COBIT 2019
Build, Acquire and Implement – COBIT 2019

COBIT 2019 BAI02.03: BAI02.03 Manage requirements risk

The functional, technical and information-processing risks that come with the enterprise's requirements, the assumptions behind them and the solution put forward are identified, recorded, ranked and reduced: requirements risk affecting quality, function and technology is found (for example users not involved enough, expectations that cannot be met, developers building features nobody asked for, assumptions that do not hold, and requirements left incomplete); a suitable response is chosen; and each risk is analysed by estimating how likely it is and how it would affect budget and schedule, with the cost of the responses evaluated.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 1 control

  • 8.26 Application security requirements

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Build, Acquire and Implement – COBIT 2019

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.