COBIT 2019
Align, Plan and Organize – COBIT 2019

COBIT 2019 APO13.02: APO13.02 Define and manage an information security and privacy risk treatment plan

An information security plan sets out how information security risk is managed and kept consistent with enterprise strategy and architecture. Recommendations for improvement rest on business cases that have been approved; they are delivered as part of developing services and solutions and then run as an integral part of business operations. A risk treatment plan, consistent with strategic objectives and the architecture, names the most suitable management practices and security solutions, together with the resources, responsibilities and priorities needed to manage the risks identified. The architecture holds an inventory of the solution components that manage security-related risk. Proposals to carry out the plan are backed by business cases that address funding and roles. Input is provided to the design and development of the practices and solutions chosen. Training and awareness programmes on information security and privacy are put in place. Security and privacy procedures and controls are planned, designed, implemented and monitored in an integrated way so that security events are prevented, detected and responded to promptly. How effective the chosen practices are is measured so that results can be compared and repeated.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 2 controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Align, Plan and Organize – COBIT 2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.