APO01 | Managed I&T Management Framework | 0 |
APO02 | Managed Strategy | 0 |
APO07 | Managed Human Resources | 0 |
APO08 | Managed Relationships | 0 |
APO09 | Managed Service Agreements | 0 |
APO10 | Managed Vendors | 0 |
APO12 | Managed Risk | 0 |
APO13 | Managed Security | 0 |
APO14 | Managed Data | 0 |
BAI01 | Managed Programs | 0 |
BAI02 | Managed Requirements Definition | 0 |
BAI03 | Managed Solutions Identification and Build | 0 |
BAI06 | Managed IT Changes | 0 |
BAI07 | Managed IT Change Acceptance and Transitioning | 0 |
BAI08 | Managed Knowledge | 0 |
BAI09 | Managed Assets | 0 |
BAI10 | Managed Configuration | 0 |
COBIT-APO01 | Managed IT management framework | 0 |
COBIT-APO02 | Managed strategy | 0 |
COBIT-APO03 | Managed enterprise architecture | 0 |
COBIT-APO04 | Managed innovation | 0 |
COBIT-APO05 | Managed portfolio | 0 |
COBIT-APO06 | Managed budget and costs | 0 |
COBIT-APO07 | Managed human resources | 0 |
COBIT-APO08 | Managed relationships | 0 |
COBIT-APO09 | Managed service agreements | 0 |
COBIT-APO10 | Managed vendors | 0 |
COBIT-APO11 | Managed quality | 0 |
COBIT-APO12 | Managed risk | 0 |
COBIT-APO13 | Managed security | 0 |
COBIT-APO14 | Managed data | 0 |
COBIT-BAI01 | Managed programs | 0 |
COBIT-BAI02 | Managed requirements definition | 157 |
COBIT-BAI03 | Managed solutions identification and build | 0 |
COBIT-BAI04 | Managed availability and capacity | 52 |
COBIT-BAI05 | Managed organizational change | 0 |
COBIT-BAI06 | Managed IT changes | 0 |
COBIT-BAI07 | Managed IT change acceptance and transitioning | 0 |
COBIT-BAI08 | Managed knowledge | 0 |
COBIT-BAI09 | Managed assets | 0 |
COBIT-BAI10 | Managed configuration | 0 |
COBIT-BAI11 | Managed projects | 0 |
COBIT-DSS01 | Managed operations | 0 |
COBIT-DSS02 | Managed service requests and incidents | 0 |
COBIT-DSS03 | Managed problems | 0 |
COBIT-DSS04 | Managed continuity | 0 |
COBIT-DSS05 | Managed security services | 0 |
COBIT-DSS06 | Managed business process controls | 0 |
COBIT-EDM01 | Ensured governance framework setting and maintenance | 0 |
COBIT-EDM02 | Ensured benefits delivery | 0 |
COBIT-EDM03 | Ensured risk optimization | 0 |
COBIT-EDM04 | Ensured resource optimization | 0 |
COBIT-EDM05 | Ensured stakeholder engagement | 0 |
COBIT-MEA01 | Managed performance and conformance monitoring | 0 |
COBIT-MEA02 | Managed system of internal control | 0 |
COBIT-MEA03 | Managed compliance with external requirements | 0 |
COBIT-MEA04 | Managed assurance | 0 |
DSS01 | Managed Operations | 0 |
DSS02 | Managed Service Requests and Incidents | 0 |
DSS05 | Managed Security Services | 0 |
EDM01 | Ensured Governance Framework Setting and Maintenance | 0 |
EDM02 | Ensured Benefits Delivery | 0 |
EDM03 | Ensured Risk Optimization | 0 |
EDM04 | Ensured Resource Optimization | 0 |
EDM05 | Ensured Stakeholder Engagement | 0 |
MEA01 | Managed Performance and Conformance Monitoring | 0 |
MEA02 | Managed System of Internal Control | 0 |
MEA03 | Managed Compliance with External Requirements | 0 |
APO01 | APO01 Managed I&T Management Framework | 0 |
APO01.01 | APO01.01 Design the management system for enterprise I&T | 1 |
APO01.02 | APO01.02 Communicate management objectives, direction and decisions made | 3 |
APO01.03 | APO01.03 Implement management processes (to support the achievement of governance and management objectives) | 1 |
APO01.04 | APO01.04 Define and implement the organizational structures | 2 |
APO01.05 | APO01.05 Establish roles and responsibilities | 2 |
APO01.06 | APO01.06 Optimize the placement of the IT function | 1 |
APO01.07 | APO01.07 Define information (data) and system ownership | 1 |
APO01.08 | APO01.08 Define target skills and competencies | 2 |
APO01.09 | APO01.09 Define and communicate policies and procedures | 2 |
APO01.10 | APO01.10 Define and implement infrastructure, services and applications to support the governance and management system | 1 |
APO01.11 | APO01.11 Manage continual improvement of the I&T management system | 1 |
APO02 | APO02 Managed Strategy | 0 |
APO02.01 | APO02.01 Understand enterprise context and direction | 1 |
APO02.02 | APO02.02 Assess current capabilities, performance and digital maturity of the enterprise | 1 |
APO02.03 | APO02.03 Define target digital capabilities | 1 |
APO02.04 | APO02.04 Conduct a gap analysis | 0 |
APO02.05 | APO02.05 Define the strategic plan and road map | 1 |
APO02.06 | APO02.06 Communicate the I&T strategy and direction | 1 |
APO03 | APO03 Managed Enterprise Architecture | 0 |
APO03.01 | APO03.01 Develop the enterprise architecture vision | 0 |
APO03.02 | APO03.02 Define reference architecture | 1 |
APO03.03 | APO03.03 Select opportunities and solutions | 0 |
APO03.04 | APO03.04 Define architecture implementation | 0 |
APO03.05 | APO03.05 Provide enterprise architecture services | 0 |
APO04 | APO04 Managed Innovation | 0 |
APO04.01 | APO04.01 Create an environment conducive to innovation | 0 |
APO04.02 | APO04.02 Maintain an understanding of the enterprise environment | 0 |
APO04.03 | APO04.03 Monitor and scan the technology environment | 0 |
APO04.04 | APO04.04 Assess the potential of emerging technologies and innovative ideas | 0 |
APO04.05 | APO04.05 Recommend appropriate further initiatives | 0 |
APO04.06 | APO04.06 Monitor the implementation and use of innovation | 0 |
APO05 | APO05 Managed Portfolio | 0 |
APO05.01 | APO05.01 Determine the availability and sources of funds | 0 |
APO05.02 | APO05.02 Evaluate and select programs to fund | 0 |
APO05.03 | APO05.03 Monitor, optimize and report on investment portfolio performance | 0 |
APO05.04 | APO05.04 Maintain portfolios | 0 |
APO05.05 | APO05.05 Manage benefits achievement | 0 |
APO06 | APO06 Managed Budget and Costs | 0 |
APO06.01 | APO06.01 Manage finance and accounting | 0 |
APO06.02 | APO06.02 Prioritize resource allocation | 0 |
APO06.03 | APO06.03 Create and maintain budgets | 0 |
APO06.04 | APO06.04 Model and allocate costs | 0 |
APO06.05 | APO06.05 Manage costs | 0 |
APO07 | APO07 Managed Human Resources | 0 |
APO07.01 | APO07.01 Acquire and maintain adequate and appropriate staffing | 1 |
APO07.02 | APO07.02 Identify key IT personnel | 1 |
APO07.03 | APO07.03 Maintain the skills and competencies of personnel | 2 |
APO07.04 | APO07.04 Assess and recognize/reward employee job performance | 1 |
APO07.05 | APO07.05 Plan and track the usage of IT and business human resources | 0 |
APO07.06 | APO07.06 Manage contract staff | 1 |
APO08 | APO08 Managed Relationships | 0 |
APO08.01 | APO08.01 Understand business expectations | 1 |
APO08.02 | APO08.02 Align I&T strategy with business expectations and identify opportunities for IT to enhance the business | 1 |
APO08.03 | APO08.03 Manage the business relationship | 0 |
APO08.04 | APO08.04 Coordinate and communicate | 0 |
APO08.05 | APO08.05 Provide input to the continual improvement of services | 1 |
APO09 | APO09 Managed Service Agreements | 0 |
APO09.01 | APO09.01 Identify I&T services | 1 |
APO09.02 | APO09.02 Catalog I&T-enabled services | 0 |
APO09.03 | APO09.03 Define and prepare service agreements | 1 |
APO09.04 | APO09.04 Monitor and report service levels | 1 |
APO09.05 | APO09.05 Review service agreements and contracts | 1 |
APO10 | APO10 Managed Vendors | 0 |
APO10.01 | APO10.01 Identify and evaluate vendor relationships and contracts | 2 |
APO10.02 | APO10.02 Select vendors | 1 |
APO10.03 | APO10.03 Manage vendor relationships and contracts | 2 |
APO10.04 | APO10.04 Manage vendor risk. a | 1 |
APO10.05 | APO10.05 Monitor vendor performance and compliance | 2 |
APO11 | APO11 Managed Quality | 0 |
APO11.01 | APO11.01 Establish a quality management system (QMS) | 1 |
APO11.02 | APO11.02 Focus quality management on customers | 1 |
APO11.03 | APO11.03 Manage quality standards, practices and procedures and integrate quality management into key processes and solutions | 1 |
APO11.04 | APO11.04 Perform quality monitoring, control and reviews | 1 |
APO11.05 | APO11.05 Maintain continuous improvement | 1 |
APO12 | APO12 Managed Risk | 0 |
APO12.01 | APO12.01 Collect data | 1 |
APO12.02 | APO12.02 Analyze risk. a Develop a substantiated view on actual I&T risk, in support of risk decisions | 2 |
APO12.03 | APO12.03 Maintain a risk profile | 2 |
APO12.04 | APO12.04 Articulate risk | 2 |
APO12.05 | APO12.05 Define a risk management action portfolio | 1 |
APO12.06 | APO12.06 Respond to risk | 1 |
APO13 | APO13 Managed Security | 0 |
APO13.01 | APO13.01 Establish and maintain an information security management system (ISMS) | 1 |
APO13.02 | APO13.02 Define and manage an information security and privacy risk treatment plan | 1 |
APO13.03 | APO13.03 Monitor and review the information security management system (ISMS) | 1 |
APO14 | APO14 Managed Data | 0 |
APO14.01 | APO14.01 Define and communicate the organization’s data management strategy and roles and responsibilities | 1 |
APO14.02 | APO14.02 Define and maintain a consistent business glossary | 0 |
APO14.03 | APO14.03 Establish the processes and infrastructure for metadata management | 0 |
APO14.04 | APO14.04 Define a data quality strategy | 1 |
APO14.05 | APO14.05 Establish data profiling methodologies, processes and tools | 0 |
APO14.06 | APO14.06 Ensure a data quality assessment approach | 0 |
APO14.07 | APO14.07 Define the data cleansing approach | 0 |
APO14.08 | APO14.08 Manage the life cycle of data assets | 1 |
APO14.09 | APO14.09 Support data archiving and retention | 1 |
APO14.10 | APO14.10 Manage data backup and restore arrangements | 1 |
BAI01 | BAI01 Managed Programs | 0 |
BAI01.01 | BAI01.01 Maintain a standard approach for program management | 1 |
BAI01.02 | BAI01.02 Initiate a program | 0 |
BAI01.03 | BAI01.03 Manage stakeholder engagement | 0 |
BAI01.04 | BAI01.04 Develop and maintain the program plan | 0 |
BAI01.05 | BAI01.05 Launch and execute the program | 0 |
BAI01.06 | BAI01.06 Monitor, control and report on the program outcomes | 0 |
BAI01.07 | BAI01.07 Manage program quality | 0 |
BAI01.08 | BAI01.08 Manage program risk | 0 |
BAI01.09 | BAI01.09 Close a program | 0 |
BAI02 | BAI02 Managed Requirements Definition | 0 |
BAI02.01 | BAI02.01 Define and maintain business functional and technical requirements | 2 |
BAI02.02 | BAI02.02 Perform a feasibility study and formulate alternative solutions | 0 |
BAI02.03 | BAI02.03 Manage requirements risk | 1 |
BAI02.04 | BAI02.04 Obtain approval of requirements and solutions | 1 |
BAI03 | BAI03 Managed Solutions Identification and Build | 0 |
BAI03.01 | BAI03.01 Design high-level solutions | 2 |
BAI03.02 | BAI03.02 Design detailed solution components | 2 |
BAI03.03 | BAI03.03 Develop solution components | 1 |
BAI03.04 | BAI03.04 Procure solution components | 1 |
BAI03.05 | BAI03.05 Build solutions | 1 |
BAI03.06 | BAI03.06 Perform quality assurance (QA) | 1 |
BAI03.07 | BAI03.07 Prepare for solution testing | 1 |
BAI03.08 | BAI03.08 Execute solution testing | 2 |
BAI03.09 | BAI03.09 Manage changes to requirements | 1 |
BAI03.10 | BAI03.10 Maintain solutions | 1 |
BAI03.11 | BAI03.11 Define IT products and services and maintain the service portfolio | 0 |
BAI03.12 | BAI03.12 Design solutions based on the defined development methodology | 1 |
BAI04 | BAI04 Managed Availability and Capacity | 0 |
BAI04.01 | BAI04.01 Assess current availability, performance and capacity and a | 1 |
BAI04.02 | BAI04.02 Assess business impact | 1 |
BAI04.03 | BAI04.03 Plan for new or changed service requirements | 1 |
BAI04.04 | BAI04.04 Monitor and review availability and capacity | 1 |
BAI04.05 | BAI04.05 Investigate and address availability, performance and capacity issues | 1 |
BAI05 | BAI05 Managed Organizational Change | 0 |
BAI05.01 | BAI05.01 Establish the desire to change | 0 |
BAI05.02 | BAI05.02 Form an effective implementation team | 0 |
BAI05.03 | BAI05.03 Communicate desired vision | 0 |
BAI05.04 | BAI05.04 Empower role players and identify short-term wins | 0 |
BAI05.05 | BAI05.05 Enable operation and use | 0 |
BAI05.06 | BAI05.06 Embed new approaches | 0 |
BAI05.07 | BAI05.07 Sustain changes | 0 |
BAI06 | BAI06 Managed IT Changes | 0 |
BAI06.01 | BAI06.01 Evaluate, prioritize and authorize change requests | 3 |
BAI06.02 | BAI06.02 Manage emergency changes | 1 |
BAI06.03 | BAI06.03 Track and report change status | 1 |
BAI06.04 | BAI06.04 Close and document the changes | 2 |
BAI07 | BAI07 Managed IT Change Acceptance and Transitioning | 0 |
BAI07.01 | BAI07.01 Establish an implementation plan | 1 |
BAI07.02 | BAI07.02 Plan business process, system and data conversion | 0 |
BAI07.03 | BAI07.03 Plan acceptance tests | 1 |
BAI07.04 | BAI07.04 Establish a test environment | 1 |
BAI07.05 | BAI07.05 Perform acceptance tests | 1 |
BAI07.06 | BAI07.06 Promote to production and manage releases | 2 |
BAI07.07 | BAI07.07 Provide early production support | 0 |
BAI07.08 | BAI07.08 Perform a post-implementation review | 0 |
BAI08 | BAI08 Managed Knowledge | 0 |
BAI08.01 | BAI08.01 Identify and classify sources of information for governance and management of I&T | 0 |
BAI08.02 | BAI08.02 Organize and contextualize information into knowledge | 0 |
BAI08.03 | BAI08.03 Use and share knowledge | 0 |
BAI08.04 | BAI08.04 Evaluate and update or retire information | 0 |
BAI09 | BAI09 Managed Assets | 0 |
BAI09.01 | BAI09.01 Identify and record current assets | 1 |
BAI09.02 | BAI09.02 Manage critical assets | 2 |
BAI09.03 | BAI09.03 Manage the asset life cycle | 1 |
BAI09.04 | BAI09.04 Optimize asset value | 0 |
BAI09.05 | BAI09.05 Manage licenses | 1 |
BAI10 | BAI10 Managed Configuration | 0 |
BAI10.01 | BAI10.01 Establish and maintain a configuration model | 1 |
BAI10.02 | BAI10.02 Establish and maintain a configuration repository and baseline | 1 |
BAI10.03 | BAI10.03 Maintain and control configuration items | 1 |
BAI10.04 | BAI10.04 Produce status and configuration reports | 0 |
BAI10.05 | BAI10.05 Verify and review integrity of the configuration repository | 1 |
BAI11 | BAI11 Managed Projects | 0 |
BAI11.01 | BAI11.01 Maintain a standard approach for project management | 1 |
BAI11.02 | BAI11.02 Start up and initiate a project | 0 |
BAI11.03 | BAI11.03 Manage stakeholder engagement | 0 |
BAI11.04 | BAI11.04 Develop and maintain the project plan | 0 |
BAI11.05 | BAI11.05 Manage project quality | 1 |
BAI11.06 | BAI11.06 Manage project risk | 1 |
BAI11.07 | BAI11.07 Monitor and control projects | 0 |
BAI11.08 | BAI11.08 Manage project resources and work packages | 0 |
BAI11.09 | BAI11.09 Close a project or iteration | 0 |
DESIGN-FACTORS | Design factors, focus areas and capability levels | 0 |
DSS01 | DSS01 Managed Operations | 0 |
DSS01.01 | DSS01.01 Perform operational procedures | 1 |
DSS01.02 | DSS01.02 Manage outsourced I&T services | 1 |
DSS01.03 | DSS01.03 Monitor I&T infrastructure | 1 |
DSS01.04 | DSS01.04 Manage the environment | 1 |
DSS01.05 | DSS01.05 Manage facilities | 1 |
DSS02 | DSS02 Managed Service Requests and Incidents | 0 |
DSS02.01 | DSS02.01 Define classification schemes for incidents and service requests | 1 |
DSS02.02 | DSS02.02 Record, classify and prioritize requests and incidents | 1 |
DSS02.03 | DSS02.03 Verify, approve and fulfill service requests | 0 |
DSS02.04 | DSS02.04 Investigate, diagnose and allocate incidents | 1 |
DSS02.05 | DSS02.05 Resolve and recover from incidents | 1 |
DSS02.06 | DSS02.06 Close service requests and incidents | 1 |
DSS02.07 | DSS02.07 Track status and produce reports | 1 |
DSS03 | DSS03 Managed Problems | 0 |
DSS03.01 | DSS03.01 Identify and classify problems | 1 |
DSS03.02 | DSS03.02 Investigate and diagnose problems | 2 |
DSS03.03 | DSS03.03 Raise known errors | 0 |
DSS03.04 | DSS03.04 Resolve and close problems | 2 |
DSS03.05 | DSS03.05 Perform proactive problem management | 1 |
DSS04 | DSS04 Managed Continuity | 0 |
DSS04.01 | DSS04.01 Define the business continuity policy, objectives and scope | 1 |
DSS04.02 | DSS04.02 Maintain business resilience | 1 |
DSS04.03 | DSS04.03 Develop and implement a business continuity response | 2 |
DSS04.04 | DSS04.04 Exercise, test and review the business continuity plan (BCP) and disaster response plan (DRP) | 2 |
DSS04.05 | DSS04.05 Review, maintain and improve the continuity plans | 1 |
DSS04.06 | DSS04.06 Conduct continuity plan training | 1 |
DSS04.07 | DSS04.07 Manage backup arrangements | 2 |
DSS04.08 | DSS04.08 Conduct post-resumption review | 1 |
DSS05 | DSS05 Managed Security Services | 0 |
DSS05.01 | DSS05.01 Protect against malicious software | 1 |
DSS05.02 | DSS05.02 Manage network and connectivity security | 1 |
DSS05.03 | DSS05.03 Manage endpoint security | 1 |
DSS05.04 | DSS05.04 Manage user identity and logical access | 2 |
DSS05.05 | DSS05.05 Manage physical access to I&T assets | 1 |
DSS05.06 | DSS05.06 Manage sensitive documents and output devices | 1 |
DSS05.07 | DSS05.07 Manage vulnerabilities and monitor the infrastructure for security-related events | 1 |
DSS06 | DSS06 Managed Business Process Controls | 0 |
DSS06.01 | DSS06.01 Align control activities embedded in business processes with a. Percen enterprise objectives | 1 |
DSS06.02 | DSS06.02 Control the processing of information | 1 |
DSS06.03 | DSS06.03 Manage roles, responsibilities, access privileges and levels of authority | 2 |
DSS06.04 | DSS06.04 Manage errors and exceptions | 1 |
DSS06.05 | DSS06.05 Ensure traceability and accountability for information events. a. Num Ensure that business information can be traced to an originating b | 1 |
DSS06.06 | DSS06.06 Secure information assets | 1 |
EDM01 | EDM01 Ensured Governance Framework Setting and Maintenance | 0 |
EDM01.01 | EDM01.01 Evaluate the governance system | 1 |
EDM01.02 | EDM01.02 Direct the governance system | 1 |
EDM01.03 | EDM01.03 Monitor the governance system | 2 |
EDM02 | EDM02 Ensured Benefits Delivery | 0 |
EDM02.01 | EDM02.01 Establish the target investment mix | 1 |
EDM02.02 | EDM02.02 Evaluate value optimization | 1 |
EDM02.03 | EDM02.03 Direct value optimization | 1 |
EDM02.04 | EDM02.04 Monitor value optimization | 1 |
EDM03 | EDM03 Ensured Risk Optimization | 0 |
EDM03.01 | EDM03.01 Evaluate risk management | 2 |
EDM03.02 | EDM03.02 Direct risk management | 2 |
EDM03.03 | EDM03.03 Monitor risk management | 1 |
EDM04 | EDM04 Ensured Resource Optimization | 0 |
EDM04.01 | EDM04.01 Evaluate resource management | 1 |
EDM04.02 | EDM04.02 Direct resource management | 1 |
EDM04.03 | EDM04.03 Monitor resource management | 1 |
EDM05 | EDM05 Ensured Stakeholder Engagement | 0 |
EDM05.01 | EDM05.01 Evaluate stakeholder engagement and reporting requirements | 1 |
EDM05.02 | EDM05.02 Direct stakeholder engagement, communication and reporting | 2 |
EDM05.03 | EDM05.03 Monitor stakeholder engagement | 1 |
FRAMEWORK | COBIT 2019: the framework, its publications and what is held | 0 |
MEA01 | MEA01 Managed Performance and Conformance Monitoring | 0 |
MEA01.01 | MEA01.01 Establish a monitoring approach | 2 |
MEA01.02 | MEA01.02 Set performance and conformance targets | 2 |
MEA01.03 | MEA01.03 Collect and process performance and conformance data | 1 |
MEA01.04 | MEA01.04 Analyze and report performance | 2 |
MEA01.05 | MEA01.05 Ensure the implementation of corrective actions | 2 |
MEA02 | MEA02 Managed System of Internal Control | 0 |
MEA02.01 | MEA02.01 Monitor internal controls | 2 |
MEA02.02 | MEA02.02 Review effectiveness of business process controls | 1 |
MEA02.03 | MEA02.03 Perform control self-assessments | 1 |
MEA02.04 | MEA02.04 Identify and report control deficiencies | 2 |
MEA03 | MEA03 Managed Compliance With External Requirements | 0 |
MEA03.01 | MEA03.01 Identify external compliance requirements | 2 |
MEA03.02 | MEA03.02 Optimize response to external requirements | 1 |
MEA03.03 | MEA03.03 Confirm external compliance | 1 |
MEA03.04 | MEA03.04 Obtain assurance of external compliance | 1 |
MEA04 | MEA04 Managed Assurance | 0 |
MEA04.01 | MEA04.01 Ensure that assurance providers are independent and qualified | 2 |
MEA04.02 | MEA04.02 Develop risk-based planning of assurance initiatives | 2 |
MEA04.03 | MEA04.03 Determine the objectives of the assurance initiative | 1 |
MEA04.04 | MEA04.04 Define the scope of the assurance initiative | 2 |
MEA04.05 | MEA04.05 Define the work program for the assurance initiative | 1 |
MEA04.06 | MEA04.06 Execute the assurance initiative, focusing on design effectiveness | 2 |
MEA04.07 | MEA04.07 Execute the assurance initiative, focusing on operating effectiveness | 2 |
MEA04.08 | MEA04.08 Report and follow up on the assurance initiative | 2 |
MEA04.09 | MEA04.09 Follow up on recommendations and actions | 1 |
PRINCIPLES | The six principles of a governance system and the three principles of a governance framework | 0 |