Abstract
Information Technologies (IT) play a crucial role in the development of the business processes in organizations. Acquiring the best technologies is quickly becoming as important as understanding and improving the business model of organizations. As a result, many (inter)national standards and models for IT Management, IT Government and IT Security have been developed. This situation allows organizations to choose and improve their processes, selecting the models that best suit their needs. Since several relationships between these models can be found, carrying out the harmonization of their similarities and differences will make it possible to reduce the time and effort involved in implementing them. In this paper, we present a harmonization strategy which has been defined to harmonize COBIT 4.1, Basel II, VAL IT, RISK IT, ISO 27002 and ITIL V3. This work intends to support organizations which are interested in knowing how to carry out the harmonization of these models. Furthermore, as a result of the execution of the harmonization strategy we have defined, a unified model for Banking, called ITGSM, is presented. It resolves the conflicts between the models mentioned above and provides a useful reference model to organizations that are planning to adopt them.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Pardo, C., Pino, F.J., García, F., Piattini, M., Baldassarre, M.T.: Trends in Harmonization of Multiple Reference Models. In: Evaluation of Novel Approaches to Software Engineering. LNCS, Springer, Heidelberg (2011) (in press) (Special edition best papers ENASE 2010, extended and updated paper)
Oud, E.J.: The Value to IT of Using International Standards. Information Systems Control Journal 3 (2005)
NIST: National Institute of Standards and technology, NIST (2011), http://csrc.nist.gov/
ITGI: Risk IT: Framework for Management of IT Related Business Risks. IT Governance Institute (2009), http://www.isaca.org/
ITGI: VAL IT Framework 2.0. IT Governance Institute, EEUU (2008)
ITGI: COBIT Mapping: Mapping of ITIL V3 with COBIT 4.1. Technical report, IT Governance Institute (ITGI) and Office of Government Commerce, OGC (2008)
ITGI: Aligning Cobit 4.1, ITIL V3 and ISO/IEC 27002 for Business Benefit. Technical report, IT Governance Institute (ITGI) and Office of Government Commerce, OGC (2008)
Gheorghe, M., Nastase, P., Boldeanu, D., Ofelia, A.: IT governance in Romania: A case study. Technical report, International Trade and Finance Association (2008)
Abu-Musa, A.: Exploring the importance and implementation of COBIT processes in Saudi organizations: An empirical study. Information Management & Computer Security 17, 73–95 (2009)
Kulkarni, B.: Banking Industry Regulatory Challenges: Moving From Regulation-based to process based Compliance. In: LNCS, pp. 4–8 (2009)
Haes, S.D., Grembergen, W.V.: An Exploratory Study into IT Governance Implementations and its Impact on Business/IT Alignment. Inf. Sys. Manag. 26, 123–137 (2009)
ITIL: Information Technology Infrastructure Library V3 (2010), http://www.itil-officialsite.com/
ISO: Information technology -security techniques- code of practice for information security management - ISO 27002:2005. International Organization for Standardization (2005), www.iso.org/
BIS: International Convergence of Capital Measurement and Capital Standards - Basel II. Bank for International Settlements (2004), http://www.bis.org
Pardo, C., Pino, F., García, F., Piattini, M.: Homogenization of Models to Support multi-model processes in Improvement Environments. In: 4th International Conference on Software and Data Technologies, Sofía, pp. 151–156 (2009)
Baldassarre, M.T., Caivano, D., Pino, F.J., Piattini, M., Visaggio, G.: A strategy for painless harmonization of quality standards: A real case. In: Ali Babar, M., Vierimaa, M., Oivo, M. (eds.) PROFES 2010. LNCS, vol. 6156, pp. 395–408. Springer, Heidelberg (2010)
Pino, F.J., Baldassarre, M.T., Piattini, M., Visaggio, G., Caivano, D.: Mapping software acquisition practices from ISO 12207 and CMMI. In: Maciaszek, L.A., González-Pérez, C., Jablonski, S. (eds.) ENASE 2008/2009. Communications in Computer and Information Science, vol. 69, pp. 234–247. Springer, Heidelberg (2010)
Pino, F., Balssarre, M.T., Piattini, M., Visaggio, G.: Harmonizing maturity levels from CMMI-DEV and ISO/IEC 15504. Journal of Software Maintenance and Evolution: Research and Practice 22, 279–296 (2009)
Pardo, C., Pino, F.J., García, F., Piattini, M., Baldassarre, M.T.: A Process for Driving the Harmonization of Models. In: The 11th International Conference on Product Focused Software Development and Process Improvement (PROFES 2010). Second Proceeding: Short Papers, Doctoral Symposium and Workshops, Limerick, pp. 53–56 (2010)
ARMONÍAS: A Process for Driving Multi-models Harmonization, ARMONÍAS Project (2009), http://alarcos.esi.uclm.es/armonias/
Lemus, S.M., Pino, F.J., Piattini, M.: Towards a Model for Information Technology Governance applicable to the Banking Sector. In: V International Congress on IT Governance and Service Management (ITGSM 2010), pp. 1–6. Alcalá de Henares (2010)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2011 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Pardo, C., Pino, F.J., García, F., Piattini, M., Baldassarre, M.T., Lemus, S. (2011). Homogenization, Comparison and Integration: A Harmonizing Strategy for the Unification of Multi-models in the Banking Sector. In: Caivano, D., Oivo, M., Baldassarre, M.T., Visaggio, G. (eds) Product-Focused Software Process Improvement. PROFES 2011. Lecture Notes in Computer Science, vol 6759. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-21843-9_7
Download citation
DOI: https://doi.org/10.1007/978-3-642-21843-9_7
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-642-21842-2
Online ISBN: 978-3-642-21843-9
eBook Packages: Computer ScienceComputer Science (R0)