The governing body informs leaders about the I&T governance principles and secures their support, buy-in and commitment; it steers the structures, processes and practices for governing I&T so they follow the agreed principles, decision-making model and levels of authority, and it defines what information is needed for well-founded decisions. In practice it communicates the principles and agrees with executive management how leadership will be kept informed and committed; sets up or delegates the governance structures; forms a board-level I&T governance body, or its equivalent, that makes sure information and technology are governed within enterprise governance; assigns who holds responsibility, authority and accountability for decisions about I&T; makes sure communication and reporting reach those who oversee and decide; directs staff to follow ethical and professional guidelines, with consequences that are known and enforced; and directs a reward system that fosters the culture wanted.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.