COBIT Focus Area: Information & Technology Risk provides guidance related to information and technology (I&T) risk and how to apply COBIT to I&T risk practices. The publication is based on the COBIT core guidance for governance and management objectives, and it enhances the core guidance by highlighting risk-specific practices and activities as well as providing risk-specific metrics.
In COBIT 2019, a focus area describes a certain governance topic, domain or issue that can be addressed by a collection of governance and management objectives and their components. This publication describes I&T risk and includes considerations one should take into account when implementing or enhancing an organization’s risk management program.
Key publication details include:
- Provides a contemporary view on information and technology risk governance and management
- Clarifies roles of governance and management and shows how they relate to each other in the context of I&T risk
- Provides information to help more accurately identify I&T risk
- Detailed explanations so that one can better understand risk impact on the enterprise
- Knowledge of how to capitalize on investments related to I&T risk management practices
- Information on how effective I&T risk management optimizes value, with business process effectiveness and efficiency, improved quality and reduced waste and cost
- Additional information risk-specific activities, metrics and information flows.