Combining ITIL, COBIT, and ISO/IEC
27002
(in Order to Design a Comperhensive IT Framework in Organization)
Introduction
Management is an attempt to direct and
control a group of one or more people or entities for the purpose of
coordinating and harmonizing them towards accomplishing a special goal . At present
Management encompasses several dimension like human resources ,financial
resource and technological resource. One new area of management is information
technology management (or IT management). It is a combination of two branches
of study, information technology and management.
‘Information Technology’ has several definition
from different perspective :
- From the first
perspective , IT system are application and infrastructure which are components
of a larger product. They enable or are embedded in processes and service.
- From
the second perspective , IT is an organization with its own set of capabilities
and resource. IT organization can be one of various types such as business
function , shared service units and enterprise –level core units.
- From
the third perspective , IT is a category of service utilized by business . They
are typically IT application and infrastructure that are package and offered as
service by internal IT organization of external service providers. In this
perspective IT cost are treated as business expenses.
- From
the fourth perspective , IT is a category of business assets that provide a
stream of benefit for their owner , including but not limited to revenue ,
income and profit. In this perspective IT cost are treated as investment.
All definition emphasize
the importance of IT in the organization . therefore it is crucial to manage
and implement IT in the organizations. There are several standards , tools ,
frameworks, and best practice to manage and maintain IT service. The most
applicable and widely used such standards are ISO/IEC 27002 in information
security. Hence it is better to combine them to make a comprehensive IT
framework in the organization . Based on previous studies the best combination
should be between laying ITIL , COBIT and ISO/IEC 17799 together . But ITIL
de-facto standard and ISO/IEC 17799 standard recently has been refreshed and
changed.