logo资料库

COBIT5-Enabling-中文.pdf

第1页 / 共230页
第2页 / 共230页
第3页 / 共230页
第4页 / 共230页
第5页 / 共230页
第6页 / 共230页
第7页 / 共230页
第8页 / 共230页
资料共230页,剩余部分请下载后查看
Personal Copy of: Jiang Lin
ISACA® ISACA®www.isaca.orgIS IT IT 180 100,000 ISACA® 1969 ISACA® Journal IS Certified Information Systems Auditor®, CISA®Certified Information Security Manager®, CISM® Certified in the Governance of Enterprise IT®, CGEIT®Certified in Risk and Information Systems Control™, CRISC™ISACA COBIT® COBIT IT Quality Statement This Work is translated into Chinese Simplified from English language version of COBIT® 5 : Enabling Processes by the ISACA® China/Hong Kong Chapter with the permission of ISACA®. The ISACA® China/Hong Kong Chapter assumes sole responsibility for the accuracy and faithfulness of the translation. COBIT® 5ISACA®ISACA® ISACA® Copyright © 2012 ISACA. All rights reserved. For usage guidelines, see www.isaca.org/COBITuse. © 2012 ISACA www.isaca.org/COBITuse Disclaimer ISACA has designed this publication, COBIT® 5: Enabling Processes (the ‘Work’), primarily as an educational resource for governance of enterprise IT (GEIT), assurance, risk and security professionals. ISACA makes no claim that use of any of the Work will assure a successful outcome. The Work should not be considered inclusive of all proper information, procedures and tests or exclusive of other information, procedures and tests that are reasonably directed to obtaining the same results. In determining the propriety of any specific information, procedure or test, readers should apply their own professional judgement to the specific GEIT, assurance, risk and security circumstances presented by the particular systems or information technology environment. ISACA®COBIT® 5 IT GEIT ISACA® IT ISACA 3701 Algonquin Road, Suite 1010 Rolling Meadows, IL 60008 USA +1.847.253.1545 +1.847.253.1443 info@isaca.org www.isaca.org www.isaca.org/cobit ISACA www.isaca.org/knowledge-center Twitter ISACA https://twitter.com/ISACANews Twitter COBIT #COBIT LinkedIn ISACAISACA http://linkd.in/ISACAOfficial Facebook ISACA www.facebook.com/ISACAHQ COBIT® 5 ISBN 978-1-60420-279-3 2 Personal Copy of: Jiang Lin
ISACA COBIT 52009–2011 John W. Lainhart, IV, CISA, CISM, CGEIT, IBM Global Business Services, USA, Co-chair Derek J. Oliver, Ph.D., DBA, CISA, CISM, CRISC, CITP, FBCS, FISM, MInstISP, Ravenswood Consultants Ltd., UK, Co-chair Pippa G. Andrews, CISA, ACA, CIA, KPMG, Australia Elisabeth Judit Antonsson, CISM, Nordea Bank, Sweden Steven A. Babb, CGEIT, CRISC, Betfair, UK Steven De Haes, Ph.D., University of Antwerp Management School, Belgium Peter Harrison, CGEIT, FCPA, IBM Australia Ltd., Australia Jimmy Heschl, CISA, CISM, CGEIT, ITIL Expert, bwin.party digital entertainment plc, Austria Robert D. Johnson, CISA, CISM, CGEIT, CRISC, CISSP, Bank of America, USA Erik H.J.M. Pols, CISA, CISM, Shell International-ITCI, The Netherlands Vernon Richard Poole, CISM, CGEIT, Sapphire, UK Abdul Rafeq, CISA, CGEIT, CIA, FCA, A. Rafeq and Associates, India Floris Ampe, CISA, CGEIT, CIA, ISO 27000, PwC, Belgium Gert du Preez, CGEIT, PwC, Canada Stefanie Grijp, PwC, Belgium Gary Hardy, CGEIT, IT Winners, South Africa Bart Peeters, PwC, Belgium Dirk Steuperaert, CISA, CGEIT, CRISC, IT In Balance BVBA, Belgium Gary Baker, CGEIT, CA, Canada Brian Barnier, CGEIT, CRISC, ValueBridge Advisors, USA Johannes Hendrik Botha, MBCS-CITP, FSM, getITright Skills Development, South Africa Ken Buechler, CGEIT, CRISC, PMP, Great-West Life, Canada Don Caniglia, CISA, CISM, CGEIT, FLMI, USA Mark Chaplin, UK Roger Debreceny, Ph.D., CGEIT, FCPA, University of Hawaii at Manoa, USA Mike Donahue, CISA, CISM, CGEIT, CFE, CGFM, CICA, Towson University, USA Urs Fischer, CISA, CRISC, CPA (Swiss), Fischer IT GRC Consulting & Training, Switzerland Bob Frelinger, CISA, CGEIT, Oracle Corporation, USA James Golden, CISM, CGEIT, CRISC, CISSP, IBM, USA Meenu Gupta, CISA, CISM, CBP, CIPP, CISSP, Mittal Technologies, USA Gary Langham, CISA, CISM, CGEIT, CISSP, CPFA, Australia Nicole Lanza, CGEIT, IBM, USA Philip Le Grand, PRINCE2, Ideagen Plc, UK Debra Mallette, CISA, CGEIT, CSSBB, Kaiser Permanente IT, USA Stuart MacGregor, Real IRM Solutions (Pty) Ltd., South Africa Christian Nissen, CISM, CGEIT, FSM, CFN People, Denmark Jamie Pasfield, ITIL V3, MSP, PRINCE2, Pfizer, UK Eddy J. Schuermans, CGEIT, ESRAS bvba, Belgium Michael Semrau, RWE Germany, Germany Max Shanahan, CISA, CGEIT, FCPA, Max Shanahan & Associates, Australia Alan Simmonds, TOGAF9, TCSA, PreterLex, UK Cathie Skoog, CISM, CGEIT, CRISC, IBM, USA Dejan Slokar, CISA, CGEIT, CISSP, Deloitte & Touche LLP, Canada Roger Southgate, CISA, CISM, UK Nicky Tiesenga, CISA, CISM, CGEIT, CRISC, IBM, USA Wim Van Grembergen, Ph.D., University of Antwerp Management School, Belgium Greet Volders, CGEIT, Voquals N.V., Belgium Christopher Wilken, CISA, CGEIT, PwC, USA Tim M. Wright, CISA, CRISC, CBCI, GSEC, QSA, Kingston Smith Consulting LLP, UK Personal Copy of: Jiang Lin 3
Mark Adler, CISA, CISM, CGEIT, CRISC, Commercial Metals Company, USA Wole Akpose, Ph.D., CGEIT, CISSP, Morgan State University, USA Krzysztof Baczkiewicz, CSAM, CSOX, Eracent, Poland Roland Bah, CISA, MTN Cameroon, Cameroon Dave Barnett, CISSP, CSSLP, USA Max Blecher, CGEIT, Virtual Alliance, South Africa Ricardo Bria, CISA, CGEIT, CRISC, Meycor GRC, Argentina Dirk Bruyndonckx, CISA, CISM, CGEIT, CRISC, MCA, KPMG Advisory, Belgium Donna Cardall, UK Debra Chiplin, Investors Group, Canada Sara Cosentino, CA, Great-West Life, Canada Kamal N. Dave, CISA, CISM, CGEIT, Hewlett Packard, USA Philip de Picker, CISA, MCA, National Bank of Belgium, Belgium Abe Deleon, CISA, IBM, USA Stephen Doyle, CISA, CGEIT, Department of Human Services, Australia Heidi L. Erchinger, CISA, CRISC, CISSP, System Security Solutions, Inc., USA Rafael Fabius, CISA, CRISC, Uruguay Urs Fischer, CISA, CRISC, CPA (Swiss), Fischer IT GRC Consulting & Training, Switzerland Bob Frelinger, CISA, CGEIT, Oracle Corporation, USA Yalcin Gerek, CISA, CGEIT, CRISC, ITIL Expert, ITIL V3 Trainer, PRINCE2, ISO/IEC 20000 Consultant, Turkey Edson Gin, CISA, CISM, CFE, CIPP, SSCP, USA James Golden, CISM, CGEIT, CRISC, CISSP, IBM, USA Marcelo Hector Gonzalez, CISA, CRISC, Banco Central Republic Argentina, Argentina Erik Guldentops, University of Antwerp Management School, Belgium Meenu Gupta, CISA, CISM, CBP, CIPP, CISSP, Mittal Technologies, USA Angelica Haverblad, CGEIT, CRISC, ITIL, Verizon Business, Sweden Kim Haverblad, CISM, CRISC, PCI QSA, Verizon Business, Sweden J. Winston Hayden, CISA, CISM, CGEIT, CRISC, South Africa Eduardo Hernandez, ITIL V3, HEME Consultores, Mexico Jorge Hidalgo, CISA, CISM, CGEIT, ATC, Lic. Sistemas, Argentina Michelle Hoben, Media 24, South Africa Linda Horosko, Great-West Life, Canada Mike Hughes, CISA, CGEIT, CRISC, 123 Consultants, UK Grant Irvine, Great-West Life, Canada Monica Jain, CGEIT, CSQA, CSSBB, Southern California Edison, USA John E. Jasinski, CISA, CGEIT, SSBB, ITIL Expert, USA Masatoshi Kajimoto, CISA, CRISC, Japan Joanna Karczewska, CISA, Poland Kamal Khan, CISA, CISSP, CITP, Saudi Aramco, Saudi Arabia Eddy Khoo S. K., Prudential Services Asia, Malaysia Marty King, CISA, CGEIT, CPA, Blue Cross Blue Shield NC, USA Alan S. Koch, ITIL Expert, PMP, ASK Process Inc., USA Gary Langham, CISA, CISM, CGEIT, CISSP, CPFA, Australia Jason D. Lannen, CISA, CISM, TurnKey IT Solutions, LLC, USA Nicole Lanza, CGEIT, IBM, USA Philip Le Grand, PRINCE2, Ideagen Plc, UK Kenny Lee, CISA, CISM, CISSP, Bank of America, USA Brian Lind, CISA, CISM, CRISC, Topdanmark Forsikring A/S, Denmark Bjarne Lonberg, CISSP, ITIL, A.P. Moller - Maersk, Denmark Stuart MacGregor, Real IRM Solutions (Pty) Ltd., South Africa Debra Mallette, CISA, CGEIT, CSSBB, Kaiser Permanente IT, USA Charles Mansour, CISA, Charles Mansour Audit & Risk Service, UK Cindy Marcello, CISA, CPA, FLMI, Great-West Life & Annuity, USA Nancy McCuaig, CISSP, Great-West Life, Canada John A. Mitchell, Ph.D., CISA, CGEIT, CEng, CFE, CITP, FBCS, FCIIA, QiCA, LHS Business Control, UK Makoto Miyazaki, CISA, CPA, Bank of Tokyo-Mitsubishi, UFJ Ltd., Japan 4 Personal Copy of: Jiang Lin
Lucio Augusto Molina Focazzio, CISA, CISM, CRISC, ITIL, Independent Consultant, Colombia Christian Nissen, CISM, CGEIT, FSM, ITIL Expert, CFN People, Denmark Tony Noblett, CISA, CISM, CGEIT, CISSP, USA Ernest Pages, CISA, CGEIT, MCSE, ITIL, Sciens Consulting LLC, USA Jamie Pasfield, ITIL V3, MSP, PRINCE2, Pfizer, UK Tom Patterson, CISA, CGEIT, CRISC, CPA, IBM, USA Robert Payne, CGEIT, MBL, MCSSA, PrM, Lode Star Strategy Consulting, South Africa Andy Piper, CISA, CISM, CRISC, PRINCE2, ITIL, Barclays Bank Plc, UK Andre Pitkowski, CGEIT, CRISC, OCTAVE, ISO27000LA, ISO31000LA, APIT Consultoria de Informatica Ltd., Brazil Geert Poels, Ghent University, Belgium Dirk Reimers, Hewlett-Packard, Germany Steve Reznik, CISA, ADP, Inc., USA Robert Riley, CISSP, University of Notre Dame, USA Martin Rosenberg, Ph.D., Cloud Governance Ltd., UK Claus Rosenquist, CISA, CISSP, Nets Holding, Denmark Jeffrey Roth, CISA, CGEIT, CISSP, L-3 Communications, USA Cheryl Santor, CISSP, CNA, CNE, Metropolitan Water District, USA Eddy J. Schuermans, CGEIT, ESRAS bvba, Belgium Michael Semrau, RWE Germany, Germany Max Shanahan, CISA, CGEIT, FCPA, Max Shanahan & Associates, Australia Alan Simmonds, TOGAF9, TCSA, PreterLex, UK Dejan Slokar, CISA, CGEIT, CISSP, Deloitte & Touche LLP, Canada Jennifer Smith, CISA, CIA, Salt River Pima Maricopa Indian Community, USA Marcel Sorouni, CISA, CISM, CISSP, ITIL, CCNA, MCDBA, MCSE, Bupa Australia, Australia Roger Southgate, CISA, CISM, UK Mark Stacey, CISA, FCA, BG Group Plc, UK Karen Stafford Gustin, MLIS, London Life Insurance Company, Canada Delton Sylvester, Silver Star IT Governance Consulting, South Africa Katalin Szenes, CISA, CISM, CGEIT, CISSP, University Obuda, Hungary Halina Tabacek, CGEIT, Oracle Americas, USA Nancy Thompson, CISA, CISM, CGEIT, IBM, USA Kazuhiro Uehara, CISA, CGEIT, CIA, Hitachi Consulting Co., Ltd., Japan Rob van der Burg, Microsoft, The Netherlands Johan van Grieken, CISA, CGEIT, CRISC, Deloitte, Belgium Flip van Schalkwyk, Centre for e-Innovation, Western Cape Government, South Africa Jinu Varghese, CISA, CISSP, ITIL, OCA, Ernst & Young, Canada Andre Viviers, MCSE, IT Project+, Media 24, South Africa Greet Volders, CGEIT, Voquals N.V., Belgium David Williams, CISA, Westpac, New Zealand Tim M. Wright, CISA, CRISC, CBCI, GSEC, QSA, Kingston Smith Consulting LLP, UK Amanda Xu, PMP, Southern California Edison, USA Tichaona Zororo, CISA, CISM, CGEIT, Standard Bank, South Africa ISACA Kenneth L. Vander Wal, CISA, CPA, Ernst & Young LLP (retired), USA, International President Christos K. Dimitriadis, Ph.D., CISA, CISM, CRISC, INTRALOT S.A., Greece, Vice President Gregory T. Grocholski, CISA, The Dow Chemical Co., USA, Vice President Tony Hayes, CGEIT, AFCHSE, CHE, FACS, FCPA, FIIA, Queensland Government, Australia, Vice President Niraj Kapasi, CISA, Kapasi Bangad Tech Consulting Pvt. Ltd., India, Vice President Jeff Spivey, CRISC, CPP, PSP, Security Risk Management, Inc., USA, Vice President Jo Stewart-Rattray, CISA, CISM, CGEIT, CRISC, CSEPS, RSM Bird Cameron, Australia, Vice President Emil D’Angelo, CISA, CISM, Bank of Tokyo-Mitsubishi UFJ Ltd. (retired), USA, Past International President Lynn C. Lawton, CISA, CRISC, FBCS CITP, FCA, FIIA, KPMG Ltd., Russian Federation, Past International President Allan Neville Boardman, CISA, CISM, CGEIT, CRISC, CA (SA), CISSP, Morgan Stanley, UK, Director Marc Vael, Ph.D., CISA, CISM, CGEIT, CISSP, Valuendo, Belgium, Director Personal Copy of: Jiang Lin 5
Marc Vael, Ph.D., CISA, CISM, CGEIT, CISSP, Valuendo, Belgium, Chairman Michael A. Berardi Jr., CISA, CGEIT, Bank of America, USA John Ho Chi, CISA, CISM, CRISC, CBCP, CFE, Ernst & Young LLP, Singapore Phillip J. Lageschulte, CGEIT, CPA, KPMG LLP, USA Jon Singleton, CISA, FCA, Auditor General of Manitoba (retired), Canada Patrick Stachtchenko, CISA, CGEIT, Stachtchenko & Associates SAS, France 2009-2012 Patrick Stachtchenko, CISA, CGEIT, Stachtchenko & Associates SAS, France, Chairman Georges Ataya, CISA, CISM, CGEIT, CRISC, CISSP, Solvay Brussels School of Economics and Management, Belgium, Past Vice President Steven A. Babb, CGEIT, CRISC, Betfair, UK Sushil Chatterji, CGEIT, Edutech Enterprises, Singapore Sergio Fleginsky, CISA, Akzo Nobel, Uruguay John W. Lainhart, IV, CISA, CISM, CGEIT, CRISC, IBM Global Business Services, USA Mario C. Micallef, CGEIT, CPAA, FIA, Malta Anthony P. Noble, CISA, CCP, Viacom, USA Derek J. Oliver, Ph.D., DBA, CISA, CISM, CRISC, CITP, FBCS, FISM, MInstISP, Ravenswood Consultants Ltd., UK Robert G. Parker, CISA, CA, CMC, FCA, Deloitte & Touche LLP (retired), Canada Rolf M. von Roessing, CISA, CISM, CGEIT, CISSP, FBCI, Forfa AG, Switzerland Jo Stewart-Rattray, CISA, CISM, CGEIT, CRISC, CSEPS, RSM Bird Cameron, Australia Robert E. Stroud, CGEIT, CA Inc., USA ISACA IT ®ITGI® American Institute of Certified Public Accountants Commonwealth Association for Corporate Governance Inc. FIDA Inform Information Security Forum Institute of Management Accountants Inc. ISACA chapters ITGI France ITGI Japan Norwich University Solvay Brussels School of Economics and Management Strategic Technology Management Institute (STMI) of the National University of Singapore University of Antwerp Management School Enterprise GRC Solutions Inc. Hewlett-Packard IBM Symantec Corp. 6 Personal Copy of: Jiang Lin
................................................................................................................................................................................... 9 ................................................................................................................................................................................... 11 IT ................................................................................................................ 13 COBIT 5 .................................................................................................................................................................... 13 1. ...................................................................................................13 2. ...........................................................................................................13 3. IT .............................................................................................................15 4. IT ..............................................................................................................15 COBIT 5 ........................................................................................................................................................... 15 COBIT 5 ............................................................................................................................................15 COBIT 5 .......................................................................................................................................16 COBIT 5 ...............................................................................................................................16 ............................................................................................................................................................................................. 16 ................................................................................................................................................................16 IT ...........................................................................................................................................................17 COBIT 5 ......................................................................................................................................................... 19 ............................................................................................................................................................................. 21 COBIT 5 ................................................................................................................................................ 23 .......................................................................................................................................................................... 23 ............................................................................................................................................................................................. 23 COBIT 5 ........................................................................................................................................ 25 .................................................................................................................................................................................. 25 .............................................................................................................................................................................. 27 (EDM) .................................................................................................................................................29 (APO) ...................................................................................................................................................49 (BAI) ..................................................................................................................................................117 (DSS) .................................................................................................................................................171 (MEA) ................................................................................................................................................201 A. COBIT 5 ISACA ..........................................................................................................217 B. IT ...................................................................................................................225 C. IT IT ...............................................................................................................227 Personal Copy of: Jiang Lin 7
8 Personal Copy of: Jiang Lin
分享到:
收藏