Combining ITIL With Cobit and 17799
Combining ITIL With Cobit and 17799
Combining ITIL With Cobit and 17799
Page 1 (7)
Scillani Information AB
Ekgatan 6, SE 230 40 BARA
Phone: +46 (0)40 54 31 31, Fax:+46 (0)40 54 31 30
E-mail: info@scillani.se, Internet: www.scillani.com
Page 2 (7)
When you look at these standards and framework at this level it is obvious that they serve
different needs within an organization. In some essence you can use one of them and gain
something another also covers. It could be the implementation of a formal change
management process, with clearly defined responsibilities and procedures. That would enable
controls when you need to change the IT environment and also the possibility to address
security issues that are related to the change.
ISO/IEC
17799:2000
ITIL
How can I
deliver
efficient
IT-services?
COBIT
Scillani Information AB
Ekgatan 6, SE 230 40 BARA
Phone: +46 (0)40 54 31 31, Fax:+46 (0)40 54 31 30
E-mail: info@scillani.se, Internet: www.scillani.com
Page 3 (7)
COBIT
Primary
COBIT
Secondary
Service Desk
Incident Management
Problem Management
Configuration
Management
Change Management
Release Management
Scillani Information AB
Ekgatan 6, SE 230 40 BARA
Phone: +46 (0)40 54 31 31, Fax:+46 (0)40 54 31 30
E-mail: info@scillani.se, Internet: www.scillani.com
Page 4 (7)
Service Delivery follows the same results as for Service Support. It is very interesting to find
that Service Level Agreement that is a key issue in ITIL is also an important issue in COBIT.
Figure 3 ITIL Service Delivery versus COBIT
ITIL
COBIT
Primary
COBIT
Secondary
Financial Management
for IT Services
Capacity Management
DS3 Manage
Performance and
Capacity
IT Service Continuity
Management
Availability Management
DS3 Manage
Performance and
Capacity
Scillani Information AB
Ekgatan 6, SE 230 40 BARA
Phone: +46 (0)40 54 31 31, Fax:+46 (0)40 54 31 30
E-mail: info@scillani.se, Internet: www.scillani.com
Page 5 (7)
ISO/IEC 17799:2000
Primary
Service Desk
ISO/IEC 17799:2000
Secondary
6.3.2 Reporting security weaknesses
Incident Management
8.1.3 Incident
management procedures
Problem Management
Configuration
Management
Change Management
Release Management
For ITIL Service Delivery we face another problem with the terminology. In ISO 17799
security is characterized as the preservation of Confidentiality, Integrity and Availability. In
ITIL Availability is about quality aspects such as reliability, maintainability, serviceability &
resilience. Another important finding in the benchmark is that financial issues are not handled
at all in ISO 17799, instead it is about risk management meaning you mitigate risks to avoid
costs. For ITIL it is instead about financing and cost allocation for the delivery of IT-services.
Scillani Information AB
Ekgatan 6, SE 230 40 BARA
Phone: +46 (0)40 54 31 31, Fax:+46 (0)40 54 31 30
E-mail: info@scillani.se, Internet: www.scillani.com
Page 6 (7)
ISO/IEC 17799:2000
Primary
ISO/IEC 17799:2000
Secondary
4.2.2 Security requirements in third party
contracts
Financial Management
for IT Services
Capacity Management
IT Service Continuity
Management
11 Business continuity
management
Availability Management
Conclusion
In every organization today we must deliver IT services in a cost efficient manner, mitigating
security risks and comply with legal requirements. The equation is difficult to handle and in
some cases it seems like an impossible mission. To be able to survive in this environment a
combination of ITIL, COBIT and ISO 17799 can be valuable for you. You may use ITIL to
define processes, use COBIT for metrics, benchmarks and audits and use ISO 17799 to
address security issues to mitigate risks.
Figure 6 Key issues to be combined
ITIL
COBIT
ISO/IEC 17799:2000
Concept/Process
Information Security
Activities
Cost/Benefit
Benchmarking (CMM)
Controls
Audit
Scillani Information AB
Ekgatan 6, SE 230 40 BARA
Phone: +46 (0)40 54 31 31, Fax:+46 (0)40 54 31 30
E-mail: info@scillani.se, Internet: www.scillani.com
Page 7 (7)
Another recommendation that is repeated in any article, book or presentation we have come
across on this issue is that you shall not go for complete implementation of ITIL, COBIT and
ISO 17799 at the same time. A big bang implementation is bound to fail. The difficult task is
instead to choose issues that are important for you, from a cost/benefit, risk mitigation or
regulatory compliance perspective.
John Wallhoff, CISA, CISM, CISSP
is the founder and Managing Director of Scillani Information AB. Prior to this position, he
worked both as an IT-auditor, IS-consultant and with Security management practices within
enterprises like Ernst & Young and AddTrust. He has over thirteen years experience in the IT
field as an IT/IS consultant and in IS audit.
References
ITIL Service Delivery, OCG
ITIL Service Support, OCG
COBIT 3rd Edition Management Guidelines, ITGovernance Institute
COBIT 3rd Edition Control Objectives, ITGovernance Institute
COBIT 3rd Edition Audit Guidelines, ITGovernance Institute
Information security management Part 1 Code of practice for information security
management
ITIL Security Management, OCG
COBIT Security Baseline, ITGovernance Institute
COBIT mapping - Overview of International IT Guidance, ITGovernance Institute
BS7799 Information security management Part 2 Specification for information
security management systems
Whitepaper Combining ITIL with Cobit och 17799, By John Walllhoff, Scillani Information
AB (2004), www.scillani.com
Scillani Information AB
Ekgatan 6, SE 230 40 BARA
Phone: +46 (0)40 54 31 31, Fax:+46 (0)40 54 31 30
E-mail: info@scillani.se, Internet: www.scillani.com