This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Kamis, 08 Juni 2017

Review Jurnal (English Version)

Combining ITIL, COBIT, and ISO/IEC 27002
(in Order to Design a Comperhensive IT Framework in Organization
)

1.       Introduction
Management is an attempt to direct and control a group of one or more people or entities for the purpose of coordinating and harmonizing them towards accomplishing a special goal . At present Management encompasses several dimension like human resources ,financial resource and technological resource. One new area of management is information technology management (or IT management). It is a combination of two branches of study, information technology and management.
‘Information Technology’ has several definition from different perspective :
- From the first perspective , IT system are application and infrastructure which are components of a larger product. They enable or are embedded in processes and service.
- From the second perspective , IT is an organization with its own set of capabilities and resource. IT organization can be one of various types such as business function , shared service units and enterprise –level core units.
- From the third perspective , IT is a category of service utilized by business . They are typically IT application and infrastructure that are package and offered as service by internal IT organization of external service providers. In this perspective IT cost are treated as business expenses.
- From the fourth perspective , IT is a category of business assets that provide a stream of benefit for their owner , including but not limited to revenue , income and profit. In this perspective IT cost are treated as investment.

All definition emphasize the importance of IT in the organization . therefore it is crucial to manage and implement IT in the organizations. There are several standards , tools , frameworks, and best practice to manage and maintain IT service. The most applicable and widely used such standards are ISO/IEC 27002 in information security. Hence it is better to combine them to make a comprehensive IT framework in the organization . Based on previous studies the best combination should be between laying ITIL , COBIT and ISO/IEC 17799 together . But ITIL de-facto standard and ISO/IEC 17799 standard recently has been refreshed and changed.

2.       ITIL
ITIL (Information Technology Infrastructure Library) is a de-facto standard which introduced and distributed by Office of Government Commerce (OGC) in UK and includes all IT parts of organization. At present ITIL is the most widely accepted approach to IT service Management in the world. It has an iterative, multidimensional and lifecycle form structure. ITIL has an integrated approach as required by the ISO/IEC 20000 standard with following guidance.


·         Service Strategy
The service strategy provides guidance on how to design , develop and implement service management form organizational capability perspective and strategic asset. It provides guidance on the principles underpinning the practice of service management which are useful for developing service management policies, guidelines and processes across the ITIL service lifecycle . service strategy guidance is applicable in the context of other parts of ITIL lifecycle. Service strategy covers these parts of IT system : the development of markets , internal and external , service assets, service catalogue and implementation of strategy through the service lifecycle.

·         Service Design
It is guidance for the design and development of service and service management processes. It covers design principles and method for converting strategic objective into portfolios of service and service assets. The scope of Service Design is includes the changes and improvements necessary to increase or maintain value to costumer over the lifecycle of service, the continuity of service, achievements of service levels and conformance to standards and regulations. It guides organization on how to develop design capabilities for service management.

·         Service Transition
It is  guidance for the development and improvement of capabilities for transitioning new and changed service into operations. Service Transition provides guidance on how the requirements of service strategy encoded in Service Design are effectively realized in Service Operation while controlling the risk of failure and disruption . This part of ITIL framework combines practices in release management , program management and risk management and place them in the practical context of service management.

·         Service Operation
Service Operation tries to embody practice in the management of Service Operation. It includes guidance on achieving effectiveness and efficiency in the delivery and support of service so as to ensure value for the customer and the service provider. Strategic objectives are ultimately realized through Service Operation , therefore making it a critical capability.

·         Continual Service Improvement
This is including of instrumental guidance in creating and maintaining value for customers through better design , introduction and operation of service. It combines principles , practice and methods from quality management, Change Management and  capability improvement. Organization learn to realize incremental and large-scale improvements in service quality , operational efficiency and business continuity.

3.       COBIT
The control Objectives for Information and related Technology (COBIT) is a set of best practice (framework) for information technology management created by the Information System Audit and Control Association (ISACA), and the IT Governance Institute (ITGI) in 1992 . COBIT was released and used primarily by the IT community. Later Management Guidelines were added , and COBIT became the internationally accepted framework  for IT governance and control.
                COBIT provides managers , auditors, and IT users with a set of generally accepted measures , indicators, processes and best practice to assist them in maximizing the benefits derived through the use of information technology and developing appropriate IT governance and control in a company.
                The COBIT mission is to research , develop, publicize and promote an authoritative , up to date, international set of generally accepted information technology control objective for day-to-day use by business managers and auditors. Managers, auditors ,and users benefit from the development of COBIT because it helps them understand their IT system and decide the level of security and control that is necessary to protect their companies assets through the development of an IT governance model.

COBIT covers four domains:

·         Plan and Organize
The Planning and Organization domain covers the use of technology and how best it can be used in a company to help achieve the company’s goals and objective. It also highlights the organizational and infrastructural form IT is to take in order to achieve the optimal results and to generate the most benefits from the use of IT.

·         Acquire and Implement
The aim is to identify its IT requirements acquiring the technology and to implement it within the company’s current business processes.
This domain also addresses the development of a maintenance plan that a company should adopt in order to prolong the life of an IT system and its components.

·         Delivery and Support
This domain tries to manage delivery service which include:
§  Define and Manage Service Levels
§  Manage Third-party Service
§  Manage Performance and Capacity
§  Ensure Continuous Service
§  Ensure System Security
§  Identify and Allocated Costs
§  Educated and Train Users
§  Manage Service Desk and Incidents
§  Manage the configuration
§  Manage Problems
§  Manage Data
§  Manage the Physical Environment
§  Manage Operation

·         Monitor and Evaluate
The Monitoring and Evaluation domain deals with a company’s strategy in assessing the needs of the company and whether or not the current IT system still meets the objectives for which it was designed and the controls necessary to comply with regulatory requirements. Monitoring also covers the issue of an independent assessment of the effectiveness of IT system in its ability to meet business objective and the company’s control process by internal and external auditors.

4.       ISO/IEC 27002
This is an information security management system (ISMS) standard which is the code of practice for Information Security Management. It list security control objectives and recommended range of a specific security controls .

Organizations that implement an ISMS in accordance with the best practice advice in ISO/IEC 27002 are likely simultaneously to meet the requirements of ISO/IEC 27002, but certification is entirely optional (unless mandated by the organization’s stakeholder).

5.       ITIL related to COBIT
The strength within ITIL is the way processes are described with difference activities and flowcharts to use for target implementation . Cost/Benefit and Implementation issues are also described. There are also guidelines for reviews and Critical Success Factors, but these issues  are better described in COBIT, First of all COBIT is defined by the IT-audit community as a framework highly suitable for authority. COBIT is also stronger when it come to management issues where “Management Guidelines” provides the implementer with a reference where Critical Success Factors are describe together with Key Goal Indicators ,Key Performance Indicators  and Capability Maturity Models (CMM).

When ITIL is benchmarked with COBIT , it has been found that they correspond with each other to a high degree ,especially, when the processes  of COBIT are ITIL based as in its latest version . In spite of different words used for the same issues but they cover the same problem. It is only for incident Management in ITIL that there is not any equivalent in COBIT. This however ,does not mean that it is not covered at all. Instead it may be covered in the other part of the framework or with a different approach. As shown in table therefore it is better to borrow concepts/process, Activities, Cost/Benefits and planning to Implementation from ITIL standard and audits from COBIT to design a comprehensive framework.

6.       ITIL related to ISO/IEC 27002
As already mentioned, ISO/IEC 27002 is used for information security and not just IT issues, With such broad objective it is apparent that ISO/IEC 27002 does not correspond with ITIL as much as ITIL does with COBIT . ISO/IEC 27002 main straight is in its application for ensuring overall security at all levels within an organization.
Problem Management and Configuration Management in ITIL have not any equivalent in ISO 27002. Configuration Management has a huge impact on the IT environment and it should be handled in a secure manner. In addition in ISO/IEC 27002 security is characterized as the preservation of confidentially , integrity and Availability. In ITIL Availability is about quality aspect such as reliability, maintainability , serviceability & resilience. Another important finding in the benchmark it that financial issues are not handled at all in ISO/IEC27002 ,instead it is about only risk management, i.e. the implementer should mitigate risks to avoid costs. ITIL on the other hand , is about financing and cost allocation for the delivery of IT-services.
Therefore it is better to borrow Information Security process from ISO/IEC 270002 in designing a comprehensive framework.

Conclusion
In every organization today, IT service must be delivered in a cost efficient manner, mitigating security risk and complying with legal requirements. The equation is difficult to handle and in some cases it seems like an  impossible mission . To be able to survive in this environment a combination of ITIL, COBIT and ISO/IEC 27002 can be value able for organization targets , Implementers should use ITIL to define strategies , plans and processes, use COBIT for metrics, benchmarks and audits and use ISO/IEC 27002 to address security issues to mitigate the risk as below in Table 2.
ITIL
COBIT
ISO/IEC 27002
Concepts/process
Critical Success Factors
Information Security
Activities
Metric (CSF,KPI)

Cost/Benefits
Benchmarking (CMM)

Planning for Implementation



Audit


        

Review Jurnal

MANAJEMEN RESIKO TEKNOLOGI INFORMASI UNTUK KEBERLANGSUNGAN LAYANAN PUBLIK MENGGUNAKAN FRAMEWORK INFORMATION TECHNOLOGY INFRASTRUCTURE LIBRARY(ITIL VERSI 3)

ABSTRAKS
Kemajuan teknologi Informasi dan komunikasi (TIK) serta meluasnya perkembangan infrastruktur informasi global telah mengubah pola dan cara beraktivitas pada organisasi, institusi, industri, maupun pemerintahan. Fakta semakin meningkatnya ketergantungan organisasi kepada TI untuk mencapai tujuan strategi dan kebutuhan organisasi menjadi pendorong utama pentingnya TIK. Manajemen TI dan merencanakan strategi-strategi dalam keberlangsungan layanan TI harus dilakukan secara sistematis dan latihan yang terus menurus untuk meningkatkan dan memperbaiki layanan TI.
Kata Kunci: Manajemen resiko TI, ITIL,Layanan TI

1.      PENDAHULUAN
     Kemajuan teknologi informasi dan komunikasi (TIK) serta meluasnya perkembangan infrastruktur informasi global telah mengubah pola dan cara beraktivitas pada organisasi, institusi, industri, maupun pemerintahan. Fakta semakin meningkatnya ketergantungan organisasi kepada TI untuk mencapai tujuan strategi dan kebutuhan organisasi  menjadi pendorong utama pentingnya TIK. Ketergantungan tersebut menyebabkan tumbuhnya kebutuhan akan layanan TI berkualitas tinggi yang mengikuti kebutuhan organisasi dan user yang sesuai dengan perkembangannya.
     Penyelenggaraan pemerintahan dalam rangka pelayanan publik memerlukan tata kelola yang baik(Permenkominfo, 2007). Di sisi lain, penggunaan TIK oleh institusi pemerintahan sudah dilakukan sejak beberapa dekade lalu, dengan intensitas yang semakin meningkat. Dalam upaya memastikan penggunaan TIK tersebut benar-bbenar mendukung tujuan penyelenggaraan pemerintahan, dengan memperhatikan efisiensi penggunaan sumber daya dan pengelolaan risiko terkait dengan itu, maka diperlukan tata kelola TI (Permenkominfo, 2007).
              Untuk meminimilasi resiko tersebut, setiap instansi pemerintahan daerah diharapkan dapat menyusun langkah terpadu untuk menjamin keberlangsungan layanan agar tetap dapat berfungsi dengan baik terutama dalam penggunaan layanan TI.
       Information Technology Infrastructure Library (ITIL) sebagai suatu kerangka kerja manajemen layanan TI dapat digunakan sebagai panduan dalam menyusun langkah-langkah operasional tersebut. Dengan kerangka kerja ITIL diharapkan resiko yang mungkin terjadi dapat diminimalisasi serta dapat dilakukan mitigasi resiko dalam upaya menjaga keberlangsungan layanan TI.

2.      MANAJEMEN RESIKO TI
 Resiko merupakan fungsi kemungkinan (likelihood) sumber ancaman (threat-source) mengeksploitasi kerentanan (vulnerability) potensial, yang menghasilkan dampak (impact) kejadian yang merugikan organisasi (Spremic, 2008). Menurut Spremic, resiko yang terjadi pada pemanfaatan TI dapat memberikan dampak negatif terhadap aset TI (data, software, hardware), layanan TI, bisnis proses, serta organisasi secara keseluruhan.
                   Sedangkan menurut IT governance, IT Audit dan IT security, manajemen resiko TI adalah proses untuk memahami dan memberikan respon terhadap faktor yang dapat menyebabkan kegagalan dalam autentikasi, non-repudiation, kerahasiaan, integritas atau ketersediaan dari sistem informasi. Sesuai dengan kebijakan yang tertuang didalam Permenkominfo no 41 tahun 2007, bahwa dalam rangka melakukan tata kelola TI oleh institusi pemerintahan perlu dilakukan manajemen resiko yang mencakup resiko proyek, resiko atas informasi, dan resiko atas keberlangsungan layanan (Permenkominfo, 2007)

2.1 Perencanaan Manajemen Resiko TI
Menurut Spremic (2008) untuk keberhasilan dalam menjaga segala sesuatu yang dapat menyebabkan permasalahan, setiap organisasi harus membangun metode dan teknik untuk mengendalikan insiden-insiden yang terjadi pada TI dan untuk mengidentifikasi resiko yang mungkin terjadi. Terdapat tahapan-tahapan penting dalam perencanaan manajemen resiko TI:
Identifikasi dan klasifikasi resiko TI,
Penilaian resiko TI (Business Impact Analysis) dan menentukan prioritas,
Strategi penanggulangan resiko TI – identifikasi pengendalian TI,
Implementasi dan dokumentasi dari penanggulangan resiko (pengendalian TI),
Pendekatan portofolio resiko TI dan keselarasan dengan strategi bisnis,
Pengawasan berkala terhadap tingkat resiko TI dan audit.

2.2 Kerangka Kerja Manajemen Resiko TI
Prinsip M_o_R – prinsip-prinsip tersebut merupakan esensi dalam pengembangan praktik manajemen resiko yang baik dan diturunkan dari prinsip-prinsip tatakelola perusahaan (corporate governance).
   Pendekatan M_o_R – pendekatan organisasi untuk prinsip-prinsip tersebut dibutuhkan untuk mendefinisikan dan persetujuan dalam dokumen berikut:
Kebijakan manajemen resiko
Panduan proses
Perencanaan
Registrasi resiko
Permasalahan log
Proses M_o_R – berikut ini menjelaskan empat tahapan aktivitas dalam manajemen resiko:
Identifikasi – ancaman dan peluang dalam aktivitas yang dapat mempengaruhi kemampuan dalam mencapai tujuan.
Menilai – pemahaman net effect dari identifikasi ancaman dan peluang aktivitas yang dilakukan.
Merencanakan – mempersiapkan tanggapan manajemen secara spesifik yang dapat mengurangi ancaman dan memaksimalkan peluang.
Implementasi – penerapan rencana manajemen resiko, mengawasi efektivitas dan mengambil langkah yang diperlukan dalam menanggulangi ekspektasi yang tidak sesuai.
         Embedding dan reviewing M_o_R diperlukan review keberlanjutan dan peningkatan bahwa hal tersebut masih baik untuk digunakan Komunikasi diperlukan aktivitas komunikasi yang tepat dalam menjamin bahwa setiap orang tetap up to date dengan perubahan dalam ancaman, peluang dan seluruh aspek manajemen resiko.

2.3 Information Technology Service Continuity Management  (ITSCM)
        ITSCM merupakan salah satu proses area dari service design ITIL versi 3. Tujuan dari ITSCM adalah untuk mendukung seluruh proses manajemen keberlangsungan bisnis dengan memastikan bahwa kebutuhan teknis TI dan fasilitas layanan (termasuk sistem komputer, jaringan, aplikasi, data repositories, telekomunikasi, lingkungan, dukungan teknis dan service desk) dapat kembali beroperasi dan sesuai dengan timescale bisnis.

Sasaran dari ITSCM diantaranya adalah untuk :
Memelihara rencana-rencana berkelanjutan layanan TI (IT service continuity plans) dan rencana-rencana pemulihan TI yang mendukung kelanjutan bisnis
Melengkapi exercise business impact analysis (BIA) secara teratur untuk menjamin seluruh rencana-rencana berkelanjutan dikelola agar selaras dengan dampak perubahan dan kebutuhan bisnis
Menyediakan panduan dan saran untuk seluruh area bisnis dan TI yang berkaitan dengan kelanjutan dan pemulihan
Memastikan mekanisme yang tepat untuk kelanjutan dan pemulihan agar sesuai dengan tujuan kelanjutan bisnis
Menilai dan dampak perubahan pada rencanarencana kelanjutan layanan TI dan rencanarencana pemulihan TI
Memastikan bahwa ketersediaan layanan diimplementasikan sesuai dengan anggaran yang ditetapkan
3.      IMPLEMENTASI

3.1 Tahap Inisialisasi
Pada tahap ini dilakukan aktivitas-aktivitas sebagai berikut:
Penentuan kebijakan – hal ini harus dibangun dan dikomunikasikan sehingga semua orang yang ada di organisasi dapat terlibat. Dalam kebijakan ini ditentukan sasaran serta fokus dari manajemen. Peran dari pimpinan sangat menentukan keberhasilan dari kegiatan yang dilaksanakan.
Lingkup – pada tahap ini ditentukan lingkup serta tanggungjawab dari setiap staf yang ada diorganisasi. Kewenangan dan tanggungjawab dari setiap staf disesuaikan dengan kemampuan dan kapabilitas yang dimilikinya, agar mendukung terhadap setiap kegiatan yang akan dilaksanakan.
Alokasi Sumberdaya – keberlangsungan dari bisnis membutuhkan sumberdaya diantaranya uang dan sumberdaya manusia. Hal ini sangat penting untuk mendukung kelangsungan dari proses. Penentuan alokasi sumberdaya dengan tepat dapat mengefisiensikan kinerja yang dilakukan.
Struktur pengendali dan Organisasi Proyek – kegiatan yang dilakukan perlu diorganisir dan dikendalikan dengan baik, karena kegiatan yang bersifat kompleks sehingga perlu dilakukan langkah-langkah sistematis dan terkendali.
Perencanaan dan Proyek yang berkualitas – perencanaan yang baik dapat menjamin keberhasilan pencapaian kualitas kegiatan. Setiap kegiatan yang akan dilaksanakan perlu direncanakan dengan matang agar hasil yang diperoleh dapat dimaksimalkan serta meminimalisasi resiko-resiko yang terjadi.

3.2 Tahap Kebutuhan dan Strategi
3.2.1 Analisis Resiko
Pada tahap ini menilai level resiko dan membuat ranking resiko dengan mempertimbangkan faktor kecenderungan (likelihood) dan besarnya dampak resiko (impact). Pada proses penilaian ini memanfaatkan kerangka kerja Management of Risk (M_o_R). Pendekatan analisa resiko dapat secara kualitatif atau kuantitatif.

3.2.2 Strategi Keberlangsungan Layanan TI
Setelah mengetahui resiko-resiko yang terjadi serta prioritas yang harus dilakukan dari hasil analisis resiko maka dapat dirancang strategi-strategi untuk keberlangsungan layanan TI.
4.      
P   PENUTUP
Keberlangsungan layanan pada pelayanan publik merupakan salah satu hal yang perlu ditata kelola agar penyelenggaran pelayanan dapat terselenggara dengan baik sehingga masyarakat dan pengguna dapat terlayani sesuai dengan kebutuhannya. Manajemen resiko TI dan merencanakan strategistrategi dalam keberlangsungan layanan TI harus dilakukan secara sistematis dan latihan yang terus menerus untuk meningkatkan dan memperbaiki proses layanan TI.












Tugas (Softskill) Review Jurnal


PERBEDAAN ITIL DAN COBIT




Perbedaan ITIL & COBIT

COBIT atau Control OBjective of Information and related Technology merupakan sebuah pedoman bagi pengelolaan IT termasuk input, proses, output, serta process control yang terbagi kedalam 4 obyektif dan 34 area kunci. Masing-masing obyektif tersebut adalah: Planing & Organization (PO), Acquisition & Implementation (AI), Delivery & Support (DS) dan Monitoring.

Sedangkah ITIL merupakan sebuah kerangka pengelolaan layanan IT yang terbagi kedalam proses dan fungsi (lihat penjelasan tentang apa itu ITIL dalam artikel terpisah). Dua area/modul dalam ITIL, yaitu Service Support dan Delivery kemudian menjadi CORE dalam ITIL versi 2, yang kemudian kita kenal dengan IT Service Management.

Apabila dilihat dari posisi kedua pendekatan tersebut, maka dapat kita lihat hubungan secara langsung diantara Delivery & Support (COBIT) dan ITSM. Dimana COBIT mengatur masalah obyektif yang harus dicapai oleh sebuah organisasi dalam memberikan layanan IT, sedangkan ITIL merupakan best practice cara-cara pengelolaan IT untuk mencapai obyektif organisasi. Sehingga dapat dikatakan bahwa COBIT dan ITIL merupakan dua pendekatan dalam IT Governance dan tata kelola layanan teknologi informasi yang saling melengkapi. Apabila dibedah lebih jauh, relavansi ITIL tidak hanya berhenti di area Deliveri & Support, tetapi bisa kita petakan ke area COBIT lainnya.

Bagi anda yang sudah menggunakan COBIT sebagai standar kontrol terhadap pengelolaan IT, anda dapat juga mengimplementasikan ITIL dalam upaya meningkatkan tingkat kematangan IT perusahaan anda (Maturity Level). Bagi yang belum mengimplementasikannya dapat mengkombinasikan kedua pendekatan ini karena hubungannya satu dengan yang lain adalah saling melengkapi.






Referensi:


- https://id.wikipedia.org/wiki/ITIL


- http://aheva17.blogspot.co.id/2010/07/cobit.html


- http://itilindo.com/2009/03/17/posisi-itil-dan-cobit/