COBIT 2019: what it asks of an approval matrix
The COBIT practices that name levels of authority and transaction limits outright, segregate origination from approval, and reduce reliance on a single person.
Quoted for every matrix.
Approval families anchored here
40COBIT 2019: every clause cited, quoted
9 of the 231 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
COBIT APO01.05 Establish roles and responsibilitiesRoles and responsibilities for enterprise I&T are defined and communicated, including authority levels, responsibilities and accountability: I&T-related roles and responsibilities for all personnel are established, agreed and communicated in line with business needs, with responsibilities and accountabilities clearly delineated, especially for decision making and approvals; continuity requirements including staff backup and cross-training shape the roles; up-to-date contact information and role descriptions feed the service continuity process; role descriptions require adherence to management policies and procedures, the code of ethics and professional practice; accountability is defined through the roles; roles are structured so that no single role can compromise a critical process; and supervisory practices confirm that roles are properly exercised, that everyone has the authority and resources to perform them and that performance is reviewed.
Where matrices usually fall short: Approval authority exercised by people whose role description does not grant it; One role able to initiate, approve and execute a critical process
Source: COBIT 2019
COBIT APO07.02 Identify key IT personnelKey IT personnel are identified and reliance on any single individual performing a critical job function is minimised through knowledge capture, knowledge sharing, succession planning and staff backup: guidelines set a minimum annual vacation for key individuals as a security precaution, appropriate actions are taken on job changes and especially terminations, documentation, knowledge sharing, succession planning, backup, cross-training and job rotation reduce single-person dependence, and staff backup plans are tested regularly.
Where matrices usually fall short: Critical function that only one person can perform; Backup named but never tested
Source: COBIT 2019
COBIT APO10.03 Manage vendor relationships and contractsThe supplier relationship is formalised and managed for each supplier, contracts and service delivery are managed, maintained and monitored, and new or changed contracts conform to enterprise standards and legal and regulatory requirements: relationship owners are assigned and accountable for service quality; a formal communication and review process sets interactions and schedules; formal contracts are agreed, managed, maintained and renewed in conformance with standards and law; contracts with key service vendors provide for review of the vendor's site, practices and controls by management or independent third parties, with independent audit and assurance agreed; disputes are handled through established procedures after relationship and communication have been tried; roles and responsibilities are formalised per vendor, with a lead contractor role considered where several vendors combine to deliver a service; and the relationship's effectiveness is evaluated with improvements defined, communicated and agreed.
Where matrices usually fall short: Key vendor contract with no right to audit; Multi-vendor service with no lead accountable for the whole
Source: COBIT 2019
COBIT BAI06.01 Evaluate, prioritize and authorize change requestsAll requests for change are evaluated to determine their impact on business processes and I&T services and to assess whether the change will adversely affect the operational environment and introduce unacceptable risk, and changes are logged, prioritised, categorised, assessed, authorised, planned and scheduled: formal change requests let process owners and IT request changes to processes, infrastructure, systems or applications, with all changes arising only through the change management process and pre-screened for standard changes; requests are categorised (business process, infrastructure, operating systems, networks, applications, packaged software) and related to affected configuration items; they are prioritised on business and technical requirements, resources and legal, regulatory and contractual reasons; each change is formally approved by process owners, service managers and IT technical stakeholders as appropriate, with low-risk frequent changes pre-approved as standard; approved changes are planned and scheduled; every request is evaluated in a structured way with impact analysis on processes, infrastructure, systems, applications, continuity plans and service providers so that all affected components are identified; and the effect of contracted providers on change management is considered, including integration of their processes into the enterprise's.
Where matrices usually fall short: Changes made outside the process by administrators with direct access; Impact analysis that ignores the continuity plan and outsourced components
Source: COBIT 2019
COBIT BAI06.02 Manage emergency changesEmergency changes are carefully managed to minimise further incidents, controlled and made securely, and assessed and authorised appropriately after the change: what constitutes an emergency change is defined; a documented procedure declares, assesses, preliminarily approves, authorises after the change and records emergency changes; all emergency access arrangements for changes are appropriately authorised, documented and revoked after the change is applied; and all emergency changes are monitored with post-implementation reviews involving all concerned parties, considering root causes such as problems with business processes, application development, infrastructure, testing or the environment and initiating corrective action.
Where matrices usually fall short: Emergency access left in place after the change; Emergencies used as a route around normal change approval
Source: COBIT 2019
COBIT DSS05.04 Manage user identity and logical accessAll users have information access rights in accordance with business requirements, coordinated with business units that manage their own access rights within processes: access rights follow business function, process requirements and security policy, with identity and access management aligned to defined roles and responsibilities and the principles of least privilege, need to know and need to have; all changes to access rights (creation, modification, deletion) are administered promptly on approved and documented transactions authorised by designated management; privileged accounts are segregated, reduced to the minimum necessary and actively managed with all their activity monitored; all information processing activities are uniquely identified by functional role with roles consistently defined across business units including those defined by the business within applications; all access is authenticated on the individual's role or business rules; all users, internal, external and temporary, and their activity on applications, infrastructure, operations, development and maintenance are uniquely identifiable; an audit trail of access is kept according to sensitivity and regulation; and management regularly reviews all accounts and privileges.
Where matrices usually fall short: Shared administrator accounts; Leavers' accounts still active weeks later; Access reviews signed without the reviewer checking
Source: COBIT 2019
COBIT DSS06.02 Control the processing of informationThe execution of business process activities and related controls is operated on enterprise risk so that information processing is valid, complete, accurate, timely and secure, reflecting legitimate and authorised business use: the originator of transactions is authenticated and their authority verified; duties are segregated between origination and approval; transactions are verified as accurate, complete and valid through controls such as sequence, limit, range, validity, reasonableness, table look-ups, existence, key verification, check digit, completeness, duplicate and logical relationship checks and time edits, with validation rules and criteria reviewed periodically; erroneously input data are corrected and resubmitted without compromising original authorisation levels, retaining original source documents for reconstruction; data integrity and validity are maintained through the processing cycle with erroneous transactions not disrupting valid ones; output is handled in an authorised manner, delivered to the right recipient, protected in transmission and verified for accuracy and completeness; data integrity is maintained through unexpected interruptions and confirmed after failures; and transaction data passed between applications and functions inside or outside the enterprise are checked for proper addressing, authenticity of origin and integrity of content, with authentication and integrity protection in transit.
Where matrices usually fall short: One person able to originate and approve a payment; Interface files accepted without checking origin or integrity
Source: COBIT 2019
COBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authorityBusiness roles, responsibilities, levels of authority and segregation of duties supporting the process objectives are managed, and access to all information assets related to business processes is authorised: roles and responsibilities follow approved job descriptions and process activities; levels of authority for approving transactions, transaction limits and other decisions follow approved job roles; sensitive activities are allocated so that duties are clearly segregated; access rights and privileges are the minimum needed for predefined job roles, removed or revised immediately on role change or termination; regular awareness and training cover roles, responsibilities, the importance of controls and the security, integrity, confidentiality and privacy of information; administrative privileges are secured, tracked and controlled to prevent misuse; and access control definitions, logs and exception reports are periodically reviewed so that privileges remain valid and aligned with current staff and roles.
Where matrices usually fall short: Transaction limits not enforced in the system; Access accumulated across role changes
Source: COBIT 2019
COBIT MEA02.01 Monitor internal controlsThe I&T control environment and control framework are continuously monitored, benchmarked and improved to meet organisational objectives: the boundaries of the internal control system are identified, including how controls cover outsourced and offshore development or production; the status of external service providers' internal controls is assessed and their compliance with legal, regulatory and contractual obligations confirmed; monitoring and evaluation follow organisational governance standards and industry-accepted frameworks and practices, including monitoring of controls' performance and the control environment; control exceptions are promptly reported, followed up and analysed, with corrective actions prioritised and implemented according to the risk profile and recurring exceptions raised for management attention; independent evaluations by internal audit or peers are considered; the control system is maintained against ongoing change in business and I&T risk, the control environment and processes, with gaps evaluated and recommended for improvement; and the control framework's performance is regularly evaluated against industry standards and good practice with a continuous improvement approach considered.
Where matrices usually fall short: Outsourced processing outside the boundary of the control system; Same exception recurring without escalation
Source: COBIT 2019