COBIT 2019
Monitor, Evaluate and Assess – COBIT 2019

COBIT 2019 MEA02.02: MEA02.02 Review effectiveness of business process controls

How controls operate, including monitoring and testing evidence, is reviewed to make sure the controls inside business processes work effectively, with activities that keep evidence of effectiveness through means such as periodic tests, ongoing monitoring, independent assessments, command and control centres and network operations centres, so that the evidence assures internal and external stakeholders: the risk to organisational objectives is understood and prioritised; key controls are identified, together with a strategy fit for validating them; the information that shows whether the control environment is working effectively is identified; evidence of control effectiveness is retained; and cost-effective procedures gather that information in keeping with information quality criteria.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Monitor, Evaluate and Assess – COBIT 2019

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.