COMBINING ITIL, COBIT AND ISO/IEC 27002 FOR STRUCTURING COMPREHENSIVE INFORMATION TECHNOLOGY FOR MANAGEMENT IN ORGANIZATIONS
Maico Gehrmann
Abstract
Open-access reader
Maico Gehrmann
Abstract
Open-access reader
Several methodologies, tools and standards have been designed to help IT management within organizations. Companies seek, with the use of these mechanisms, the placement of IT management and organizational strategies, mainly to ensure that IT helps with the objectives of the business and the results of the organization. Despite the vast amount of options for tools, methodologies and standards available, when they are used independently, these are not sufficiently wide-ranging to meet all the needs of IT management. This document analyzes ITIL, COBIT and ISO/IEC 27002 methodologies through literature review, highlighting their similarities and differences through the comparison between them. From this analysis, an overall structure is proposed which uses a combination of ITIL, COBIT and ISO/IEC 27002 that can be used by any organization as a more comprehensive solution for the handling and servicing of IT management. As any process, there are positive and negative points. Some negative points of a methodology may be strengthened by the positive ones of other methodologies. This creates more efficient processes.
OpenAlex reports 26 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Several methodologies, tools and standards have been designed to help IT management within organizations. Companies seek, with the use of these mechanisms, the placement of IT management and organizational strategies, mainly to ensure that IT helps with the objectives of the business and the results of the organization. Despite the vast amount of options for tools, methodologies and standards available, when they are used independently, these are not sufficiently wide-ranging to meet all the needs of IT management. This document analyzes ITIL, COBIT and ISO/IEC 27002 methodologies through literature review, highlighting their similarities and differences through the comparison between them. From this analysis, an overall structure is proposed which uses a combination of ITIL, COBIT and ISO/IEC 27002 that can be used by any organization as a more comprehensive solution for the handling and servicing of IT management. As any process, there are positive and negative points. Some negative points of a methodology may be strengthened by the positive ones of other methodologies. This creates more efficient processes.
Key concepts: COBIT, Information Technology Infrastructure Library, ITIL security management, Process management, Financial management for IT services, Process (computing), Information security management system, Knowledge management