COBIT 2019
Evaluate, Direct and Monitor (governance) – COBIT 2019

COBIT 2019 EDM03.02: EDM03.02 Direct risk management

The governing body directs that risk management practices be put in place so that there is reasonable confidence that I&T risk is managed appropriately and that the I&T risk actually faced stays within the appetite the board has set. The I&T risk strategy is translated into, and built into, risk management practices and operations. Plans for communicating about risk at every level are developed. Mechanisms are put in place to react fast when risk changes and to report it at once to the right management level, following agreed escalation principles that say what is reported, when, where and in what way. Anyone may raise risks, opportunities, issues and concerns with the right party whenever they arise; risk is handled under the policies and procedures the enterprise has published, and passed up to those who decide. The main goals and metrics for governing and managing risk, and how they are to be captured and reported, are identified and approved.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 1 control

ISO/IEC 38500:2024 · 1 control

  • 5.10.2 Risk governance: governance implications for use of IT

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Evaluate, Direct and Monitor (governance) – COBIT 2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.