3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

  • Upload
    sanny

  • View
    219

  • Download
    3

Embed Size (px)

Citation preview

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    1/97

    Instructions

    1. Use the Process results tab (example in appendix A of the guide) to summarize your results of the

    The Self-assessment Guide is provided as a stand-alone guide,which caless rigorous assessment of the capability of their I processes. his may be a precursor to underta!iassessment. The approach is based on the COBIT PAMused in the $%&I ' Assessment Programreuirements in support of the self assessment nor does it require use of the COBIT PAM; su*cifull self#assessment template has been pro"ided that simpli,es the process without the need to refer

    $%&I Assessment Programme.

    1. It is recommended that the assessment be underta!en by a small team or re"iewed by a team of Ialthough independent assessors are not reuired for this.

    . If a more rigoruous assessment is reuired and-or e"identiary reuirements to be produced then utemplates at /. and 0. of the tool!it

    /. ou are reuired to start at le"el 1 because that is where the spec,c uestions are as!ed about thachie"ed.

    0. At 2e"el 1 3or each process be assessed as! if the process is achie"eing its outcomes answer yescomments to support your conclusion.

    '. 3or 2e"el 1 you can 5A6 each of the outcomes but the assessment approach reuires an o"erall aattribute le"el PA1.1

    7. At higher le"els you are no longer looking at specic process outcoesbut at o"erall generito '.

    8. o PA99 a particular le"el the process must be rated 2argely or 3ully to mo"e onto the next le"el alexample if PA.1 is 2argely and PA. 3ully you are deemed to be at 2e"el but the o"erall 2e"el rassess at higher le"els.

    8. Use this process as a 'pre-cursor' to a more detailed assessment and not as the deniti

    processes.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    2/97

    "#$%&SS SS&SS(&)T #&SU*TS

    "rocess I+ "rocess )ame *evel *evel *evel *evel / *evel 0 *evel 1

    6:+;1 2 *

    6:+; 6nsure &ene,ts :eli"ery6:+;/ 6nsure 5is! %ptimisation

    6:+;0 6nsure 5esource %ptimisation

    6:+;' 6nsure 9ta!eholder ransparency

    Align, Plan and Organise

    AP%;1 +anage the I +anagement 3ramewor!

    AP%; +anage 9trategy

    AP%;/ +anage 6nterprise Architecture

    AP%;0 +anage Inno"ation

    AP%;' +anage Portfolio

    AP%;7 +anage &udget and $osts

    AP%;8 +anage +anage 9er"ice Agreements

    AP%1; +anage 9uppliers

    AP%11 +anage ?uality

    AP%1 +anage 5is!

    AP%1/ +anage 9ecurity

    Build, Acquire and Implement

    &AI;1 +anage Programmes and Pro@ects

    &AI; +anage 5euirements :e,nition *

    &AI;/ +anage 9olutions Identi,cation and &uild

    To 3eassessed

    Processes for Governance of Enterprise IT -Evaluate, Direct and Monitor

    6nsure o"ernance 3ramewor! 9etting and+aintenance

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    3/97

    &AI;0 +anage A"ailability and $apacity

    &AI;' +anage %rganisational $hange 6nablement

    &AI;7 +anage $hanges

    &AI;8 +anage $hange Acceptance and ransitioning

    &AI;= +anage Bnowledge

    &AI;> +anage Assets

    &AI1; +anage $on,guration

    Deliver, ervice and upport

    :99;1 +anage %perations

    :99; +anage 9er"ice 5euests and Incidents:99;/ +anage Problems

    :99;0 +anage $ontinuity

    :99;' +anage 9ecurity 9er"ices

    :99;7 +anage &usiness Process $ontrols

    Monitor, Evaluate and Assess+6A;1

    +6A;

    +6A;/

    +onitor 6"aluate and Assess Performance and$onformance

    +onitor 6"aluate and Assess the 9ystem of Internal$ontrol

    +onitor 6"aluate and Assess $ompliance with6xternal 5euirements

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    4/97

    )- ;C#1'C "- 1'C#';C *- ';C#='C 2- 814-4

    ) 5 )ot chieved" 5 "artiall! chieved* 5 *argel! chieved2- 2ull! chieved

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    5/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    6/97

    Self-assessmentTemplate 6

    Process Dame 2e"el ;

    &AI;1

    9I (anage

    "urpose

    5ating by$riteria

    $apability2e"el Achie"ed

    ssess ;hether the follo;ing

    outcomes are achieved.

    2e"el ;Incomplete

    The process is not implemented,or fails to achieve its processpurpose.

    *evel "erformed

    " . The implemented processachieves its process purpose.

    )- ;C#1'C "- 1'C#';C *- ';C#=

    )E Dot Achie"ed"E Partially Achie"ed* E 2argely Achie"ed2# 3ully Achie"ed

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    7/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    8/97

    *evel (anaged

    " . "erformance (anagement- measure of the e7tent to;hich the performance of theprocess is managed.

    " . =or> "roduct (anagement

    - measure of the e7tent to;hich the ;or> productsproduced 3! the process areappropriatel! managed. The

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    9/97

    ;or pro ucts or outputs romthe process are dened andcontrolled.

    *evel /&sta3lished " /. "rocess +enition - measure of the e7tent to ;hich astandard process is maintained tosupport the deplo!ment of thedened process.

    " /. "rocess +eplo!ment - measure of the e7tent to ;hichthe standard process ise?ectivel! deplo!ed as a denedprocess to achieve its processoutcomes.

    *evel 0"redicta3le

    " 0. "rocess (easurement - measure of the e7tent to ;hichmeasurement results are used toensure that performance of theprocess supports theachievement of relevant processperformance o3:ectives in support

    of dened 3usiness goals.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    10/97

    " 0. "rocess %ontrol - measure of the e7tent to ;hichthe process is @uantitativel!managed to produce a processthat is sta3le, capa3le andpredicta3le ;ithin dened limits.

    *evel 1$ptimiAing.

    " 1. "rocess innovation - measure of the e7tent to ;hichchanges to the process areidentied from anal!sis ofcommon causes of variation inperformance, and frominvestigations of innovativeapproaches to the denition anddeplo!ment of the process.

    " 1. "rocess optimisation - measure of the e7tent to ;hichchanges to the denition,management and performance ofthe process result in e?ectiveimpact that achieves the relevantprocess improvement o3:ectives.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    11/97

    ppendi7 + of the Self-assessment Guide

    2e"el 1 2e"el

    PA 1.1 PA .1

    "rogrammes and "ro:ects

    %riteria

    he following process outcomes are being achie"edF

    5ealise business bene,ts and reduce the ris! of unexpected delays costs and "maximising their contribution to the in"estment and ser"ices portfolio.

    %riteria re

    (et BC)

    At this le"el there is little or no e"idence of any achie"ement ofthe process purpose.

    'C 2- ='C#1;;C

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    12/97

    &AI;1#%1 5ele"ant sta!eholders are engaged in theprogrammes and pro@ects.

    &AI;1#% he scope and outcomes of programmes and pro@ectsare "iable and aligned with ob@ecti"es.

    &AI;1#%/ Programme and pro@ect plans are li!ely to achie"e theexpected outcomes.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    13/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    &AI;1#%0 he programme and pro@ect acti"ities are executedaccording to the plans.

    &AI;1#%' here are su*cient programme and pro@ect resources

    to perform acti"ities according to the plans.

    &AI;1#%7 he programme and pro@ect expected bene,ts areachie"ed and accepted.

    a) %b@ecti"es for the performance of the process areidenti,ed.

    b) Performance of the process is planned and monitored.

    c) Performance of the process is ad@usted to meet plans.

    d) 5esponsibilities and authorities for performing theprocess are de,ned assigned and communicated.

    e) Resources and information necessary for performingthe process are identi,ed made a"ailable allocated andused.

    f) Interfaces between the in"ol"ed parties aremanaged to ensure both eHecti"e communication andalso clear assignment of responsibility.

    a) Reuirements for the wor! products of the process arede,ned.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    14/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    b) Reuirements for documentation and control of thewor! products are de,ned.

    c) or! products are appropriately identi,eddocumented and controlled.

    d) Wor! products are re"iewed in accordance with plannedarrangements and ad@usted as necessary to meetreuirements.

    a) Astandard process including appropriate tailoringguidelines is de,ned that describes the fundamentalelements that must be incorporated into a de,ned process.

    b) The seuence and interaction of the standard processwith other processes is determined.

    c) 5euired competencies and roles for performing aprocess are identi,ed as part of the standard process.

    d) Reuired infrastructure and wor! en"ironment forperforming a process are identi,ed as part of thestandard process.

    e) Suitable methods for monitoring the eHecti"eness andsuitability of the process are determined.

    a) Ade,ned process is deployed based upon anappropriately selected and-or tailored standard process.

    b) Reuired roles responsibilities and authorities forperforming the de,ned process are assigned and

    communicated.

    c) Personnel performing the de,ned process arecompetent on the basis of appropriate education trainingand experience.

    d) Reuired resources and information necessary forperforming the de,ned process are made a"ailableallocated and used.

    e) Reuired infrastructure and wor! en"ironment forperforming the de,ned process are made a"ailablemanaged and maintained.

    f) Appropriate data are collected and analysed as abasis for understanding the beha"iour of and todemonstrate the suitability and eHecti"eness of theprocess and to e"aluate where continuousimpro"ement of the process can be made.

    a) Process information needs in support of rele"antde,ned business goals are established.

    b) Process measurement ob@ecti"es are deri"ed fromprocess information needs.

    c) Quantitati"e ob@ecti"es for process performance insupport of rele"ant business goals are established.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    15/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    d) Measures and freuency of measurement are identi,edand de,ned in line with process measurement ob@ecti"esand uantitati"e ob@ecti"es for process performance.

    e) Results of measurement are collected analysed andreported in order to monitor the extent to which theuantitati"e ob@ecti"es for process performance are met.

    f) +easurement results are used to characterise processperformance.

    a) Analysis and control techniues are determined andapplied where applicable.

    b) Control limits of "ariation are established for normalprocess performance.

    c) Measurement data are analysed for special causes of"ariation.

    d) Correcti"e actions are ta!en to address special causes of"ariation.

    e) $ontrol limits are re#established (as necessary) followingcorrecti"e action.

    a) Pprocess impro"ement ob@ecti"es for the process arede,ned that support the rele"ant business goals.

    b) Appropriate data are analysed to identify commoncauses of "ariations in process performance.

    c) Appropriate data are analysed to identify opportunitiesfor best practice and inno"ation.

    d) Impro"ement opportunities deri"ed from newtechnologies and process concepts are identi,ed.

    e) An implementation strategy is established to achie"e theprocess impro"ement ob@ecti"es.

    a) Impact of all proposed changes is assessed against theob@ecti"es of the de,ned process and standard process.

    b) Implementation of all agreed changes is managed toensure that any disruption to the process performance is

    understood and acted upon.

    c) Based on actual performance, eHecti"eness of process change ise"aluated against the de,ned product reuirements andprocess ob@ecti"es to determine whether results are due tocommon or special causes.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    16/97

    PA .

    Duestion %omment

    $verall rating for the process

    lue erosion by impro"ing communications to and in"ol"ement of business and end users ensuring the "

    :oes the $ompany ha"e policies andprcoedures or existing processes for Iprogramme and pro@ect management(planning execution monitoring)J

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    17/97

    # :oes the sta!eholder in"ol"ed in wor! anddecision ma!ing for each of theprogrammes and pro@ectsJ

    # Apa!ah setiap pemang!u !epentingandilibat!an dalam setiap penger@aan danpengambilan !eputusan untu! setiapprogram dan proye! yang dila!u!anJ

    # ho is the sta!eholder which directlydri"es in e"ery crucial pro@ect at PAsuransi +aipar! IndonesiaJ# 9iapa pemang!u !epentingan yang secraalangsung men@adi penggera! pada setiapproye! !rusial pada P Asuransi +aipar!IndonesiaJ

    # :oes the pro@ect is done and designed toha"e a speci,c scope and ha"e clearob@ecti"es and resultsJ# Apa!ah setiap proye! yang dila!u!an dandirancang untu! mempunyai ruang ling!upyang spesi,! dan memili!i tu@uan dan hasilyang @elasJ

    # :oes the information technology pro@ectsunderta!en are designed to achie"e adesired standard in helping achie"ebusiness goals of the companyJ# apa!ah proye! te!nologi informasi yangdi!er@a!an dirancang untu! mencapai suatustandar yang diingin!an dalam membantumencapai tu@uan bisnis perusahaanJ

    # :oes the infrastructure of informationtechnology designed to accept the reuiredstandardsJ# apa!ah infrastru!tur te!nologi informasidirancang untu! bisa menerima standaryang diingin!an tersebutJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    18/97

    # :oes in e"ery pro@ects schedules and

    milestones are clear de,nedJ# Apa!ah dalam setiap pro@e! @adwal danpencapaian ditetap!an secara @elasJ

    # :oes there is a second priority and thethird priority in each and e"ery prioritypro@ect has a clear priod of completionJ# apa!ah terdapat prioritas !edua danprioritas !etiga dalam setiap proye! dansetiap prioritas tersebut memili!i @ang!awa!tu penyelesaian yang @elasJ

    # :oes the company conducts matureallocations of programs and resource in anypro@ect planningJ# apa!ah perusahaan mela!u!an alo!asiprogram dan sumber daya yang matangdalam setiap perencanaan proye!J

    # :oes the entire pro@ect and informationtechnology program is designed to supportbusiness operations and the companyKs

    goalsJ

    # apa!ah seluruh proye! dan programte!nologi informasi dirancang untu! dapatmendu!ung operasional bisnis dan tu@uanperusahaanJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    19/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    20/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    21/97

    2e"el / 2e"el 0

    PA /.1 PA /. PA 0.1 PA 0.

    alue and uality of pro@ect deli"erables and

    Dot achie"ed(;#1'C)

    Partially

    Achie"ed(1'C #';C)

    2argely

    Achie"ed(';C # ='C)

    3ully Achie"ed(='#1;;C)

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    22/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    23/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    24/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    25/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    26/97

    Self-assessmentTemplate 6

    Process Dame 2e"el ;

    &AI;

    9I

    "urpose

    5ating by$riteria

    $apability2e"el Achie"ed

    ssess ;hether the follo;ing

    outcomes are achieved.

    2e"el ;Incomplete

    The process is not implemented,or fails to achieve its processpurpose.

    *evel "erformed

    " . The implemented processachieves its process purpose.

    )- ;C#1'C "- 1'C#';C *- ';C#=

    )E Dot Achie"ed"E Partially Achie"ed* E 2argely Achie"ed2# 3ully Achie"ed

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    27/97

    *evel (anaged

    " . "erformance (anagement- measure of the e7tent to;hich the performance of theprocess is managed.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    28/97

    " . =or> "roduct (anagement- measure of the e7tent to;hich the ;or> productsproduced 3! the process are

    appropriatel! managed. The;or> products 6or outputs fromthe process are dened andcontrolled.

    *evel /&sta3lished

    " /. "rocess +enition - measure of the e7tent to ;hich astandard process is maintained tosupport the deplo!ment of thedened process.

    " /. "rocess +eplo!ment - measure of the e7tent to ;hichthe standard process ise?ectivel! deplo!ed as a denedprocess to achieve its processoutcomes.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    29/97

    *evel 0"redicta3le

    " 0. "rocess (easurement - measure of the e7tent to ;hichmeasurement results are used toensure that performance of theprocess supports theachievement of relevant processperformance o3:ectives in supportof dened 3usiness goals.

    " 0. "rocess %ontrol - measure of the e7tent to ;hichthe process is @uantitativel!managed to produce a processthat is sta3le, capa3le andpredicta3le ;ithin dened limits.

    *evel 1$ptimiAing. " 1. "rocess innovation - measure of the e7tent to ;hichchanges to the process areidentied from anal!sis ofcommon causes of variation inperformance, and frominvestigations of innovativeapproaches to the denition anddeplo!ment of the process.

    " 1. "rocess optimisation - measure of the e7tent to ;hichchanges to the denition,management and performance ofthe process result in e?ectiveimpact that achieves the relevantprocess improvement o3:ectives.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    30/97

    ppendi7 + of the Self-assessment Guide

    2e"el 1 2e"el

    PA 1.1 PA .1

    ene #e@uirements

    $reate feasible optimal solutions that meet enterprise needs while minimising ri

    %riteria

    he following process outcomes are being achie"edF

    %riteria re

    (et BC)

    At this le"el there is little or no e"idence of any achie"ement ofthe process purpose.

    &AI;#%1 &usiness functional and technical reuirements reLect

    enterprise needs and expectations.

    'C 2- ='C#1;;C

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    31/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    32/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    f) Interfaces between the in"ol"ed parties aremanaged to ensure both eHecti"e communication andalso clear assignment of responsibility.

    a) Reuirements for the wor! products of the process are

    de,ned.

    b) Reuirements for documentation and control of thewor! products are de,ned.

    c) or! products are appropriately identi,eddocumented and controlled.

    d) Wor! products are re"iewed in accordance with plannedarrangements and ad@usted as necessary to meetreuirements.

    a) Astandard process including appropriate tailoringguidelines is de,ned that describes the fundamentalelements that must be incorporated into a de,ned process.

    b) The seuence and interaction of the standard processwith other processes is determined.

    c) 5euired competencies and roles for performing aprocess are identi,ed as part of the standard process.

    d) Reuired infrastructure and wor! en"ironment forperforming a process are identi,ed as part of thestandard process.

    e) Suitable methods for monitoring the eHecti"eness and

    suitability of the process are determined.

    a) Ade,ned process is deployed based upon anappropriately selected and-or tailored standard process.

    b) Reuired roles responsibilities and authorities forperforming the de,ned process are assigned andcommunicated.

    c) Personnel performing the de,ned process arecompetent on the basis of appropriate education training

    and experience.

    d) Reuired resources and information necessary forperforming the de,ned process are made a"ailableallocated and used.

    e) Reuired infrastructure and wor! en"ironment forperforming the de,ned process are made a"ailablemanaged and maintained.

    f) Appropriate data are collected and analysed as abasis for understanding the beha"iour of and todemonstrate the suitability and eHecti"eness of theprocess and to e"aluate where continuous

    impro"ement of the process can be made.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    33/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    a) Process information needs in support of rele"antde,ned business goals are established.

    b) Process measurement ob@ecti"es are deri"ed fromprocess information needs.

    c) Quantitati"e ob@ecti"es for process performance in

    support of rele"ant business goals are established.

    d) Measures and freuency of measurement are identi,edand de,ned in line with process measurement ob@ecti"esand uantitati"e ob@ecti"es for process performance.

    e) Results of measurement are collected analysed andreported in order to monitor the extent to which theuantitati"e ob@ecti"es for process performance are met.

    f) +easurement results are used to characterise processperformance.

    a) Analysis and control techniues are determined andapplied where applicable.

    b) Control limits of "ariation are established for normalprocess performance.

    c) Measurement data are analysed for special causes of"ariation.

    d) Correcti"e actions are ta!en to address special causes of"ariation.

    e) $ontrol limits are re#established (as necessary) followingcorrecti"e action.

    a) Pprocess impro"ement ob@ecti"es for the process arede,ned that support the rele"ant business goals.

    b) Appropriate data are analysed to identify commoncauses of "ariations in process performance.

    c) Appropriate data are analysed to identify opportunitiesfor best practice and inno"ation.

    d) Impro"ement opportunities deri"ed from newtechnologies and process concepts are identi,ed.

    e) An implementation strategy is established to achie"e theprocess impro"ement ob@ecti"es.

    a) Impact of all proposed changes is assessed against theob@ecti"es of the de,ned process and standard process.

    b) Implementation of all agreed changes is managed toensure that any disruption to the process performance isunderstood and acted upon.

    c) Based on actual performance, eHecti"eness of process change is

    e"aluated against the de,ned product reuirements andprocess ob@ecti"es to determine whether results are due tocommon or special causes.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    34/97

    PA .

    s!.

    Duestion %omment

    $verall rating for the process

    :oes the $ompany ha"e documentationof for the de,nition of businessfunctional and technical reuirementsand feasibility study for I pro@ectsJ

    # :oes the pro@ect proposals andinformation technology programoutlining in detail the functions ofbusiness and technical needs andexpectations of the companyJ# apa!ah proposal proye! dan programte!nologi informasi men@abar!an denganrinci fungsi bisnis dan te!nis !ebutuhandan harapan perusahaanJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    35/97

    # :oes all pro@ects and programsdesigned information technology hasful,lled business functional technicaland compliance reuirement at thecompanyJ# apa!ah seluruh proye! dan programte!nologi informasi yang dirancang telahmemenuhi fungsi bisnis te!nis dan!ebutuhan !epatuhan di Perusahaan J

    # :oes all pro@ects and programsdesigned information technology hasful,lled business functional technical

    and compliance reuirement at the%MB-&IJ# apa!ah seluruh proye! dan programte!nologi informasi yang dirancang telahmemenuhi fungsi bisnis te!nis dan!ebutuhan !epatuhan di %MB-&I J

    # :oes the company has a ris!management documentation for eachris! will occur at the companyJ

    # apa!ah perusahaan memili!ido!umentasi mana@emen resi!o untu!setiap resi!o yang a!an ter@adi diperusahaanJ

    # :oes the entire pro@ect proposal andinformation technology program describethe budget and the results to beobtainedJ# apa!ah seluruh proposal proye! danprogram te!nologi informasi

    men@abar!an mengenai anggaran biayayang dibutuh!an dan hasil yang a!andidapat!anJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    36/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    37/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    38/97

    2e"el / 2e"el 0

    PA /.1 PA /. PA 0.1 PA 0.

    Dot achie"ed(;#1'C)

    Partially

    Achie"ed(1'C #';C)

    2argely

    Achie"ed(';C # ='C)

    3ully Achie"ed(='#1;;C)

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    39/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    40/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    41/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    42/97

    Self-assessmentTemplate 6

    Process Dame 2e"el ;

    &AI;/

    9I/ Identif

    "urpose

    5ating by$riteria

    $apability2e"el Achie"ed

    ssess ;hether the follo;ing

    outcomes are achieved.

    2e"el ;Incomplete

    The process is not implemented,or fails to achieve its processpurpose.

    *evel "erformed

    " . The implemented processachieves its process purpose.

    )- ;C#1'C "- 1'C#';C *- ';C#=

    )E Dot Achie"ed"E Partially Achie"ed* E 2argely Achie"ed2# 3ully Achie"ed

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    43/97

    *evel (anaged

    " . "erformance (anagement- measure of the e7tent to;hich the performance of theprocess is managed.

    " . =or> "roduct (anagement- measure of the e7tent to;hich the ;or> products

    produced 3! the process areappropriatel! managed. The;or> products 6or outputs fromthe process are dened and

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    44/97

    .

    *evel /

    &sta3lished

    " /. "rocess +enition -

    measure of the e7tent to ;hich astandard process is maintained tosupport the deplo!ment of thedened process.

    " /. "rocess +eplo!ment - measure of the e7tent to ;hichthe standard process ise?ectivel! deplo!ed as a denedprocess to achieve its processoutcomes.

    *evel 0"redicta3le

    " 0. "rocess (easurement - measure of the e7tent to ;hich

    measurement results are used toensure that performance of theprocess supports theachievement of relevant rocess

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    45/97

    performance o3:ectives in supportof dened 3usiness goals.

    " 0. "rocess %ontrol - measure of the e7tent to ;hichthe process is @uantitativel!managed to produce a process

    that is sta3le, capa3le andpredicta3le ;ithin dened limits.

    *evel 1$ptimiAing.

    " 1. "rocess innovation - measure of the e7tent to ;hichchanges to the process are

    identied from anal!sis ofcommon causes of variation inperformance, and frominvestigations of innovativeapproaches to the denition anddeplo!ment of the process.

    " 1. "rocess optimisation - measure of the e7tent to ;hichchanges to the denition,management and performance ofthe process result in e?ectiveimpact that achieves the relevantprocess improvement o3:ectives.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    46/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    47/97

    ppendi7 + of the Self-assessment Guide

    2e"el 1 2e"el

    PA 1.1 PA .1

    and 9uild Solutions

    6stablish timely and cost#eHecti"e solutions capable of supporting enter

    %riteria

    he following process outcomes are being achie"edF

    %riteria re

    (et BC)

    At this le"el there is little or no e"idence of anyachie"ement of the process purpose.

    &AI;/#%1 he solution design including rele"antcomponents meets enterprise needs aligns withstandards and addresses all identi,ed ris!.

    'C 2- ='C#1;;C

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    48/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    &AI;/#% he solution conforms to the design is inaccordance with organisational standards and hasappropriate control security and auditability.

    &AI;/#%/ he solution is of acceptable uality and hasbeen successfully tested.

    &AI;/#%0 Appro"ed changes to reuirements arecorrectly incorporated into the solution.

    &AI;/#%' +aintenance acti"ities successfully addressbusiness and technological needs.

    a) %b@ecti"es for the performance of the processare identi,ed.

    b) Performance of the process is planned andmonitored.

    c) Performance of the process is ad@usted to meetplans.

    d) 5esponsibilities and authorities for performingthe process are de,ned assigned andcommunicated.

    e) Resources and information necessary forperforming the process are identi,ed madea"ailable allocated and used.

    f) Interfaces between the in"ol"ed parties aremanaged to ensure both eHecti"ecommunication and also clear assignment ofresponsibility.

    a) Reuirements for the wor! products of theprocess are de,ned.

    b) Reuirements for documentation and control ofthe wor! products are de,ned.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    49/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    c) or! products are appropriately identi,eddocumented and controlled.

    d) Wor! products are re"iewed in accordance withplanned arrangements and ad@usted as necessary tomeet reuirements.

    a) Astandard process including appropriatetailoring guidelines is de,ned that describes thefundamental elements that must be incorporatedinto a de,ned process.

    b) The seuence and interaction of the standardprocess with other processes is determined.

    c) 5euired competencies and roles forperforming a process are identi,ed as part of thestandard process.

    d) Reuired infrastructure and wor!en"ironment for performing a process areidenti,ed as part of the standard process.

    e) Suitable methods for monitoring theeHecti"eness and suitability of the process aredetermined.

    a) Ade,ned process is deployed based upon anappropriately selected and-or tailored standardprocess.

    b) Reuired roles responsibilities andauthorities for performing the de,ned processare assigned and communicated.

    c) Personnel performing the de,ned process arecompetent on the basis of appropriate educationtraining and experience.

    d) Reuired resources and informationnecessary for performing the de,ned process aremade a"ailable allocated and used.

    e) Reuired infrastructure and wor!

    en"ironment for performing the de,ned processare made a"ailable managed and maintained.

    f) Appropriate data are collected and analysedas a basis for understanding the beha"iour ofand to demonstrate the suitability andeHecti"eness of the process and to e"aluatewhere continuous impro"ement of the process canbe made.

    a) Process information needs in support of rele"antde,ned business goals are established.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    50/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    b) Process measurement ob@ecti"es are deri"edfrom process information needs.

    c) Quantitati"e ob@ecti"es for process performancein support of rele"ant business goals areestablished.

    d) Measures and freuency of measurement areidenti,ed and de,ned in line with processmeasurement ob@ecti"es and uantitati"e ob@ecti"esfor process performance.

    e) Results of measurement are collected analysedand reported in order to monitor the extent to whichthe uantitati"e ob@ecti"es for process performanceare met.

    f) +easurement results are used to characteriseprocess performance.

    a) Analysis and control techniues are determinedand applied where applicable.

    b) Control limits of "ariation are established fornormal process performance.

    c) Measurement data are analysed for specialcauses of "ariation.

    d) Correcti"e actions are ta!en to address specialcauses of "ariation.

    e) $ontrol limits are re#established (as necessary)following correcti"e action.

    a) Pprocess impro"ement ob@ecti"es for the processare de,ned that support the rele"ant business goals.

    b) Appropriate data are analysed to identify commoncauses of "ariations in process performance.

    c) Appropriate data are analysed to identifyopportunities for best practice and inno"ation.

    d) Impro"ement opportunities deri"ed from newtechnologies and process concepts are identi,ed.

    e) An implementation strategy is established to

    achie"e the process impro"ement ob@ecti"es.

    a) Impact of all proposed changes is assessedagainst the ob@ecti"es of the de,ned process andstandard process.

    b) Implementation of all agreed changes ismanaged to ensure that any disruption to theprocess performance is understood and acted upon.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    51/97

    c) Based on actual performance, eHecti"eness of process changeis e"aluated against the de,ned productreuirements and process ob@ecti"es to determinewhether results are due to common or specialcauses.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    52/97

    PA .

    rise strategic and operational ob@ecti"es.

    Duestion %omment

    $verall rating for the process

    :oes the $ompany ha"e existing process orpolicies and procedures for the design andde"elopment of I solutionsJ

    # :oes the company ha"e written 9%P andbuild solution for manage the 6xist pro@ect andaligns with standards and addressess allidenti,ed ris!J# Apa!ah perusahaan mempunyai 9%P tertulisdan pembuatan solusi untu! memeliharaproye! yang ada dan se@alan dengan standardan mengidenti,!asi seluruh resi!o yang adaJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    53/97

    # :oes the company ha"e written 9%P andbuild solution in accordance withorganisational standard and has appropriate

    control security and auditabilityJ# Apa!ah perusahaan mempunyai 9%P tertulisdan pembuatan solusi yang sesuai denganstandar organisasi pengendalian yang tepat!eamanan dan auditabilityJ

    # :oes the existing 9%P has been appro"ed bythe authorities and conducted an adeuatetestJ# Apa!ah 9%P yang ada sudah disetu@ui olehpiha! berwenang dan dila!u!an test yangmemadaiJ

    # :oes designed solution has been throughtesting by the 5 N : section so the uality isin accordance with the desiredJ# Apa!ah solusi yang dirancang sudah melaluipengu@ian oleh bagian 5N: sehingga!ualitasnya sudah sesuai dengan yangdiingin!anJ

    # :oes any solution is used regularly andproperly maintained by the companyJ# Apa!ah setiap solusi diguna!an secara rutindan dipelihara dengan bai! oleh perusahaanJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    54/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    55/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    56/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    57/97

    2e"el / 2e"el 0

    PA /.1 PA /. PA 0.1 PA 0.

    Dot achie"ed(;#1'C)

    Partially

    Achie"ed(1'C #';C)

    2argely

    Achie"ed(';C # ='C)

    3ully Achie"ed(='#1;;C)

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    58/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    59/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    60/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    61/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    62/97

    Self-assessmentTemplate 6

    Process Dame 2e"el ;

    &AI;0

    9I0 (anage

    "urpose

    5ating by$riteria

    $apability2e"el Achie"ed

    ssess ;hether the follo;ing

    outcomes are achieved.

    2e"el ;Incomplete

    The process is not implemented,or fails to achieve its processpurpose.

    *evel "erformed

    " . The implemented processachieves its process purpose.

    )- ;C#1'C "- 1'C#';C *- ';C#=

    )E Dot Achie"ed"E Partially Achie"ed* E 2argely Achie"ed2# 3ully Achie"ed

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    63/97

    *evel

    (anaged

    " . "erformance (anagement

    - measure of the e7tent to;hich the performance of theprocess is managed.

    " . =or> "roduct (anagement- measure of the e7tent to;hich the ;or> productsproduced 3! the process areappropriatel! managed. The;or> products 6or outputs fromthe process are dened andcontrolled.

    *evel /&sta3lished

    " /. "rocess +enition - measure of the e7tent to ;hich astandard process is maintained tosupport the deplo!ment of thedened process.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    64/97

    " /. "rocess +eplo!ment - measure of the e7tent to ;hichthe standard process ise?ectivel! deplo!ed as a denedprocess to achieve its processoutcomes.

    *evel 0"redicta3le

    " 0. "rocess (easurement - measure of the e7tent to ;hichmeasurement results are used toensure that performance of theprocess supports theachievement of relevant processperformance o3:ectives in supportof dened 3usiness goals.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    65/97

    " 0. "rocess %ontrol - measure of the e7tent to ;hichthe process is @uantitativel!managed to produce a processthat is sta3le, capa3le andpredicta3le ;ithin dened limits.

    *evel 1$ptimiAing.

    " 1. "rocess innovation - measure of the e7tent to ;hichchanges to the process areidentied from anal!sis ofcommon causes of variation inperformance, and frominvestigations of innovativeapproaches to the denition anddeplo!ment of the process.

    " 1. "rocess optimisation - measure of the e7tent to ;hichchanges to the denition,

    management and performance ofthe process result in e?ectiveimpact that achieves the relevantprocess improvement o3:ectives.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    66/97

    ppendi7 + of the Self-assessment Guide

    2e"el 1 2e"el

    PA 1.1 PA .1

    vaila3ilit! E %apacit!

    +aintain ser"ice a"ailability e*cient management of resources and optim

    %riteria

    he following process outcomes are being achie"edF

    %riteria re

    (et BC)

    At this le"el there is little or no e"idence of anyachie"ement of the process purpose.

    &AI;0#%1 he a"ailability plan anticipates the businessexpectation of critical capacity reuirements.

    'C 2- ='C#1;;C

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    67/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    &AI;0#% $apacity performance and a"ailability meetreuirements.

    &AI;0#%/ A"ailability performance and capacity issues areidenti,ed and routinely resol"ed.

    a) %b@ecti"es for the performance of the process areidenti,ed.

    b) Performance of the process is planned andmonitored.

    c) Performance of the process is ad@usted to meetplans.

    d) 5esponsibilities and authorities for performing theprocess are de,ned assigned and communicated.

    e) Resources and information necessary forperforming the process are identi,ed made a"ailableallocated and used.

    f) Interfaces between the in"ol"ed parties aremanaged to ensure both eHecti"e communicationand also clear assignment of responsibility.

    a) Reuirements for the wor! products of the processare de,ned.

    b) Reuirements for documentation and control ofthe wor! products are de,ned.

    c) or! products are appropriately identi,ed

    documented and controlled.d) Wor! products are re"iewed in accordance withplanned arrangements and ad@usted as necessary tomeet reuirements.

    a) Astandard process including appropriate tailoringguidelines is de,ned that describes the fundamentalelements that must be incorporated into a de,nedprocess.

    b) The seuence and interaction of the standard

    process with other processes is determined.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    68/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    c) 5euired competencies and roles for performinga process are identi,ed as part of the standardprocess.

    d) Reuired infrastructure and wor! en"ironmentfor performing a process are identi,ed as part ofthe standard process.

    e) Suitable methods for monitoring the eHecti"enessand suitability of the process are determined.

    a) Ade,ned process is deployed based upon anappropriately selected and-or tailored standardprocess.

    b) Reuired roles responsibilities and authoritiesfor performing the de,ned process are assignedand communicated.

    c) Personnel performing the de,ned process are

    competent on the basis of appropriate educationtraining and experience.

    d) Reuired resources and information necessaryfor performing the de,ned process are madea"ailable allocated and used.

    e) Reuired infrastructure and wor! en"ironmentfor performing the de,ned process are madea"ailable managed and maintained.

    f) Appropriate data are collected and analysed asa basis for understanding the beha"iour of andto demonstrate the suitability and eHecti"eness ofthe process and to e"aluate where continuousimpro"ement of the process can be made.

    a) Process information needs in support of rele"antde,ned business goals are established.

    b) Process measurement ob@ecti"es are deri"ed fromprocess information needs.

    c) Quantitati"e ob@ecti"es for process performance insupport of rele"ant business goals are established.

    d) Measures and freuency of measurement areidenti,ed and de,ned in line with processmeasurement ob@ecti"es and uantitati"e ob@ecti"esfor process performance.

    e) Results of measurement are collected analysedand reported in order to monitor the extent to whichthe uantitati"e ob@ecti"es for process performanceare met.

    f) +easurement results are used to characteriseprocess performance.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    69/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    a) Analysis and control techniues are determined andapplied where applicable.

    b) Control limits of "ariation are established for normalprocess performance.

    c) Measurement data are analysed for special causesof "ariation.

    d) Correcti"e actions are ta!en to address specialcauses of "ariation.

    e) $ontrol limits are re#established (as necessary)following correcti"e action.

    a) Pprocess impro"ement ob@ecti"es for the processare de,ned that support the rele"ant business goals.

    b) Appropriate data are analysed to identify commoncauses of "ariations in process performance.

    c) Appropriate data are analysed to identifyopportunities for best practice and inno"ation.

    d) Impro"ement opportunities deri"ed from newtechnologies and process concepts are identi,ed.

    e) An implementation strategy is established toachie"e the process impro"ement ob@ecti"es.

    a)

    Impact of all proposed changes is assessed againstthe ob@ecti"es of the de,ned process and standardprocess.

    b) Implementation of all agreed changes is managedto ensure that any disruption to the processperformance is understood and acted upon.

    c) Based on actual performance, eHecti"eness of process change ise"aluated against the de,ned product reuirementsand process ob@ecti"es to determine whether resultsare due to common or special causes.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    70/97

    PA .

    isation of system performance through prediction of future performance and capacity reuirements.

    Duestion %omment

    $verall rating for the process

    :oes the $ompany ha"e existingprocess or policies and procedures forthe assessment of the a"ailabilityperformance and capacity of ser"icesand resourcesJ

    # :oes the company has 9%P regardingcapacity planningJ# Apa!ah Perusahaan memili!i 9%Pmengenai perencanaan !apasitas J

    # :oes the company ha"e plan foranticipate a"ailability of capacity when inthe critical conditionJ# Apa!ah Perusahaan memili!i rencanaantisipasi !etersediaan !apasitas pada

    saat !ondisi !ritisJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    71/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    72/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    73/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    74/97

    2e"el / 2e"el 0

    PA /.1 PA /. PA 0.1 PA 0.

    Dot achie"ed(;#1'C)

    Partially

    Achie"ed(1'C #';C)

    2argely

    Achie"ed(';C # ='C)

    3ully Achie"ed(='#1;;C)

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    75/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    76/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    77/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    78/97

    Self-assessmentTemplate 6

    Process Dame 2e"el ;

    &AI;7

    9IF (

    "urpose

    5ating by$riteria

    $apability2e"el Achie"ed

    ssess ;hether the follo;ing

    outcomes are achieved.

    2e"el ;Incomplete

    The process is not implemented,or fails to achieve its processpurpose.

    *evel "erformed

    " . The implemented processachieves its process purpose.

    )- ;C#1'C "- 1'C#';C *- ';C#=

    )E Dot Achie"ed"E Partially Achie"ed* E 2argely Achie"ed2# 3ully Achie"ed

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    79/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    80/97

    *evel (anaged

    " . "erformance (anagement- measure of the e7tent to;hich the performance of theprocess is managed.

    " . =or> "roduct (anagement- measure of the e7tent to;hich the ;or> productsproduced 3! the process areappropriatel! managed. The;or> products 6or outputs fromthe process are dened andcontrolled.

    *evel /&sta3lished

    " /. "rocess +enition - measure of the e7tent to ;hich a

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    81/97

    s an ar process s ma n a ne osupport the deplo!ment of thedened process.

    " /. "rocess +eplo!ment -

    measure of the e7tent to ;hichthe standard process ise?ectivel! deplo!ed as a denedprocess to achieve its processoutcomes.

    *evel 0"redicta3le

    " 0. "rocess (easurement - measure of the e7tent to ;hichmeasurement results are used toensure that performance of theprocess supports theachievement of relevant processperformance o3:ectives in supportof dened 3usiness goals.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    82/97

    " 0. "rocess %ontrol - measure of the e7tent to ;hichthe process is @uantitativel!managed to produce a processthat is sta3le, capa3le andpredicta3le ;ithin dened limits.

    *evel 1$ptimiAing.

    " 1. "rocess innovation - measure of the e7tent to ;hichchanges to the process areidentied from anal!sis ofcommon causes of variation inperformance, and from

    investigations of innovativeapproaches to the denition anddeplo!ment of the process.

    " 1. "rocess optimisation -

    measure of the e7tent to ;hichchanges to the denition,management and performance ofthe process result in e?ectiveimpact that achieves the relevantprocess improvement o3:ectives.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    83/97

    ppendi7 + of the Self-assessment Guide

    2e"el 1 2e"el

    PA 1.1 PA .1

    nage %hanges

    6nable fast and reliable deli"ery of change to the business and mitigat

    %riteria

    he following process outcomes are being achie"edF

    %riteria re

    (et BC)

    At this le"el there is little or no e"idence of anyachie"ement of the process purpose.

    'C 2- ='C#1;;C

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    84/97

    &AI;7#%1 Authorised changes are made in a timelymanner and with minimal errors.

    &AI;7#% Impact assessments re"eal the eHect of thechange on all aHected components.

    &AI;7#%/ All emergency changes are re"iewed and

    authorised after the change.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    85/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    &AI;7#%0 Bey sta!eholders are !ept informed of allaspects of the change.

    a) %b@ecti"es for the performance of the processare identi,ed.

    b) Performance of the process is planned andmonitored.

    c) Performance of the process is ad@usted tomeet plans.

    d) 5esponsibilities and authorities for performingthe process are de,ned assigned andcommunicated.

    e) Resources and information necessary forperforming the process are identi,ed madea"ailable allocated and used.

    f) Interfaces between the in"ol"ed partiesare managed to ensure both eHecti"ecommunication and also clear assignment ofresponsibility.

    a) Reuirements for the wor! products of theprocess are de,ned.

    b) Reuirements for documentation and controlof the wor! products are de,ned.

    c) or! products are appropriately identi,eddocumented and controlled.

    d) Wor! products are re"iewed in accordancewith planned arrangements and ad@usted asnecessary to meet reuirements.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    86/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    a) Astandard process including appropriatetailoring guidelines is de,ned that describes thefundamental elements that must be incorporatedinto a de,ned process.

    b) The seuence and interaction of the standardprocess with other processes is determined.

    c) 5euired competencies and roles forperforming a process are identi,ed as part of thestandard process.

    d) Reuired infrastructure and wor!en"ironment for performing a process areidenti,ed as part of the standard process.

    e) Suitable methods for monitoring theeHecti"eness and suitability of the process aredetermined.

    a) Ade,ned process is deployed based upon anappropriately selected and-or tailored standardprocess.

    b) Reuired roles responsibilities andauthorities for performing the de,ned processare assigned and communicated.

    c) Personnel performing the de,ned process arecompetent on the basis of appropriate educationtraining and experience.

    d) Reuired resources and informationnecessary for performing the de,ned processare made a"ailable allocated and used.

    e) Reuired infrastructure and wor!en"ironment for performing the de,nedprocess are made a"ailable managed andmaintained.

    f) Appropriate data are collected andanalysed as a basis for understanding thebeha"iour of and to demonstrate thesuitability and eHecti"eness of the processand to e"aluate where continuous

    impro"ement of the process can be made.

    a) Process information needs in support ofrele"ant de,ned business goals are established.

    b) Process measurement ob@ecti"es are deri"edfrom process information needs.

    c) Quantitati"e ob@ecti"es for processperformance in support of rele"ant business goalsare established.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    87/97

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    As a result of full achie"ement of this attributeF

    d) Measures and freuency of measurement areidenti,ed and de,ned in line with processmeasurement ob@ecti"es and uantitati"eob@ecti"es for process performance.

    e) Results of measurement are collectedanalysed and reported in order to monitor theextent to which the uantitati"e ob@ecti"es forprocess performance are met.

    f) +easurement results are used to characteriseprocess performance.

    a) Analysis and control techniues are determinedand applied where applicable.

    b) Control limits of "ariation are established fornormal process performance.

    c) Measurement data are analysed for specialcauses of "ariation.

    d) Correcti"e actions are ta!en to address specialcauses of "ariation.

    e) $ontrol limits are re#established (as necessary)following correcti"e action.

    a) Pprocess impro"ement ob@ecti"es for theprocess are de,ned that support the rele"antbusiness goals.

    b) Appropriate data are analysed to identifycommon causes of "ariations in processperformance.

    c) Appropriate data are analysed to identifyopportunities for best practice and inno"ation.

    d) Impro"ement opportunities deri"ed from newtechnologies and process concepts are identi,ed.

    e) An implementation strategy is established toachie"e the process impro"ement ob@ecti"es.

    a) Impact of all proposed changes is assessedagainst the ob@ecti"es of the de,ned process andstandard process.

    b) Implementation of all agreed changes ismanaged to ensure that any disruption to theprocess performance is understood and actedupon.

    c) Based on actual performance, eHecti"eness of processchange is e"aluated against the de,ned productreuirements and process ob@ecti"es to determinewhether results are due to common or special

    causes.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    88/97

    PA .

    ion of the ris! of negati"ely impacting the stability or integrity of the changed en"ironment.

    Duestion %omment

    $verall rating for the process

    :oes the $ompany ha"e existing process orpolicies and procedures on changemanagement for both standard changes andemergency maintenance relating to businessprocesses application and architectureJ hisco"ers change standards and proceduresimpact assessment prioritization andauthorization emergency changes trac!ingreporting closure and documentation.

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    89/97

    # :oes there is a 9%P regarding changesacti"ity are made by the companyJ

    # Apa!ah terdapat 9%P mengenai a!ti"itasperubahan yang dibuat oleh PerusahaanJ

    # :oes there is application changes orhardware changes are made in this yearJ# Apa!ah terdapat perubahan apli!asi atauperubahan hardware yang dibuat dalamtahun iniJ

    # If es :oes that changes are appro"ed byauthorized partyJ# Mi!a ya apa!ah perubahan tersebutdisetu@ui oleh piha! yang berwenangJ

    # :oes there is documentation of the impactof the eHect of the changes made on the IcomponentJ# apa!ah terdapat do!umentasi mengenaidampa! pengaruh terhadap perubahan yangdila!u!an atas !omponen IJ

    # :oes there is a 9%P regarding emergencychanges acti"ity are made by the companyJ# Apa!ah terdapat 9%P mengenai a!ti"itasperubahan darurat yang dibuat olehPerusahaanJ

    # If es :oes that changes are appro"ed byauthorized partyJ# Mi!a ya apa!ah perubahan tersebutdisetu@ui oleh piha! yang berwenangJ

    # :oes the company conduct a re"iew of thechanges madeJ# Apa!ah perusahaan mela!u!an re"iewterhadap perubahan yang dila!u!anJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    90/97

    # :oes the changes made by the company

    communicated to sta!eholdersJ# Apa!ah perubahan yang dila!u!an olehperusahaan diinformasi!an !epada parapemang!u !epentinganJ

    # If yes through what media the informationgi"en to sta!eholdersJ# Mi!a ya melalui media apa informasitersebut diberi!an !epada para pemang!u!epentingan J

    # :oes the sta!eholders are gi"en the

    opportunity to gi"e feedbac! on the changesmade by the $ompanyJ# Apa!ah para pemang!u !epentingandiberi!an !esempatan untu! dapatmemberi!an masu!an terhadap perubahanyang dila!u!an oleh PerusahaanJ

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    91/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    92/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    93/97

    2e"el / 2e"el 0

    PA /.1 PA /. PA 0.1 PA 0.

    Dot achie"ed(;#1'C)

    Partially

    Achie"ed(1'C #';C)

    2argely

    Achie"ed(';C # ='C)

    3ully Achie"ed(='#1;;C)

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    94/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    95/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    96/97

  • 7/23/2019 3. COBIT 5-Self-Assessment Templates - BAI - 25 August 2015

    97/97