COBIT 2019
Evaluate, Direct and Monitor (governance) – COBIT 2019

COBIT 2019 EDM03.01: EDM03.01 Evaluate risk management

The governing body keeps examining and evaluating how risk bears on the use of I&T now and in future, considers whether the enterprise's appetite for risk is suitable, and sees that risk to enterprise value arising from I&T is identified and managed. It understands the organisation and the context of its I&T risk; sets the risk appetite (how much I&T-related risk the enterprise is prepared to accept while pursuing its objectives) and the tolerance levels, which are deviations from that appetite acceptable for a limited time; checks that the I&T risk strategy fits the enterprise risk strategy and that the appetite stays below the enterprise's risk capacity; weighs I&T risk factors before strategic decisions are taken so that risk forms part of how decisions are made; judges risk management activities against how much I&T-related loss the enterprise can bear and how much its leadership will tolerate; and attracts and retains the people and skills that managing I&T risk requires.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • P7 Principle 7: Identifies and analyzes risk

ISO/IEC 38500:2024 · 1 control

  • 5.10.2 Risk governance: governance implications for use of IT

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Evaluate, Direct and Monitor (governance) – COBIT 2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.