Skip to content
- COBIT EDM01.01 - Evaluate the governance system.
- COBIT EDM01.02 - Direct the governance system.
- COBIT EDM01.03 - Monitor the governance system.
- COBIT EDM02.01 - Establish the target investment mix.
- COBIT EDM02.02 - Evaluate value optimization.
- COBIT EDM02.03 - Direct value optimization.
- COBIT EDM02.04 - Monitor value optimization.
- COBIT EDM03.01 - Evaluate risk management.
- COBIT EDM03.02 - Direct risk management.
- COBIT EDM03.03 - Monitor risk management.
- COBIT EDM04.01 - Evaluate resource management.
- COBIT EDM04.02 - Direct resource management.
- COBIT EDM04.03 - Monitor resource management.
- COBIT EDM05.01 - Evaluate stakeholder engagement and reporting requirements.
- COBIT EDM05.02 - Direct stakeholder engagement, communication and reporting.
- COBIT EDM05.03 - Monitor stakeholder engagement.
- COBIT APO01.01 - Design the management system for enterprise I&T.
- COBIT APO01.02 - Communicate management objectives, direction and decisions made.
- COBIT APO01.03 - Implement management processes
- COBIT APO01.04 - Define and implement the organizational structures.
- COBIT APO01.05 - Establish roles and responsibilities.
- COBIT APO01.06 - Optimize the placement of the IT function.
- COBIT APO01.07 - Define information (data) and system ownership.
- COBIT APO01.08 - Define target skills and competencies.
- COBIT APO01.09 - Define and communicate policies and procedures.
- COBIT APO01.10 - Define and implement infrastructure, services and applications to support the governance and management system.
- COBIT APO01.11 - Manage continual improvement of the I&T management system.
- COBIT APO02.01 - Understand enterprise context and direction.
- COBIT APO02.02 - Assess current capabilities, performance and digital maturity of the enterprise.
- COBIT APO02.03 - Define target digital capabilities.
- COBIT APO02.04 - Conduct a gap analysis.
- COBIT APO02.05 - Define the strategic plan and road map.
- COBIT APO02.06 - Communicate the I&T strategy and direction.
- COBIT APO03.01 - Develop the enterprise architecture vision.
- COBIT APO03.02 - Define reference architecture.
- COBIT APO03.03 - Select opportunities and solutions.
- COBIT APO03.04 - Define architecture implementation.
- COBIT APO03.05 - Provide enterprise architecture services.
- COBIT APO04.01 - Create an environment conducive to innovation.
- COBIT APO04.02 - Maintain an understanding of the enterprise environment.
- COBIT APO04.03 - Monitor and scan the technology environment.
- COBIT APO04.04 - Assess the potential of emerging technologies and innovative ideas.
- COBIT APO04.05 - Recommend appropriate further initiatives.
- COBIT APO04.06 - Monitor the implementation and use of innovation.
- COBIT APO05.01 - Determine the availability and sources of funds.
- COBIT APO05.02 - Evaluate and select programs to fund.
- COBIT APO05.03 - Monitor, optimize and report on investment portfolio performance.
- COBIT APO05.04 - Maintain portfolios.
- COBIT APO05.05 - Manage benefits achievement.
- COBIT APO06.01 - Manage finance and accounting.
- COBIT APO06.02 - Prioritize resource allocation.
- COBIT APO06.03 - Create and maintain budgets.
- COBIT APO06.04 - Model and allocate costs.
- COBIT APO06.05 - Manage costs.
- COBIT APO07.01 - Acquire and maintain adequate and appropriate staffing.
- COBIT APO07.02 - Identify key IT personnel.
- COBIT APO07.03 - Maintain the skills and competencies of personnel.
- COBIT APO07.04 - Assess and recognize/reward employee job performance.
- COBIT APO07.05 - Plan and track the usage of IT and business human resources.
- COBIT APO07.06 - Manage contract staff.
- COBIT APO08.01 - Understand business expectations.
- COBIT APO08.02 - Align I&T strategy with business expectations and identify opportunities for IT to enhance the business.
- COBIT APO08.03 - Manage the business relationship.
- COBIT APO08.04 - Coordinate and communicate.
- COBIT APO08.05 - Provide input to the continual improvement of services.
- COBIT APO09.01 - Identify I&T services.
- COBIT APO09.02 - Catalog I&T-enabled services.
- COBIT APO09.03 - Define and prepare service agreements.
- COBIT APO09.04 - Monitor and report service levels.
- COBIT APO09.05 - Review service agreements and contracts.
- COBIT APO10.01 - Identify and evaluate vendor relationships and contracts.
- COBIT APO10.02 - Select vendors.
- COBIT APO10.03 - Manage vendor relationships and contracts.
- COBIT APO10.04 - Manage vendor risk.
- COBIT APO10.05 - Monitor vendor performance and compliance.
- COBIT APO11.01 - Establish a quality management system (QMS).
- COBIT APO11.02 - Focus quality management on customers.
- COBIT APO11.03 - Manage quality standards, practices and procedures and integrate quality management into key processes and solutions.
- COBIT APO11.04 - Perform quality monitoring, control and reviews.
- COBIT APO11.05 - Maintain continuous improvement.
- COBIT APO12.01 - Collect data.
- COBIT APO12.02 - Analyze risk.
- COBIT APO12.03 - Maintain a risk profile.
- COBIT APO12.04 - Articulate risk.
- COBIT APO12.05 - Define a risk management action portfolio.
- COBIT APO12.06 - Respond to risk.
- COBIT APO13.01 - Establish and maintain an information security management system (ISMS).
- COBIT APO13.02 - Define and manage an information security risk treatment plan.
- COBIT APO13.03 - Monitor and review the information security management system (ISMS).
- COBIT APO14.01 - Define and communicate the organization's data management strategy and roles and responsibilities.
- COBIT APO14.02 - Define and maintain a consistent business glossary.
- COBIT APO14.03 - Establish the processes and infrastructure for metadata management.
- COBIT APO14.04 - Define a data quality strategy.
- COBIT APO14.05 - Establish data profiling methodologies, processes and tools.
- COBIT APO14.06 - Ensure a data quality assessment approach.
- COBIT APO14.07 - Define the data cleansing approach.
- COBIT APO14.08 - Manage the life cycle of data assets.
- COBIT APO14.09 - Support data archiving and retention.
- COBIT APO14.10 - Manage data backup and restore arrangements.
- COBIT BAI01.01 - Maintain a standard approach for program management.
- COBIT BAI01.02 - Initiate a program.
- COBIT BAI01.03 - Manage stakeholder engagement.
- COBIT BAI01.04 - Develop and maintain the program plan.
- COBIT BAI01.05 - Launch and execute the program.
- COBIT BAI01.06 - Monitor, control and report on the program outcomes.
- COBIT BAI01.07 - Manage program quality.
- COBIT BAI01.08 - Manage program risk.
- COBIT BAI01.09 - Close a program.
- COBIT BAI02.01 - Define and maintain business functional and technical requirements.
- COBIT BAI02.02 - Perform a feasibility study and formulate alternative solutions.
- COBIT BAI02.03 - Manage requirements risk.
- COBIT BAI02.04 - Obtain approval of requirements and solutions.
- COBIT BAI03.01 - Design high-level solutions.
- COBIT BAI03.02 - Design detailed solution components.
- COBIT BAI03.03 - Develop solution components.
- COBIT BAI03.04 - Procure solution components.
- COBIT BAI03.05 - Build solutions.
- COBIT BAI03.06 - Perform quality assurance (QA).
- COBIT BAI03.07 - Prepare for solution testing.
- COBIT BAI03.08 - Execute solution testing.
- COBIT BAI03.09 - Manage changes to requirements.
- COBIT BAI03.10 - Maintain solutions.
- COBIT BAI03.11 - Define IT products and services and maintain the service portfolio.
- COBIT BAI03.12 - Design solutions based on the defined development methodology.
- COBIT BAI04.01 - Assess current availability, performance and capacity and create a baseline.
- COBIT BAI04.02 - Assess business impact.
- COBIT BAI04.03 - Plan for new or changed service requirements.
- COBIT BAI04.04 - Monitor and review availability and capacity.
- COBIT BAI04.05 - Investigate and address availability, performance and capacity issues.
- COBIT BAI05.01 - Establish the desire to change.
- COBIT BAI05.02 - Form an effective implementation team.
- COBIT BAI05.03 - Communicate desired vision.
- COBIT BAI05.04 - Empower role players and identify short-term wins.
- COBIT BAI05.05 - Enable operation and use.
- COBIT BAI05.06 - Embed new approaches.
- COBIT BAI05.07 - Sustain changes.
- COBIT BAI06.01 - Evaluate, prioritize and authorize change requests.
- COBIT BAI06.02 - Manage emergency changes.
- COBIT BAI06.03 - Track and report change status.
- COBIT BAI06.04 - Close and document the changes.
- COBIT BAI07.01 - Establish an implementation plan.
- COBIT BAI07.02 - Plan business process, system and data conversion.
- COBIT BAI07.03 - Plan acceptance tests.
- COBIT BAI07.04 - Establish a test environment.
- COBIT BAI07.05 - Perform acceptance tests.
- COBIT BAI07.06 - Promote to production and manage releases.
- COBIT BAI07.07 - Provide early production support.
- COBIT BAI07.08 - Perform a post-implementation review.
- COBIT BAI08.01 - Identify and classify sources of information for governance and management of I&T.
- COBIT BAI08.02 - Organize and contextualize information into knowledge.
- COBIT BAI08.03 - Use and share knowledge.
- COBIT BAI08.04 - Evaluate and update or retire information.
- COBIT BAI09.01 - Identify and record current assets.
- COBIT BAI09.02 - Manage critical assets.
- COBIT BAI09.03 - Manage the asset life cycle.
- COBIT BAI09.04 - Optimize asset value.
- COBIT BAI09.05 - Manage licenses.
- COBIT BAI10.01 - Establish and maintain a configuration model.
- COBIT BAI10.02 - Establish and maintain a configuration repository and baseline.
- COBIT BAI10.03 - Maintain and control configuration items.
- COBIT BAI10.04 - Produce status and configuration reports.
- COBIT BAI10.05 - Verify and review integrity of the configuration repository.
- COBIT BAI11.01 - Maintain a standard approach for project management.
- COBIT BAI11.02 - Start up and initiate a project.
- COBIT BAI11.03 - Manage stakeholder engagement.
- COBIT BAI11.04 - Develop and maintain the project plan.
- COBIT BAI11.05 - Manage project quality.
- COBIT BAI11.06 - Manage project risk.
- COBIT BAI11.07 - Monitor and control projects.
- COBIT BAI11.08 - Manage project resources and work packages.
- COBIT BAI11.09 - Close a project or iteration.
- COBIT DSS01.01 - Perform operational procedures.
- COBIT DSS01.02 - Manage outsourced I&T services.
- COBIT DSS01.03 - Monitor I&T infrastructure.
- COBIT DSS01.04 - Manage the environment.
- COBIT DSS01.05 - Manage facilities.
- COBIT DSS02.01 - Define classification schemes for incidents and service requests.
- COBIT DSS02.02 - Record, classify and prioritize requests and incidents.
- COBIT DSS02.03 - Verify, approve and fulfill service requests.
- COBIT DSS02.04 - Investigate, diagnose and allocate incidents.
- COBIT DSS02.05 - Resolve and recover from incidents.
- COBIT DSS02.06 - Close service requests and incidents.
- COBIT DSS02.07 - Track status and produce reports.
- COBIT DSS03.01 - Identify and classify problems.
- COBIT DSS03.02 - Investigate and diagnose problems.
- COBIT DSS03.03 - Raise known errors.
- COBIT DSS03.04 - Resolve and close problems.
- COBIT DSS03.05 - Perform proactive problem management.
- COBIT DSS04.01 - Define the business continuity policy, objectives and scope.
- COBIT DSS04.02 - Maintain business resilience.
- COBIT DSS04.03 - Develop and implement a business continuity response.
- COBIT DSS04.04 - Exercise, test and review the business continuity plan (BCP) and disaster response plan (DRP).
- COBIT DSS04.05 - Review, maintain and improve the continuity plans.
- COBIT DSS04.06 - Conduct continuity plan training.
- COBIT DSS04.07 - Manage backup arrangements.
- COBIT DSS04.08 - Conduct post-resumption review.
- COBIT DSS05.01 - Protect against malicious software.
- COBIT DSS05.02 - Manage network and connectivity security.
- COBIT DSS05.03 - Manage endpoint security.
- COBIT DSS05.04 - Manage user identity and logical access.
- COBIT DSS05.05 - Manage physical access to I&T assets.
- COBIT DSS05.06 - Manage sensitive documents and output devices.
- COBIT DSS05.07 - Manage vulnerabilities and monitor the infrastructure for security-related events.
- COBIT DSS06.01 - Align control activities embedded in business processes with enterprise objectives.
- COBIT DSS06.02 - Control the processing of information.
- COBIT DSS06.03 - Manage roles, responsibilities, access privileges and levels of authority.
- COBIT DSS06.04 - Manage errors and exceptions.
- COBIT DSS06.05 - Ensure traceability and accountability for information events.
- COBIT DSS06.06 - Secure information assets.
- COBIT MEA01.01 - Establish a monitoring approach.
- COBIT MEA01.02 - Set performance and conformance targets.
- COBIT MEA01.03 - Collect and process performance and conformance data.
- COBIT MEA01.04 - Analyze and report performance.
- COBIT MEA01.05 - Ensure the implementation of corrective actions.
- COBIT MEA02.01 - Monitor internal controls.
- COBIT MEA02.02 - Review effectiveness of business process controls.
- COBIT MEA02.03 - Perform control self-assessments.
- COBIT MEA02.04 - Identify and report control deficiencies.
- COBIT MEA03.01 - Identify external compliance requirements.
- COBIT MEA03.02 - Optimize response to external requirements.
- COBIT MEA03.03 - Confirm external compliance.
- COBIT MEA03.04 - Obtain assurance of external compliance.
- COBIT MEA04.01 - Ensure that assurance providers are independent and qualified.
- COBIT MEA04.02 - Develop risk-based planning of assurance initiatives.
- COBIT MEA04.03 - Determine the objectives of the assurance initiative.
- COBIT MEA04.04 - Define the scope of the assurance initiative.
- COBIT MEA04.05 - Define the work program for the assurance initiative.
- COBIT MEA04.06 - Execute the assurance initiative, focusing on design effectiveness.
- COBIT MEA04.07 - Execute the assurance initiative, focusing on operating effectiveness.
- COBIT MEA04.08 - Report and follow up on the assurance initiative.
- COBIT MEA04.09 - Follow up on recommendations and actions.