IT Governance, COBIT

COBIT 2019: Delivery, Services and Support (DSS)

The six processes of the DSS domain in COBIT 2019 structure the delivery of IT services, incident support, continuity, and security.

July 4, 2022 4MATT Insights

COBIT DSS (Deliver, Service, and Support) is the COBIT 2019 domain comprised of 6 processes that guide how IT should operate, handle incidents, and ensure the continuity and security of services delivered to the business. This article details each COBIT DSS process, its role in delivering IT services, and how it connects to the ServiceNow platform—complementing the APO, BAI, and EDM domains already published on the 4MATT blog.

Overview of COBIT DSS Processes

Process Name Main focus
DSS01 Managed Operations Operational execution and infrastructure monitoring
DSS02 Managed Service Requests and Incidents Call handling and resolution
DSS03 Managed Problems Root cause and recurrence prevention
DSS04 Managed Business Continuity BCP, DRP and operational resilience
DSS05 Managed Security Services Access, vulnerabilities, and security policies
DSS06 Managed Business Process Controls Data integrity and regulatory compliance

Detailed Process Description

DSS 01 – Managed Operations

Objective: Coordinate and execute internal and outsourced IT operational activities.

Guidelines:

  1. Execute standard operating procedures (SOPs).
  2. Continuously monitor the infrastructure.
  3. To ensure consistent delivery of IT products and services.

DSS 02 – Managed Service Requests and Incidents

Objective: To provide quick and effective responses to incidents and user requests.

  1. Register, categorize, and respond to calls.
  2. Diagnose and resolve incidents.
  3. Escalate to specialized teams when necessary.

This process relies directly on a good ITSM structure to reduce response time and maintain business productivity.

DSS 03 – Managed Problems

Objective: Identify the root cause of problems to prevent recurrence of incidents.

  1. Reduce operational costs associated with recurring failures.
  2. Improve service levels.
  3. Increase availability and user satisfaction.

Integrate problem management with a CMDB Structured analysis allows for much more precise impact analysis and fault tracking.

DSS 04 – Managed Business Continuity

Objective: Create and maintain business continuity plans (BCP) and disaster recovery plans (DRP).

  1. To ensure that critical processes are not interrupted.
  2. Adapt operations quickly to failures or disasters.
  3. Reduce operational risks in a structured way.

See how the COBIT 2019 APO domain It supports the strategic alignment that underpins operational continuity.

DSS 05 – Managed Security Services

Objective: To guarantee the protection of corporate information.

  1. Manage access and privileges.
  2. Monitor vulnerabilities and security incidents.
  3. Implement information security policies.

Learn more about Information security and compliance applied to IT operations.

DSS 06 – Managed Business Process Controls

Objective: Define and operate internal and external controls to ensure information integrity and security.

  1. Control data input and output.
  2. Monitor information processing.
  3. Ensure regulatory compliance.

This process interacts with the domain. COBIT 2019 BAI, responsible for building and implementing the controls defined here.

COBIT 2019 and ServiceNow: DSS running on the platform

Data Security System (DSS) processes don't just exist on paper—they need a platform to execute them with reliable data. ServiceNow Enables DSS02 (incidents and requests) via ITSM, DSS03 (problems) via integration with CMDB, and DSS05/DSS06 (security and controls) via GRC and SecOps modules. Implementing COBIT DSS with the support of a mature platform reduces manual compliance effort and creates end-to-end traceability between process, control, and evidence — with 4MATT, a ServiceNow Elite Partner in Brazil with over 80 certified specialists, responsible for the implementation and support of these capabilities.

Conclusion

The DSS domain of COBIT 2019 is fundamental for companies of all sizes to deliver IT services reliably, quickly, and securely, ensuring business continuity and alignment with corporate strategy. Organizations that treat COBIT DSS as an ongoing discipline—and not as a one-off audit exercise—tend to reduce recurring incidents and strengthen business area confidence in IT operations.

Companies that apply these processes:

  • They reduce incident response time.
  • They increase the availability of critical services.
  • They strengthen business continuity and operational resilience.
  • They improve compliance and information security.