| The Information Technology Infrastructure Library | | | | COBIT and ISO also provide guidance, key indicators, |
| (ITIL) is an industry-leading set of IT Service | | | | and controls for the definition of service-level |
| Management best practices. These best practices for | | | | agreements, capacity planning, availability |
| the support and delivery of IT services can help a | | | | management, and business continuity, which |
| company document IT processes. | | | | complement ITIL service delivery processes. |
| ITIL is part of the foundation of the COBIT model, | | | | IT organizations are under more pressure to meet |
| which defines control objectives for IT in support of | | | | the business goals. ITIL and COBIT can enable |
| business processes. | | | | organizations: |
| ITIL is about providing guidelines as to what should | | | | 1.Manage IT from a business perspective and achieve |
| be done and steps to trying to get best practices in | | | | business goals. 2.Put in place clear process goals, |
| place and COBIT is more about "proving and | | | | based on the organization's business goals 3.Ensure |
| establishing a set of objectives to show control. It's | | | | effective IT governance and control at the process |
| more of an audit and measurement tool to determine | | | | level, and enable IT to demonstrate that it meets or |
| if things were done right. | | | | exceeds the requirements. |
| The ITIL process documentation and COBIT control | | | | COBIT processes are focused on business |
| objectives are a powerful combination that can | | | | requirements, and provide guidance in determining |
| accelerate Sarbanes Oxley and BASEL II compliance | | | | what is sufficient to meet these requirements. ITIL |
| as well. | | | | defines best practice processes for ITSM and shows |
| ITIL is strong on delivery and support processes. It | | | | how to get there. It focuses on method and defines |
| describes how to structure operational processes but | | | | a more comprehensive set of processes than |
| is weak on security controls and processes. | | | | COBIT, providing a roadmap for building processes. |
| COBIT is focused on controls and metrics. It also | | | | With the combination of ITIL and COBIT, IT can |
| lacks a security component but provides a more | | | | meet business objectives and thus delivering higher |
| global view of IT processes at the IT organization | | | | quality business services at lower costs. |
| management principles than ITIL. | | | | |