Figure 9 Immediate High-Level Reporting – One of hundreds of existing reports – Easily customized

Figure 10 Heat Map Shows Residual and Inherent Risk – Accounting Oversight Ready

Figure 11 Source Documentation shows Regulation and Standards – Instantaneous regulatory background reporting
The Architecture
(This information is old but history matters.)
Evolution of ideas as demonstrated by most recent updates to CobiT 5, Delivering Business Benefits With COBIT: An Introduction to COBIT 5, By Derek Oliver, Ph.D., CISA, CISM, CRISC, and John Lainhart, CISA, CISM, CGEIT, CRISC, CIPP/G
Quoting directly from the online article, "The draft model was then stored in the metal safe repository, and the picture of the model was generated by the repository. The model reflects the structure of the COBIT 4.1 framework, IT Assurance Guide: Using COBIT and COBIT 4.1 Process Assessment Model Exposure Draft, with an extension as explained in the figure. The extension of some attributes in the assurance model is included to show how a model can be adapted to specific requirements (e.g., the support of an assessment process) and still keep the original model.
The model shows all the important terms, their properties, and their relationships. It can be used to teach, design, and structure the information base that will contain the model. This is not the metamodel, but it is what the authors wanted to express or show about the model. It is also only a draft or proof of concept of the architecture; however, it is a good basis from which to start and can be extended or changed easily for use in other intended purposes.
Beyond the descriptive function, the model is also intended to structure the information base where the instances of the model with the complete textual information are stored, maintained and documented."

This is the organic design created by Robin Basham as a UML for OASIS to describe the integration of continuous monitoring from the device and network up to the Process and Business Framework. Most of this design is reflected in every product we build and in our EnterpriseGRC Solutions SharePoint platform.
Figure 12 GRC Application Components

EnterpriseGRC Solutions is referencing common standard methodology and is not the creator of either CISSP or ISO 27001 guidance. [ii] © 2006 IT Governance Institute, COBIT® Mapping: Mapping of ISO/IEC 17799:2005 With COBIT® 4.0, with permission to reproduce sections of ISO/IEC 17799:2005, copyright 2005 the International Organization for Standardization (ISO), granted to ITGI by ISO.



Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics