SlideShare a Scribd company logo
1 of 20
A Flexible Method for COBIT
2019 Process Selection
André Fernandes, Rafael Almeida, Miguel
Mira da Silva
Agenda
• Introduction
• Research Question
• Theoretical Background
• Proposal
• Demonstration
• Evaluation
• Conclusion
2
Introduction
• From COBIT 5 to COBIT 2019
• Generic
• Provide guidance
• Apply to enterprises of all sizes
3
Introduction
• COBIT 2019
• Design Factors
• Goals Cascade
• The COBIT 5 Mechanism
• One of the Design Factors
4
Research Question
• Addition or removal of Design Factors
• Design Factor has its own set of evaluation parameters that are
impossible to be modified, added or deleted
• With the absence of customisation possibilities, this process
cannot be adapted to the particular context of an organisation or
improved based on the experiences and knowledge of expert
• There is a lack of theoretical evidence that supports COBIT2019
method
5
Theoretical Background
• Contingency Factors:
• Factors that, depending on organizations context, may influence the EGIT
implementation. (Pereira & Mira da Silva, 2012)
• These factors are called EGIT contingency factors
6
Theoretical Background
7
Authors Identified Factors
(Pereira and Mira da Silva 2012) • Culture
• Structure
• Size
• Industry
• Regional Differences
• Maturity
• Strategy
• Ethical
• Trust
(Weil and Ross 2004) • Strategic and performance goals
• Structure
• Governance experience
• Size and Diversity
• Industry and Regional differences
(Sambamurthy and Zmud 1999) • Overall Governance mode
• Firm size
• Diversification mode
• Diversification breadth
• Exploitation strategy for scope
economies
• Line IT knowledge
Theoretical Background
• Multi-Criteria Decision Making (MCDM)
• Methods that support decision making in the presence of multiple criteria
factors
• Can be applied into diverse real-world decisions.
8
Theoretical Background
• Analytic Hierarchy Process (AHP)
• Method for ranking decisions alternatives and selecting the best one
• Works with multiple criteria
• One of the most recognized methods in the literature (Velasquez & Hester,
2013)
• Consistency Ratio
9
Proposal
• Universality: The method should be applicable to all Design Factors.
• Customisable Criteria: The method should allow the organisation to
determine the weight of each of the criteria.
• Flexibility: The method should allow the addition or removal of
criteria as intended by the organisation.
• Automatic: Part of the process should be completely automated. The
level of automation should be similar to that presented by the COBIT
2019 Toolkit.
10
Proposal
11
Criteria
Sub-Criteria
Alternatives
Proposal
12
Proposal
13
Demonstration
• Choosing Egs
• EGs Prioritisation
14
EG 03 EG 11
EG 03 1 1
EG 11 1 1
Demonstration
• Cascade To AGs
• AGs Prioritisation
15
AG 01 AG 11
AG 01 1 1/3
AG 11 3 1
AG 01 AG 11
AG 01 1 1
AG 11 1 1
Demonstration
• Results
16
Evaluation: First round of Interviews
• 20 IT managers and COBIT specialists were invited
• 14 accepted the invitation
• Categorization of the candidates
1. Fundamental Awareness (basic knowledge)
2. Novice (limited experience)
3. Intermediate (practical application)
4. Advanced (applied theory)
5. Expert (recognized authority)
17
Evaluation: Second round of Interviews
18
Conclusion
• Achievements
• Management Objectives are
prioritised
• Flexible
• Universal
• Customisable
• Automatic
• Limitations
• More empirical work
• Human subjectivity
• Greater geographical diversification
• Lack of scientific studies
19
A Flexible Method for COBIT
2019 Process Selection
André Fernandes, Rafael Almeida, Miguel
Mira da Silva

More Related Content

Similar to cobit

Streamlining a Global Life Sciences Company's Pharmacovigilance Operations
Streamlining a Global Life Sciences Company's Pharmacovigilance OperationsStreamlining a Global Life Sciences Company's Pharmacovigilance Operations
Streamlining a Global Life Sciences Company's Pharmacovigilance OperationsPerficient
 
2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...
2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...
2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...Perficient
 
chapter06.pptx
chapter06.pptxchapter06.pptx
chapter06.pptxDataRobert
 
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdfSabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdfBrion Carroll (II)
 
Agile and Its Impact on Productivity
Agile and Its Impact on ProductivityAgile and Its Impact on Productivity
Agile and Its Impact on ProductivityDCG Software Value
 
How to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery PhaseHow to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery PhaseMontrium
 
Benchmarking for hrd professionals
Benchmarking for hrd professionalsBenchmarking for hrd professionals
Benchmarking for hrd professionalsSorab Sadri
 
Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)
Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)
Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)Lungelo Gcwabaza
 
Project_Integration_Managemen.pptx
Project_Integration_Managemen.pptxProject_Integration_Managemen.pptx
Project_Integration_Managemen.pptxIvarsLinde1
 
Poor business analysis The Culprit of IT project Failure
Poor business analysis  The Culprit of IT project FailurePoor business analysis  The Culprit of IT project Failure
Poor business analysis The Culprit of IT project FailureRezaul Karim Majumder
 
Business Process Management Introduction
Business Process Management IntroductionBusiness Process Management Introduction
Business Process Management IntroductionGBTEC Software AG
 
Webinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessmentsWebinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessmentsBiZZdesign
 
The Six Month Data Center
The Six Month Data CenterThe Six Month Data Center
The Six Month Data Centersflaig
 
CompTIA Project+ Objectives
CompTIA Project+ ObjectivesCompTIA Project+ Objectives
CompTIA Project+ Objectivessombat nirund
 
Governing Agile Teams: Disciplined Strategies to Increase Agile Effectiveness
Governing Agile Teams: Disciplined Strategies to Increase Agile EffectivenessGoverning Agile Teams: Disciplined Strategies to Increase Agile Effectiveness
Governing Agile Teams: Disciplined Strategies to Increase Agile EffectivenessTechWell
 

Similar to cobit (20)

SSCG 8D Problem Solving
SSCG 8D Problem SolvingSSCG 8D Problem Solving
SSCG 8D Problem Solving
 
Streamlining a Global Life Sciences Company's Pharmacovigilance Operations
Streamlining a Global Life Sciences Company's Pharmacovigilance OperationsStreamlining a Global Life Sciences Company's Pharmacovigilance Operations
Streamlining a Global Life Sciences Company's Pharmacovigilance Operations
 
2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...
2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...
2013 OHSUG - Facilitating Pharmacovigilance Globalization with Process Reengi...
 
chapter06.pptx
chapter06.pptxchapter06.pptx
chapter06.pptx
 
PMP-Scope Management area
PMP-Scope Management areaPMP-Scope Management area
PMP-Scope Management area
 
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdfSabrion_Consulting_Overview CPG Retail Apparel.pdf
Sabrion_Consulting_Overview CPG Retail Apparel.pdf
 
Agile and Its Impact on Productivity
Agile and Its Impact on ProductivityAgile and Its Impact on Productivity
Agile and Its Impact on Productivity
 
How to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery PhaseHow to Get Started with GxP Processes in Office 365 - The Discovery Phase
How to Get Started with GxP Processes in Office 365 - The Discovery Phase
 
Benchmarking for hrd professionals
Benchmarking for hrd professionalsBenchmarking for hrd professionals
Benchmarking for hrd professionals
 
Project Planning & Feasibility Study
Project Planning & Feasibility StudyProject Planning & Feasibility Study
Project Planning & Feasibility Study
 
Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)
Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)
Gcwabaza, Lungelo - Conference Presentation (GREENOVATE)
 
Project_Integration_Managemen.pptx
Project_Integration_Managemen.pptxProject_Integration_Managemen.pptx
Project_Integration_Managemen.pptx
 
5 project prioritization
5 project prioritization5 project prioritization
5 project prioritization
 
Poor business analysis The Culprit of IT project Failure
Poor business analysis  The Culprit of IT project FailurePoor business analysis  The Culprit of IT project Failure
Poor business analysis The Culprit of IT project Failure
 
Business Process Management Introduction
Business Process Management IntroductionBusiness Process Management Introduction
Business Process Management Introduction
 
Webinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessmentsWebinar slide-deck-enterprise-architecture-capability-assessments
Webinar slide-deck-enterprise-architecture-capability-assessments
 
Sysdev
SysdevSysdev
Sysdev
 
The Six Month Data Center
The Six Month Data CenterThe Six Month Data Center
The Six Month Data Center
 
CompTIA Project+ Objectives
CompTIA Project+ ObjectivesCompTIA Project+ Objectives
CompTIA Project+ Objectives
 
Governing Agile Teams: Disciplined Strategies to Increase Agile Effectiveness
Governing Agile Teams: Disciplined Strategies to Increase Agile EffectivenessGoverning Agile Teams: Disciplined Strategies to Increase Agile Effectiveness
Governing Agile Teams: Disciplined Strategies to Increase Agile Effectiveness
 

Recently uploaded

Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeFree and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeCzechDreamin
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...FIDO Alliance
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераMark Opanasiuk
 
Syngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdfSyngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdfSyngulon
 
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties ReimaginedEasier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties Reimaginedpanagenda
 
What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024Stephanie Beckett
 
Enterprise Knowledge Graphs - Data Summit 2024
Enterprise Knowledge Graphs - Data Summit 2024Enterprise Knowledge Graphs - Data Summit 2024
Enterprise Knowledge Graphs - Data Summit 2024Enterprise Knowledge
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Julian Hyde
 
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxWSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxJennifer Lim
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyJohn Staveley
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...FIDO Alliance
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfFIDO Alliance
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...panagenda
 
AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101vincent683379
 
TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024Stephen Perrenod
 
Designing for Hardware Accessibility at Comcast
Designing for Hardware Accessibility at ComcastDesigning for Hardware Accessibility at Comcast
Designing for Hardware Accessibility at ComcastUXDXConf
 
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomSalesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomCzechDreamin
 
A Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System StrategyA Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System StrategyUXDXConf
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...CzechDreamin
 
WebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM PerformanceWebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM PerformanceSamy Fodil
 

Recently uploaded (20)

Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeFree and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджера
 
Syngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdfSyngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdf
 
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties ReimaginedEasier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
 
What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024
 
Enterprise Knowledge Graphs - Data Summit 2024
Enterprise Knowledge Graphs - Data Summit 2024Enterprise Knowledge Graphs - Data Summit 2024
Enterprise Knowledge Graphs - Data Summit 2024
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
 
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxWSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John Staveley
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
 
AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101
 
TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024
 
Designing for Hardware Accessibility at Comcast
Designing for Hardware Accessibility at ComcastDesigning for Hardware Accessibility at Comcast
Designing for Hardware Accessibility at Comcast
 
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomSalesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
 
A Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System StrategyA Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System Strategy
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 
WebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM PerformanceWebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM Performance
 

cobit

  • 1. A Flexible Method for COBIT 2019 Process Selection André Fernandes, Rafael Almeida, Miguel Mira da Silva
  • 2. Agenda • Introduction • Research Question • Theoretical Background • Proposal • Demonstration • Evaluation • Conclusion 2
  • 3. Introduction • From COBIT 5 to COBIT 2019 • Generic • Provide guidance • Apply to enterprises of all sizes 3
  • 4. Introduction • COBIT 2019 • Design Factors • Goals Cascade • The COBIT 5 Mechanism • One of the Design Factors 4
  • 5. Research Question • Addition or removal of Design Factors • Design Factor has its own set of evaluation parameters that are impossible to be modified, added or deleted • With the absence of customisation possibilities, this process cannot be adapted to the particular context of an organisation or improved based on the experiences and knowledge of expert • There is a lack of theoretical evidence that supports COBIT2019 method 5
  • 6. Theoretical Background • Contingency Factors: • Factors that, depending on organizations context, may influence the EGIT implementation. (Pereira & Mira da Silva, 2012) • These factors are called EGIT contingency factors 6
  • 7. Theoretical Background 7 Authors Identified Factors (Pereira and Mira da Silva 2012) • Culture • Structure • Size • Industry • Regional Differences • Maturity • Strategy • Ethical • Trust (Weil and Ross 2004) • Strategic and performance goals • Structure • Governance experience • Size and Diversity • Industry and Regional differences (Sambamurthy and Zmud 1999) • Overall Governance mode • Firm size • Diversification mode • Diversification breadth • Exploitation strategy for scope economies • Line IT knowledge
  • 8. Theoretical Background • Multi-Criteria Decision Making (MCDM) • Methods that support decision making in the presence of multiple criteria factors • Can be applied into diverse real-world decisions. 8
  • 9. Theoretical Background • Analytic Hierarchy Process (AHP) • Method for ranking decisions alternatives and selecting the best one • Works with multiple criteria • One of the most recognized methods in the literature (Velasquez & Hester, 2013) • Consistency Ratio 9
  • 10. Proposal • Universality: The method should be applicable to all Design Factors. • Customisable Criteria: The method should allow the organisation to determine the weight of each of the criteria. • Flexibility: The method should allow the addition or removal of criteria as intended by the organisation. • Automatic: Part of the process should be completely automated. The level of automation should be similar to that presented by the COBIT 2019 Toolkit. 10
  • 14. Demonstration • Choosing Egs • EGs Prioritisation 14 EG 03 EG 11 EG 03 1 1 EG 11 1 1
  • 15. Demonstration • Cascade To AGs • AGs Prioritisation 15 AG 01 AG 11 AG 01 1 1/3 AG 11 3 1 AG 01 AG 11 AG 01 1 1 AG 11 1 1
  • 17. Evaluation: First round of Interviews • 20 IT managers and COBIT specialists were invited • 14 accepted the invitation • Categorization of the candidates 1. Fundamental Awareness (basic knowledge) 2. Novice (limited experience) 3. Intermediate (practical application) 4. Advanced (applied theory) 5. Expert (recognized authority) 17
  • 18. Evaluation: Second round of Interviews 18
  • 19. Conclusion • Achievements • Management Objectives are prioritised • Flexible • Universal • Customisable • Automatic • Limitations • More empirical work • Human subjectivity • Greater geographical diversification • Lack of scientific studies 19
  • 20. A Flexible Method for COBIT 2019 Process Selection André Fernandes, Rafael Almeida, Miguel Mira da Silva

Editor's Notes

  1. Hello, Welcome to the presentation of our paper “A Flexible Method for COBIT 2019 Process Selection”
  2. The presentation will follow this Agenda.
  3. In 2018 COBIT 5 was updated to COBIT 2019 However, COBIT 2019, is still a generic framework that provides guidance to organizations of all sizes.
  4. One of the big differences between COBIT 5 and COBIT 2019 was the introduction of Design Factors. This changed the paradigm of COBIT process selection. Before, the Goals Cascade was the method to select the processes, now it is only one of the eleven different criteria to select the processes.
  5. When analysing this new way of selecting and prioritizing processes, we found out that this method doesn’t allow the addition or removal of Design Factors The DF has its own fix set of criteria that are impossible to be changed. This lack of customisation doesn’t allow the adaption to specific organization contexts When reading the COBIT manual we didn’t found any evidence or explanation that supports the method.
  6. In the Theoretical Background we will explore some concepts necessary to understand our propose method. In the Literature we can find the concept of Contingency factors, that are defined as Factors that, depending on organizations context, may influence the EGIT implementation. Since the contingency factors share a similar definition with the Design Factors of COBIT 2019, we can consider that they are based on the same principles.
  7. On the left table we can observe that multiple authors consider different sets of Factors that can influence the implementation of EGIT. However, in COBIT 2019 we are presented with a fixed and rigid set of Design Factors, which can compromise the EGIT implementation.
  8. In our research, we noticed that MCDM is suitable to solve this problem. MCDM are methods that support decision making considering multiple criteria. After analysing multiple MCDM algorithms, we concluded that AHP is the most suitable for this task.
  9. AHP is one of the most used MCDM algorithms and allows us to rank multiple alternatives considering multiple criteria.
  10. We propose a method that satisfies the following criteria. Universality: Customisable Criteria: Flexibility: Automatic: These four criteria solves the problems of the existing COBIT 2019 method. We create a prototype of this method in DF2 and now I’m going to explain how the AHP was setup in this specific DF.
  11. To apply the AHP in this problem we need to define what the criteria, sub-criteria and alternatives will be. The criteria are the different EGs The sub-criteria are the Ags And the alternatives are the MO, the processes that we want to select and prioritize.
  12. Now that we have the structure of AHP represented in the COBIT 2019 we need to establish the Saaty scale necessary to evaluate the criteria, sub-criteria and alternatives. We propose the following scale to perfom this evaluation. The table is read as follows, for example: If an EG has a Primary relationship with the first AG and a Secondary relationship with the second AG, then we evaluate the First AG with 3 and the Second with 1/3.
  13. In this figure we can see the all process of DF2. As we all can notice, the changes to the normal procedure are minimal. In the same way as the tool provided by COBIT 2019, the only interaction that the user needs to have is to evaluate the different EGs.
  14. Now we are going to demonstrate the method in detail. Lets consider the example where the user chooses the EG03 and EG11. Next, the user needs to evaluate them. Let’s say that both are equally important.
  15. From now on, the method will run by itself. The first step is to cascade to the AGs, as we can see in the Picture. In this step only AGs with a Primary relationship with the chosen EGs are selected. Next, the evaluation. In the left table both AGs have a Primary relationship with the EG03 so they are equally important In the right table, the AG01 has a Secondary relation and AG11 has a Primary, so AG11 is evaluated with a 3 .
  16. The method will apply the same rational to the Mos and then the result will be computed This table shows the result of this example.
  17. To evaluate our method multiple IT managers and COBIT specialists were invited for an interview, whom we categorized into 5 different cattegories according to their level of expertise.
  18. In the second interview, we filter out the candidates that are categorized as lower than 3. We conducted a semi structured interview where the experts perform a manual evaluation on a fictional scenario they created. Then they compared the result of their judgements anonymously with the result from our method and the COBIT 2019 method. In the end, 4 out of 5 experts preferred the result of our method.
  19. In conclusion our achievements can be summarized as follows: We proposed a method that is able to prioristed management objectives while being flexible universal customisable and automatic There are also some limitations in our research, for example More empirical work Human subjectivity Greater geographical diversification Lack of scientific studies