COBIT 2019
Align, Plan and Organize – COBIT 2019

COBIT 2019 APO12.06: APO12.06 Respond to risk

When a risk materialises the enterprise responds promptly with effective measures that keep the size of the loss down. Plans are prepared, kept current and tested that set out exactly what to do if a risk event could trigger an incident in operations or development that is significant and would seriously harm the business, including routes for escalation across the enterprise. When an incident happens, the relevant plan is used to reduce its impact. Incidents are categorised, loss exposures are compared with tolerance thresholds, business impacts are communicated to decision makers and the risk profile is updated. Past adverse events, losses and opportunities that were missed are investigated for their root causes, and those root causes, any further response requirements and process improvements are passed to decision makers and built into the risk governance process.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Align, Plan and Organize – COBIT 2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.