• No se han encontrado resultados

CASETA DE ACCESO, CABINA ACÚSTICA Y ESCALERA DE EMERGENCIA subtotal azotea

D.9 ACARREO Y RETIROS DE MATERIALES PRODUCTO DE DEMOLICIONES EN CAMION DE

II. CASETA DE ACCESO, CABINA ACÚSTICA Y ESCALERA DE EMERGENCIA subtotal azotea

In addition, each process contains its own maturity model. Using the COBIT® maturity models, management can identify how well IT is being managed in their organization and compare that to what they know about their competitors and about the industry as a whole.

Several COBIT® processes contain control objectives or activities related to SQA. For example, the detailed control objectives of PO8 Manage Quality include, PO8.1 to “establish and maintain a QMS that provides a standard, formal and con- tinuous approach regarding quality management that is aligned with the business requirements…,“ PO8.6 to “define, plan and implement measurements to monitor continuing compliance to the QMS, as well as the value the QMS provides…,” and PO8.5 that requires that “an overall quality plan that promotes continuous improvement is maintained and communicated regularly.”

Conformance, or compliance, to COBIT®4.0 is not defined within the docu- ment itself. However, based on language in the document, and in related documents, it is reasonable to believe that conformance to COBIT®4.0 is achieved by an IT pro- cess that satisfies the detailed control objectives of one or more COBIT®processes, and the six generic process control requirements. Probably, the IT Assurance Guide will clarify conformance (or compliance) when it is released.

3.4

SQA in ITIL

®

The IT Infrastructure Library (ITIL®) is a library of products that presents best prac- tices for IT service management (ITSM). ITSM is what an organization does to pro- vide and support IT services “of a quality corresponding to the objectives of the business, and which meet the requirements and expectations of the customer” [39]. Each organization that follows an ITIL®publication is expected to implement the ITIL®processes in its own way.

ITIL®organizes ITSM best practices into generic processes. In most cases, a core ITIL®publication is a collection of topically related processes. Historically, two top- ics, service support and service delivery, have been the focal points around which ITIL®has been organized.

When this chapter was written, there were eight core ITIL® publications [40–47], Service Support, Service Delivery, Planning to Implement Service Manage- ment, Security Management, ICT Infrastructure Management, Application Man- agement, Business Perspective Volume 1, and Business Perspective Volume 2, and several complementary products (for example, Introduction to ITIL®[39], Software Asset Management [48], and ITIL® Small-Scale Implementation [49]). However, the material in the core publications was being rewritten, and repackaged in version 3 of ITIL®, as Service Strategy, Service Design, Service Transition, Service Opera- tion, and Continual Service Improvement, and released in June 2007.

ITIL®is a responsibility of the Office of Government Commerce (OGC) within the U.K. Treasury. For more information, see the ITIL®page at the OGC Web site [50]. ITIL®products are published by The Stationery Office (TSO) in London [51]. To learn more about ITIL®publications, or to purchase them directly, see [52].

The publication Service Support [40] presents processes for incident manage- ment, problem management, configuration management, change management, and release management. It also describes a service desk, but not as a process, rather as a part of an organization. Within ITIL®publications, a service desk is a group of peo- ple who carry out some or all activities of the ITIL®service support processes, par- ticularly incident management, release management, change management, and configuration management.

The ITIL®publication Service Delivery [41] describes processes for service level management, financial management, capacity management, IT service continuity management, and availability management.

Security management is still emerging as a profession of its own, so software- market-wide consensus about what it is, exactly, may not exist yet. However, within ITIL®, security management activities aim to provide an acceptable level of information confidentiality, integrity, and availability. Security management activi- ties are described in the publication Security Management [43].

Within ITIL®publications, the word “infrastructure” (sometimes replaced by “technical infrastructure”) means the collection of hardware and software compo- nents and services that underlie applications. Within ITIL®, “application” has a meaning that is very similar to the meaning of “information system.” The publica- tion ICT Infrastructure Management [44] describes four infrastructure manage- ment processes: design and planning, deployment, operations, and technical support.

The publication Planning to Implement Service Management [42] tackles the problems that organizations face when introducing IT service management prac- tices for the first time, or when improving service management practices that are already in place. It suggests a six-stage continuous service improvement program.

The ITIL®publication Application Management [45] presents a set of practices that integrate application development with service delivery and service support processes. The goal is to identify activities that increase the likelihood that, when application elements of the IT infrastructure are developed, application products that result will be well matched to the activities in the other ITIL®processes.

Many ITIL®processes in these publications have activities that SQA might sup- port or do, in some implementations, for example:

Monitoring the effectiveness of the incident cycle (during incident management);

Carrying out a configuration audit (during configuration management);Evaluating implemented changes (during change management);

Testing or accepting releases (during release management);Assessing ITSM processes (as described in [42]).

The two remaining core ITIL® publications, Business Perspective, Volume 1 [46], and Business Perspective, Volume 2 [47], aim to explain IT service customers 3.4 SQA in ITIL®

to IT service providers, with the goal of clarifying how the IT service providers can improve what they do.

“Conformance to ITIL®” is not defined within ITIL®itself, in the sense that the ITIL®publications do not define the conditions that would justify a claim of confor- mance to the library of core publications, or even a claim of conformance to the col- lection of all the processes that they define.

Some ITIL® processes, for example Change Management, include individual guidance on evaluating compliance with the practices that they document. But, most do not. And, OGC does not provide or accredit assessments of conformity, either to ITIL®as a whole or to individual ITIL®documents.

There are commercial firms who perform assessments of service management processes against the ITIL®model. Also, self-assessment tools for the same purpose can be downloaded (e.g., from itSMF). However, it is probably best to think of ITIL®simply as a collection of best practices that are intended for use with reason- able care, even with the help of professional advice in some situations.

Organizations that wish to demonstrate conformity to ITIL®processes can opt for certification against ISO/IEC 20000 instead. As the next section of this chapter explains, ISO/IEC 20000 is aligned with ITIL®.

ITIL®publications are sometimes used with the COBIT®standard. To compare ITIL®to COBIT®, ITIL® focuses on processes, while COBIT®focuses on control objectives. Implementing ITIL®processes can support the achievement of COBIT® objectives.

3.4.1 ISO/IEC 20000

ISO/IEC 20000 [53, 54] is a two-part standard for ITSM. It maps easily to ITIL®, because, in its original form, it was BS 15000, which was aligned with ITIL®by agreement between OGC [50], BSI [55], and itSMF [56].

ISO/IEC 20000-1:2005 [53] defines requirements. Clause 3 defines general management requirements, including responsibility requirements, documentation requirements, and requirements related to staff training and competence. Clause 4 adds requirements for a Plan (planning)-Do (implementation)-Check (monitoring and measuring)-Act (continuous improvement) cycle. See Chapter 2 for further elab- oration on a Plan-Do-Check-Act cycle. Clause 5 presents requirements for planning and implementing new or changed services.

Clause 6 of the standard specifies requirements for service-level management, service reporting, service continuity and availability management, budgeting and accounting for IT services, capacity management, and information security management.

Clauses 8, 9, and 10 present requirements for incident management, prob- lem management, configuration management, change management, and release management.

In clauses 6, 8, 9, and 10, the alignment between ITIL®and ISO/IEC 20000: 2005 is clear. It is planned that version 3 of ITIL®will continue the alignment. The intended relationship between the two standards is that ISO/IEC 20000:2005 will define requirements for ITSM, and ITIL®will present generic practices for achieving conformance to them.

Conformance to ISO/IEC 20000-1:2005 is not defined explicitly by the stan- dard. However, many provisions of the standard are expressed using “shall.” And according to ISO/IEC rules for writing an international standard, the verb form “shall” indicates requirements that must be followed (and that may not be violated) if conformance to the standard is to be achieved. So, conformance to the standard could be said to be achieved when these requirements are satisfied.

ISO/IEC 20000-2:2005 [54] does not contain requirements (so, conformance to this part of the standard is not defined). The clauses in ISO/IEC 20000-2:2005 track exactly with those in ISO/IEC 20000-1:2005. Each clause recommends or suggests several things that, while they are not required, would help to satisfy the related requirements in ISO/IEC 2000-1. More information on this collection of IT stan- dards is provided in Chapter 14.

Documento similar