COBIT 2019
Build, Acquire and Implement – COBIT 2019

COBIT 2019 BAI03.01: BAI03.01 Design high-level solutions

The solution's high-level design, covering technology, business processes and workflows, is produced and recorded with agreed phased or rapid agile techniques, kept consistent with the I&T strategy and the enterprise architecture, and involves the business process owner: a high-level specification turns the proposed solution into a design for processes, workflows, supporting services, applications, information stores and infrastructure that satisfies business and enterprise architecture needs; qualified user experience designers and IT specialists make sure the design makes the best use of the technology proposed; the design follows the organisation's design standards, with detail suited to the solution and the development method chosen, and is consistent with the strategies of the business, the enterprise and I&T, with the architecture, the security and privacy plan and applicable law; and once quality assurance has approved it, the final high-level design goes to stakeholders and the sponsor or process owner for approval against agreed criteria, and it continues to evolve during the project as understanding improves.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 1 control

  • 8.27 Secure system architecture and engineering principles

ISO 9001:2015 · 1 control

  • 8.3.2 Design and development planning

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Build, Acquire and Implement – COBIT 2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.