View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Hardware
July 24, 2013

ISACA helps enterprises manage vendors using COBIT 5 framework

New guide provides sample SLAs, case studies and mappings.

By Duncan Macrae

Global IT association ISACA has released a new guide applying the internationally accepted COBIT 5 governance framework to help enterprises effectively manage vendors.

Vendor Management: Using COBIT 5 provides practical action items for all stakeholders involved in the vendor-management process, from the board and C-level executives to the legal department and IT. It outlines:

  • Life cycle stages and stakeholders.
  • Good practices to manage threats and risk.
  • How to manage a cloud service provider.
  • Practical service level agreement (SLA) templates, checklists and examples (available for download in an online toolkit).
  • A case study outlining the consequences of ineffective vendor management.
  • A high-level mapping of COBIT 5 and ITIL V3 for vendor management.

Nikolaos Zacharopoulos, CISA, CISSP, senior IT auditor at DeutschePost-DHL and member of ISACA’s Guidance and Practices Committee, said: "Recent research from the IT Policy Compliance Group reveals that approximately one out of five enterprises does not invest sufficient effort to manage vendors and vendor-provided services effectively.

"This means that enterprise requirements and standards are not properly incorporated into vendor contracts, ownership of information being handled by vendors remains unclear, and access to information is not guaranteed if the vendors go out of business."

The ISACA publication emphasises that IT vendor management is not solely IT’s responsibility, and clarifies the responsibilities of stakeholders within the enterprise.

Zacharopoulos added: "As companies worldwide are turning toward fewer — but much more integrated — vendors, they are benefiting from a single point of contact. However, they are simultaneously increasing risk to the enterprise, and that risk needs to be managed rigorously by all stakeholders.

"The COBIT 5 framework provides tested guidance to help them effectively govern these relationships so they deliver maximum value with minimum risk."

Content from our partners
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline
How hackers’ tactics are evolving in an increasingly complex landscape

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how New Statesman Media Group may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU