Writing Standards

Procedures are written in a clear, concise, and easily understood manner. Procedures document business processes (administrative and operational) and their controls. Procedures are created by upper and middle management as a means to translate policy to practice.

Change Requirements

Procedures, represented as processes, work instructions, standard operating procedures, work-specific training materials, and production support procedures (i.e., RunBooks), are dynamic, changing to fit current business operational practices. They must reflect the regular changes in business focus and environment. Reviews and updates of procedures are essential if they are to be relevant. Therefore, COMPANY provides notice to business management of all changes and new instances of process.  Both internal and external auditors will review procedures to identify, evaluate, and thereafter test controls over business processes. Given this knowledge, it is the responsibility of the process owner to keep current any process documentation and to notify the process librarian of any process change via This email address is being protected from spambots. You need JavaScript enabled to view it..

Additionally, part of change approval includes validation that all training and support procedures are current.)

Key Controls

The controls embedded in procedures are evaluated to ensure that they fulfill necessary control objectives while making the process as efficient and practical as possible. Some controls are designated as "key" and represent reported controls evidence in support of COMPANY regulatory attestation. Where operational practices do not match documented procedures or where documented procedures do not exist, it is difficult (for management and auditors) to identify controls and ensure that they are in continuous operation. While not all situations of this type represent control failure, each situation requires review and response based on the risk to safe and effective process management.

Documentation is a key control in that proper documentation directly supports every aspect of COMPANY control framework. The absence of documented process is a risk to operations and to COMPANY. Failure to properly document control procedures is an indication of management and control deficiencies.

NOTE: Missing or incomplete critical process documentation is not tolerated as an acceptable business practice.

Key control objectives are mapped to documentation and other evidence of control. Currently, the tool to manage this is [Name of core product or service].

Data Classification and Data Owners

The CobiT Planning and Organization Control objective "Define the Information Architecture, 2.3 Data Classification Scheme" requires a general classification framework established with regard to placement of data in information classes (i.e., security categories) as well as allocation of ownership. The "access rules", as in who can access what type of data as well as the restrictions over where that data may reside, on a per classification basis, should be appropriately defined. This is a co-dependency on Security and Security Administration, where Process assists in the implementation of classification standards, and access is further supervised and implemented through Security programs.

Process Librarians and Data Owners are dependent upon the accurate "classification of information assets" as defined by the Security Policy. End-user managers and security administrators require classifications to accurately determine who should be able to access what. The Process Librarian assists in the design of file share information, whereas the Data Owner is accountable for the classification and administration of its use. The Process Librarian assists the business to manage data assets by location and classification. The Process Librarian further supports requirements to have an information inventory of internal processes and work products.

Naming Conventions

Naming conventions are a part of the COMPANY's overall security design and are an integral part of information asset accounting. In accordance with an approved set of access rules stipulating users (or groups of users) authorized to access a resource (such as a dataset or file) and at what level (such as read or update) the access control mechanism applies these rules whenever a user attempts to access or use a protected resource. Data is maintained by location such that access is appropriately restricted.

These general naming conventions and associated files are required in a computer environment to establish and maintain personal accountability and segregation of duties in the access of data. The owners of the data or application, with the help of the security officer and process librarian, establish the name of files and subfolders for their business information. It is important to establish naming conventions that both promote the implementation of efficient access rules and simplify security administration. Naming conventions for system resources are an important prerequisite for the efficient administration of security controls.

Process Engineering Key Controls and Risks can be reviewed in Process Documentation Compliance Control - CobiT Function - CobiT Detail Objective and Risks and Associated Controls.

User roles

Main Menu