COBIT5Enabling APO12
COBIT5Enabling APO12
Area: Management
APO12 Manage Risk Domain: Align, Plan and Organise
Process Description
Continually identify, assess and reduce IT-related risk within levels of tolerance set by enterprise executive management.
Process Purpose Statement
Integrate the management of IT-related enterprise risk with overall ERM, and balance the costs and benefits of managing
IT-related enterprise risk.
The process supports the achievement of a set of primary IT-related goals:
IT-related Goal Related Metrics
02 IT compliance and support for business compliance with external laws s #OST OF )4 NON COMPLIANCE INCLUDING SETTLEMENTS AND FINES AND THE
and regulations impact of reputational loss
s .UMBER OF )4 RELATED NON COMPLIANCE ISSUES REPORTED TO THE BOARD OR
causing public comment or embarrassment
s .UMBER OF NON COMPLIANCE ISSUES RELATING TO CONTRACTUAL AGREEMENTS
107
: ENABLING PROCESSES
Head IT Administration
Chief Executive Officer
Chief Financial Officer
Business Executives
Head IT Operations
Head Development
Architecture Board
Chief Risk Officer
Service Manager
Head Architect
Privacy Officer
Compliance
Board
Audit
Key Management Practice
APO12.01
Align, Plan and Organise
I R R R R I C C A R R R R R R R R
Collect data.
APO12.02
I R C R C I R R A C C C C C C C C
Analyse risk.
APO12.03
I R C A C I R R R C C C C C C C C
Maintain a risk profile.
APO12.04
I R C R C I C C A C C C C C C C C
Articulate risk.
APO12.05
Define a risk management I R C A C I C C R C C C C C C C C
action portfolio.
APO12.06
I R R R R I C C A R R R R R R R R
Respond to risk.
108
CHAPTER 5
COBIT 5 PROCESS REFERENCE GUIDE CONTENTS
109
: ENABLING PROCESSES
outsourcers, and document the dependency on IT service management processes and IT infrastructure resources.
2. Determine and agree on which IT services and IT infrastructure resources are essential to sustain the operation of business processes. Analyse
dependencies and identify weak links.
3. Aggregate current risk scenarios by category, business line and functional area.
4. On a regular basis, capture all risk profile information and consolidate it into an aggregated risk profile.
5. Based on all risk profile data, define a set of risk indicators that allow the quick identification and monitoring of current risk and risk trends.
6. Capture information on IT risk events that have materialised, for inclusion in the IT risk profile of the enterprise.
7. Capture information on the status of the risk action plan, for inclusion in the IT risk profile of the enterprise.
Management Practice Inputs Outputs
APO12.04 Articulate risk. From Description Description To
Provide information on the current state of IT-related
Risk analysis and EDM03.03
exposures and opportunities in a timely manner to all
risk profile reports for EDM05.02
required stakeholders for appropriate response.
stakeholders APO10.04
MEA02.08
Review results of EDM03.03
third-party risk APO10.04
assessments MEA02.01
Opportunities for EDM03.03
acceptance
of greater risk
Activities
1. Report the results of risk analysis to all affected stakeholders in terms and formats useful to support enterprise decisions. Wherever possible, include
probabilities and ranges of loss or gain along with confidence levels that enable management to balance risk-return.
2. Provide decision makers with an understanding of worst-case and most-probable scenarios, due diligence exposures, and significant reputation, legal
or regulatory considerations.
3. Report the current risk profile to all stakeholders, including effectiveness of the risk management process, control effectiveness, gaps, inconsistencies,
redundancies, remediation status, and their impacts on the risk profile.
2EVIEW THE RESULTS OF OBJECTIVE THIRD PARTY ASSESSMENTS INTERNAL AUDIT AND QUALITY ASSURANCE REVIEWS AND MAP THEM TO THE RISK PROFILE 2EVIEW
identified gaps and exposures to determine the need for additional risk analysis.
5. On a periodic basis, for areas with relative risk and risk capacity parity, identify IT-related opportunities that would allow the acceptance of greater risk
and enhanced growth and return.
Management Practice Inputs Outputs
APO12.05 Define a risk management From Description Description To
action portfolio.
0ROJECT PROPOSALS FOR APO02.02
Manage opportunities to reduce risk to an acceptable
reducing risk APO13.02
level as a portfolio.
Activities
1. Maintain an inventory of control activities that are in place to manage risk and that enable risk to be taken in line with risk appetite and tolerance.
Classify control activities and map them to specific IT risk statements and aggregations of IT risk.
2. Determine whether each organisational entity monitors risk and accepts accountability for operating within its individual and portfolio tolerance levels.
$EFINE A BALANCED SET OF PROJECT PROPOSALS DESIGNED TO REDUCE RISK ANDOR PROJECTS THAT ENABLE STRATEGIC ENTERPRISE OPPORTUNITIES CONSIDERING
COSTBENEFITS EFFECT ON CURRENT RISK PROFILE AND REGULATIONS
110
CHAPTER 5
COBIT 5 PROCESS REFERENCE GUIDE CONTENTS
111