Illustration of audit processes aligned with COBIT 5 framework - Global Banking & Finance Review
This image represents the new audit programs issued by ISACA, emphasizing COBIT 5 alignment, which aids IT audit professionals in managing risk and ensuring value creation.
Technology

ISACA ISSUES 23 NEW AUDIT PROGRAMS ALIGNED WITH COBIT 5

Published by Gbaf News

Posted on November 24, 2014

3 min read

· Last updated: December 3, 2018

Add as preferred source on Google

Global IT association ISACA has issued 23 new audit programs aligned with the COBIT 5 framework. The new audit/assurance programs have been developed to help information systems (IS) audit and assurance professionals implement the good practices presented in COBIT 5 for Assurance and incorporate the seven enablers presented in COBIT 5 as part of a consistent assurance approach to assess IT risk.

Overview of APO and BAI Domains

This group of audit/assurance programs covers two important domains: Align, Plan and Organise (APO) and Build, Acquire and Implement (BAI). These domains include enterprise IT management processes that enable day-to-day delivery of IT services and products to achieve enterprise goals. Audit and assurance professionals can use all or subsets of these generic programs to build specific programs that meet their scope and assurance objectives.

APO Domain Processes and Objectives

The APO domain covers 13 processes that lay the foundation to manage information assets in a consistent way that ensures value creation and risk optimization. The 13 APO processes are:

  • Manage the IT Management Framework
  • Manage Strategy
  • Manage Enterprise Architecture
  • Manage Innovation
  • Manage Portfolio
  • Manage Budget and Costs
  • Manage Human Resources
  • Manage Relationships
  • Manage Service Agreements
  • Manage Suppliers
  • Manage Quality
  • Manage Risk
  • Manage Security

BAI Domain Processes Explained

The BAI domain covers 10 processes that ensure that projects will be managed in a consistent and efficient way to enable the enterprise to realize value from information assets. The 10 BAI processes are:

  • Manage Programmes and Projects
  • Manage Requirements Definition
  • Manage Solutions Identification and Build
  • Manage Availability and Capacity
  • Manage Organisational Change Enablement
  • Manage Changes
  • Manage Change Acceptance and Transitioning
  • Manage Knowledge
  • Manage Assets
  • Manage Configuration

An audit program has been developed for each of these processes.

Expansion of ISACA Audit Programs

In total, ISACA now has nearly 30 generic audit/assurance programs aligned with COBIT 5. The Evaluate, Direct and Monitor (EDM) domain covers five processes for the governance of enterprise IT, and those five programs were released earlier in the year to help audit professionals assess the effectiveness of the IT governance framework and its alignment with enterprise goals. Programs for the six processes included in the Deliver, Service and Support (DSS) domain will be released in December.

“ISACA’s audit programs are comprehensive and reference all seven COBIT 5 enablers and their dimensions to assess overall process performance,” said Steven Babb, CGEIT, CRISC, international vice president of ISACA and risk, compliance and assurance leader at Vodafone UK and Ireland. “The programs reference the COBIT 5 goals cascade to ensure that detailed objectives of the assurance engagement can be put into the enterprise and IT context.”

Expert Development and Program Access

The audit programs have been developed and peer reviewed by experienced audit/assurance professionals from around the world. The programs can be downloaded as Microsoft Word™ files to allow customization to fit specific operatingenvironments.

The audit/assurance programs are free for ISACA members and US $45 for nonmembers at www.isaca.org. COBIT 5 is available at www.isaca.org/cobit.

 

Key Takeaways

  • ISACA released 23 new generic audit/assurance programs aligned with COBIT 5 covering APO and BAI domains.
  • These programs supplement earlier releases for the EDM domain, with DSS domain programs slated for December.
  • Professionals can customize the Word-based templates and they are free for members (US $45 for non-members).
  • The programs integrate COBIT 5’s seven enablers and goals cascade to align assurance objectives with enterprise IT context.

References

Frequently Asked Questions

What COBIT 5 domains are covered by the 23 new audit programs?
They cover Align, Plan and Organise (APO) and Build, Acquire and Implement (BAI) domains.
Are the audit programs customizable?
Yes, they are downloadable as Microsoft Word files for customization.
How much do the programs cost?
They are free for ISACA members and cost US $45 for non-members.
When will audit programs for the Deliver, Service and Support (DSS) domain be available?
They are scheduled for release in December of the same year.

Tags

Related Articles

More from Technology

Explore more articles in the Technology category