|
CobiT and the Sarbanes-Oxley Act: The SOX Guide for SAP Operations
This pocket-sized guide is your roadmap to implementing the relevant CobiT Controls using SAP tools. Starting with the business/IT requirements dictated by the Sarbanes-Oxley Act, the authors explain the relevant controls of the CobiT framework and show you exactly which tools and services SAP provides for the smooth implementation of these controls
within your IT operations.
Foreword ... 9
Acknowledgements ... 11
1. Introduction ... 13
... 1.1 Overview of CobiT ... 13
... 1.2 COSO ... 18
... 1.3 Overview of the Sarbanes-Oxley Act ... 19
... 1.4 Connection Between CobiT and Other Standards of Best Practices ... 23
... 1.5 SAP IT Service & Application Management ... 25
2. Central SAP Tools ... 29
... 2.1 SAP Solutions for Governance, Risk, and Compliance ... 29
... 2.2 SAP Solution Manager: The SAP Platform for Application Management and Cooperation ... 35
3. CobiT Domain: Plan and Organize ... 41
... 3.1 PO1: Defining a Strategic IT Plan ... 42
... 3.2 PO2: Defining the Information Architecture ... 45
... 3.3 PO3: Determining the Technological Direction ... 52
... 3.4 PO4: Defining the IT Processes, Organization, and Relationships ... 53
... 3.5 PO5: Managing the IT Investment ... 61
... 3.6 PO6: Communicating Management Aims and Direction ... 62
... 3.7 PO7: Managing IT Human Resources ... 64
... 3.8 PO8: Managing Quality ... 68
... 3.9 PO9: Assessing and Managing IT Risks ... 71
... 3.10 PO10: Managing Projects ... 75
4. CobiT Domain: Acquire and Implement ... 79
... 4.1 AI1: Identifying Automated Solutions ... 80
... 4.2 AI2: Acquiring and Maintaining Application Software ... 83
... 4.3 AI3: Acquiring and Maintaining Technology Infrastructure ... 90
... 4.4 AI4: Enabling Operation and Use ... 97
... 4.5 AI5: Procuring IT Resources ... 101
... 4.6 AI6: Managing Changes ... 102
... 4.7 AI7: Installing and Accrediting Solutions and Changes ... 104
5. CobiT Domain: Deliver and Support ... 109
... 5.1 DS1: Defining and Managing Service Levels ... 111
... 5.2 DS2: Managing Third-Party Services ... 118
... 5.3 DS3: Managing Performance and Capacity ... 123
... 5.4 DS4: Ensuring Continuous Operation ... 125
... 5.5 DS5: Ensuring Systems Security ... 127
... 5.6 DS6: Identifying and Allocating Costs ... 135
... 5.7 DS7: Educating and Training Users ... 136
... 5.8 DS8: Managing the Service Desk and Incidents ... 138
... 5.9 DS9: Managing the Configuration ... 141
... 5.10 DS10: Managing Problems ... 143
... 5.11 DS11: Managing Data ... 146
... 5.12 DS12: Managing the Physical Environment ... 149
... 5.13 DS13: Managing Operations ... 150
6. CobiT Domain: Monitor and Evaluate ... 155
... 6.1 ME1: Monitoring and Evaluating IT Performance ... 156
... 6.2 ME2: Monitoring and Evaluating Internal Controls ... 159
... 6.3 ME3: Ensuring Compliance with Specifications ... 163
... 6.4 ME4: Ensuring IT Governance ... 164
7. Relevance of CobiT and COSO for Fulfilling SOX ... 167
8. Outlook ... 175
A. CobiT Controls ... 179
B. Literature ...191 Index ... 193
|