"The use of COBIT 4.1 (or any other IT
Governance framework) simply creates a great deal of work for an organisation
and yet may provide little benefit"
This statement is saying that ultimately IT Governance frameworks
are not necessary for organisations to adopt and that there are no benefits in
these systems. I believe it is important for any organisation, big or small, to
have some type of IT Governance system in place to ensure that fraudulent activity
does not occur.
COBIT 4.1 was designed as an educational resource for CIO’s,
Management and all control professionals and provides opportunity for
organisations to assess their own IT Governance methods and improve in areas
which are lacking. IT Governance systems are used to support business goals,
optimise business investment in IT and appropriately manage IT-related risks
and opportunities. This being said, the outcome that is gained by using an IT
Governance framework far outweigh implementation throughout the workplace,
especially when referring to medium and large organisations which have higher
risk opportunities than smaller organisations.
Benefits of IT Governance:
•
Better alignment, based on a business focus
•
A view, understandable to management, of what IT does
•
Clear ownership and responsibilities, based on
process orientation
•
General acceptability with third parties and regulators
•
Shared understanding amongst all stakeholders, based on a common language
•
Fulfilment of the COSO Requirements for the IT control environment
There are various types of Governance Frameworks which vary
depending on risk management approach versus a control framework approach.
Various Governance Frameworks:
Source: Gartner
