Control Compliance Suite

 View Only
  • 1.  CCS Standard Manager COBIT template

    Posted Jan 09, 2013 06:06 AM

    Hi Guys,

    I am working on a client requirement with CCS Standard Manager to check compliance against COBIT standard. I could not find predefined COBIT template under Standards > Predefined.

    Can someone please tell me if COBIT comes in predefined standards or where to get it and import it into Standard Manager.

     



  • 2.  RE: CCS Standard Manager COBIT template

    Posted Jan 09, 2013 01:16 PM
      |   view attached
    CCS v11? There aren't any. CCS v10.5.x has them (I'm attaching), but they aren't anything you should necessarily use. Enjoy! :)

    Attachment(s)

    zip
    CobiT from CCS 10.5.zip   343 KB 1 version


  • 3.  RE: CCS Standard Manager COBIT template

    Posted Jan 10, 2013 12:31 AM

    Thanks Matt for the response. Please check the screenshot below. These are the predefined standards I am seeing on CCS console.

     



  • 4.  RE: CCS Standard Manager COBIT template

    Posted Jan 10, 2013 07:18 AM

    What's in the "Applications" folder?



  • 5.  RE: CCS Standard Manager COBIT template

    Posted Jan 11, 2013 05:50 AM

    Under Applications are specific checks for different Applications.



  • 6.  RE: CCS Standard Manager COBIT template

    Posted Jan 11, 2013 10:51 AM

    you can import what I attached into CCS... they work... but I'd do some heavy editing to them for use "in the real world" if I were you :)



  • 7.  RE: CCS Standard Manager COBIT template

    Posted Jan 11, 2013 12:00 PM

    If you really wanted to use the COBIT standard, the suggested method now is to make sure your checks are mapped to the appropriate control statements using the controls studio.  Make sure that you have enabled the Cobit Framework and then setup a Dashboard that will look at your results on how they stack up with the Cobit Framework.   Currently there are a couple of Dashboards that you can use as reference such as PCI Mandate or SOX Mandate Dashboards.   Hopefully these will be enough for you to determine how using the controls studio works.



  • 8.  RE: CCS Standard Manager COBIT template

    Posted Jan 11, 2013 01:12 PM

    Thanks Matt and cmccoy2,

    Appreciate your feedback. I will explore the possibility of customizing the predefined standard.

    Definitely going to try Control Studio for mapping controls aspect.

     



  • 9.  RE: CCS Standard Manager COBIT template

    Posted Jan 14, 2013 04:07 PM

    If you are going to use the Controls studio and you have copied checks from the predefined standards, then you will want to use the "Clone" mappings option in the Controls Studio.  This will restore the mappings of the control statements to the copied checks.   This only works if you are copying from the same instance of CCS since all of the control mappings are based on GUIDs in the database.   If you have a QA\Dev CCS instance and export\import the standards, then the clone mappings doesn't work.  This may save you some time with mappings.