isaca san francisco 2011 fall security conference g32 a modest proposal

60
G32 The Changing Influences of Social Media, WikiLeaks and Whistleblowers A Modest Proposal: The Future of IT Auditing by Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives

Upload: pw-carey

Post on 12-Jun-2015

221 views

Category:

Documents


0 download

DESCRIPTION

ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

TRANSCRIPT

Page 1: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

G32 The Changing Influences of Social

Media, WikiLeaks and WhistleblowersA Modest Proposal: The Future of IT Auditing

by Mapping ITIL V3 and ISO/IEC 27002 With

CobiT 4.1 Control Objectives

Page 2: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives

• AI (Acquire & Implement)• 1, 2, 3 & 4 --- 6 & 7

• DS (Deliver & Support)• 3, 4, & 5 --- 8, 9, 10, 11, 12 & 13

• ME (Monitor & Evaluate)• 1 & 2

• PO (Plan & Organize)• 1, 2, & 3 --- 5 & 6 --- 8, 9, & 10

2

Page 3: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

3

Page 4: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

4

Page 5: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

5

Page 6: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

6

Page 7: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

7

Page 8: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

8

Page 9: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

9

Page 10: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

10

Page 11: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

11

Page 12: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 & ISO/IEC 27002 W/CobiT 4.1 Control Objectives: Acquire and Implement (AI)

12

Page 13: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

Page 14: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

Page 15: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

Page 16: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

16

Page 17: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

17

Page 18: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

18

Page 19: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

19

Page 20: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

20

Page 21: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

21

Page 22: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

22

Page 23: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

23

Page 24: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

24

Page 25: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

25

Page 26: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

26

Page 27: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

27

Page 28: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

28

Page 29: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

29

Page 30: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

30

Page 31: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

31

Page 32: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

32

Page 33: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Deliver and Support (DS)

33

Page 34: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

34

Page 35: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

35

Page 36: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

36

Page 37: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

37

Page 38: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Monitor and Evaluate (ME)

38

Page 39: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

39

Page 40: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

40

Page 41: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

41

Page 42: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

42

Page 43: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

43

Page 44: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

44

Page 45: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

45

Page 46: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

46

Page 47: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

47

Page 48: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

48

Page 49: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

49

Page 50: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

50

Page 51: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

51

Page 52: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

52

Page 53: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

53

Page 54: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

54

Page 55: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

55

Page 56: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

56

Page 57: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

57

Page 58: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives: Plan & Organize (PO)

58

Page 59: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Summary, Conclusions & Questions

59

Thank you all for your courteous time and attention today:

• Please Note: We’ll be open to and available for discussing any & all areas addressed during this presentation.

Respectfully yours,

Pw CareyConsultant CISA-CISSPCompliance Partners, LLC1250 Grove Avenue, Suite 200Barrington, IL [email protected]/[email protected] or 224-633-1378Fax: 847-381-2067

Page 60: ISACA San Francisco 2011 Fall Security Conference G32 A Modest Proposal

Mapping ITIL V3 and ISO/IEC 27002 With CobiT 4.1 Control Objectives References

60

1. Aligning Cob iT® 4.1, ITIL® V3 and ISO/IEC 27002 for Business Benefit ® A Management Briefing From ITGI and OGC

Reservation of Rights © 2008 ITGI. All rights reserved. No part of this publication may be used, copied, reproduced, modified,

distributed, displayed, stored in a retrieval system, or transmitted in any form by any means (electronic, mechanical, photocopying, recording or otherwise), without the prior written authorisation of ITGI.

Reproduction and use of all or portions of this publication are solely permitted for academic, internal and non-commercial use and for consulting/advisory engagements, and must include full attribution of the material’s source. No other right or permission is granted with respect to this work.

© Crown Copyright material 2008, published in conjunction with the Office of Government Commerce, is reproduced with the permission of the controller of HMSO and Queen’s Printer for Scotland.

ISACA and ITGI are registered trademarks of ISACA. Co b i T® is a registered trademark of ISACA and ITGI. ITIL® is a Registered Trade Mark of the Office of Government Commerce in the United Kingdom and other countries. IT Infrastructure Library® is a Registered Trade Mark of the Office of Government Commerce in the United Kingdom and other countries.

Copies of ISO/IEC 27002:2005 and all ISO standards can be purchased from the American National Standards Institute (ANSI) at http://webstore.ansi.org, phone: +1.212.642.4980; BSI in the UK (www.bsi-global.com/shop.html); and ISO (www.iso.org/iso/store.htm).