COBIT 2019
Align, Plan and Organize – COBIT 2019

COBIT 2019 APO12.02: APO12.02 Analyze risk

The enterprise builds a well-founded picture of the I&T risk it actually faces, to inform risk decisions. The scope of the analysis is set with regard to all risk factors and to how critical assets are. I&T risk scenarios, loss exposures and reputational scenarios, including threats that compound, cascade or coincide, are developed and refreshed regularly. For each scenario the likely frequency and size of loss or gain are estimated, allowing for risk factors and the controls known to be in place. Current exposure is set against appetite and tolerance to find risk that is unacceptable or raised. Responses are proposed for any risk outside appetite and tolerance. High-level requirements are specified for the projects or programmes that will deliver the responses and for the key controls they require. Before the analysis and the business impact analysis are relied on for decisions they are validated, confirming they fit enterprise requirements and that estimates were properly calibrated. The costs and benefits of the response options (avoid, reduce, transfer or share, accept, exploit) are analysed to confirm which response is best.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 2 controls

  • P7 Principle 7: Identifies and analyzes risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Align, Plan and Organize – COBIT 2019

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.