COBIT 2019
Build, Acquire and Implement – COBIT 2019

COBIT 2019 BAI06.01: BAI06.01 Evaluate, prioritize and authorize change requests

Every change request is evaluated for its effect on business processes and I&T services and for whether it would harm the operational environment or bring unacceptable risk, and changes are logged, prioritised, categorised, assessed, authorised, planned and scheduled: process owners and IT raise formal change requests for processes, infrastructure, systems or applications, all changes come only through change management, and requests are pre-screened to spot standard changes; requests are categorised (business process, operating systems, infrastructure, applications, networks, packaged software) and linked to the configuration items they affect; priority is set by business and technical requirements, resources, and legal, regulatory and contractual reasons; each change is formally approved, as fits the case, by process owners, by service managers and by technical IT stakeholders, and frequent low-risk changes are pre-approved as standard changes; approved changes are planned and scheduled; each request is assessed in a structured way, analysing the effect on processes, infrastructure, systems, applications, continuity plans and service providers so every affected component is found; and the effect of contracted providers on change management is taken into account, including how their processes are integrated with the enterprise's own.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • P11 Principle 11: Selects and develops general controls over technology

ISO 27001:2022 · 1 control

  • 8.32 Change management

ISO 9001:2015 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Build, Acquire and Implement – COBIT 2019

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.