risk drivers, which are the value statement for each objective.  It is concise, bullet pointed.   it lacks detail of the implementation but it has the high level of the implementation alright.  It also lacks role descriptions.  So the rank beginner needs more.   But the rank beginner shouldn&#039;t be going it alone anyway - they should be hiring in expertise.&lt;/p&gt;
</description>
 <pubDate>Thu, 09 Apr 2009 06:11:00 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 4426 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>How do you get to best practice without controls?</title>
 <link>http://www.itskeptic.org/booyaaa-cobit-user-guide-service-managers-now-avai#comment-4425</link>
 <description>&lt;p&gt;With respect, the journey to the promised land of best practice requires a combination of things...&lt;/p&gt;
&lt;p&gt;Many may have noticed that ITIL no longer professes to offer &#039;best practice&#039;.  The pudding is in the form of the removal of the phrase (slogan) from the hardcopy covers.  IMHO its reverting to being a &#039;framework&#039;, into which best practices can be placed, is a sensible strategy (or design).&lt;/p&gt;
&lt;p&gt;Control objectives (measures, rules, policies and governance to others) are vital to establish and sustain a better set of practices.  What both are hinting at is an operational (service model) that can be universally applied.  COBIT will likely get their sooner given the impetus behind governance (fundamental in an economic downturn).   ITIL V3 has begun that journey with four lumpy stages to a service lifecycle, but it continues to ignore the transaction side of the house, and has all but dissed both the key realms of applications and systems development.&lt;/p&gt;
&lt;p&gt;Ask yourself - what MUST I have and what can I do without when comparing COBIT, ITIL and other candidates.  Also ask yourself if you have placed your customer at the center of your universe, or a framework.  If the former, good - then make sure you understand how each framework helps you - help your customer achieve their desired results - better, and cheaper.... old stuff this but...&lt;/p&gt;
&lt;p&gt;Whether the practices, policies, procedures and know-how used makes a difference for you and your customers is the measure of a &#039;best practice&#039;.&lt;/p&gt;
</description>
 <pubDate>Thu, 09 Apr 2009 05:05:39 +0000</pubDate>
 <dc:creator>ianclayton</dc:creator>
 <guid isPermaLink="false">comment 4425 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>COBIT vs ITIL</title>
 <link>http://www.itskeptic.org/booyaaa-cobit-user-guide-service-managers-now-avai#comment-4424</link>
 <description>&lt;p&gt;My understanding is that COBIT is about IT governance whereas ITIL is more a framwork for IT best practices.  At least that is what Pink Elephant says.&lt;/p&gt;
</description>
 <pubDate>Thu, 09 Apr 2009 04:33:23 +0000</pubDate>
 <dc:creator>Mitch</dc:creator>
 <guid isPermaLink="false">comment 4424 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Join ISACA</title>
 <link>http://www.itskeptic.org/booyaaa-cobit-user-guide-service-managers-now-avai#comment-4421</link>
 <description>&lt;p&gt;To add to the Skeptic&#039;s support of ISACA there is, for those of you who don&#039;t know, a whole bunch of valuable downloads available to members. The additional $50 subscription to MyCOBIT is a must in my opinion, giving you access to the Control Practices. &lt;/p&gt;
&lt;p&gt;There is a lot more to COBIT than the glib view of so many self declared experts that COBIT is about the &quot;What&quot; and ITIL is about the &quot;How&quot;. Like the Skeptic I use COBIT rather than ITIL as my primary framework when the option is open to me&lt;/p&gt;
&lt;p&gt;James Finister&lt;br /&gt;
Wolston Limited&lt;br /&gt;
www.wolston.net&lt;br /&gt;
www.coreITSM.com&lt;br /&gt;
http://coreitsm.blogspot.com/&lt;/p&gt;
</description>
 <pubDate>Wed, 08 Apr 2009 06:00:52 +0000</pubDate>
 <dc:creator>JamesFinister</dc:creator>
 <guid isPermaLink="false">comment 4421 at http://www.itskeptic.org</guid>
</item>
</channel>
</rss>
