COBIT 2019
Build, Acquire and Implement – COBIT 2019

COBIT 2019 BAI02.01: BAI02.01 Define and maintain business functional and technical requirements

Starting from the business case, the requirements (business information, functional, technical and control) across all initiatives needed for the intended outcomes are identified, ranked, specified and agreed: every stakeholder requirement, acceptance criteria included, is captured, ranked and recorded in an understandable way, on the understanding that requirements can change and grow more detailed as implementation advances; business requirements state how the difference between today's capability and the desired capability will be closed and how users will work with the solution; information, functional and technical requirements are specified and ranked on the basis of user experience design and confirmed stakeholder needs; requirements satisfy enterprise policies and standards, the architecture, I&T plans, internal and outsourced processes, security needs, regulation, privacy, continuity, business rules and quality; information control requirements deal with information risk and with legal, regulatory and contractual compliance; acceptance is confirmed for key aspects (business rules, user experience, information controls, continuity, compliance, auditability, ergonomics, operability, usability, safety, security and supporting documentation); scope, requirements and their changes are tracked and controlled across the life cycle; the procedure and repository used to define and maintain requirements are sized to the initiative's scale, complexity, objectives and risk; and every requirement is validated through peer review, model validation or an operational prototype.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 1 control

  • 8.26 Application security requirements

ISO 9001:2015 · 1 control

  • 8.3.3 Design and development inputs

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Build, Acquire and Implement – COBIT 2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.