COBIT 4.1
© 2007 IT Governance Institute. All rights reserved. www.itgi.org
180
COBIT 3
rd
Edition COBIT 4.1
PO1 Define a strategic IT plan.
1.1 IT as part of the 1.4
organisation’s long- and
short-range plan
1.2 IT long-range plan 1.4
1.3 IT long-range planning 1.4
—approach and structure
1.4 IT long-range plan changes 1.4
1.5 Short-range planning 1.5
for the IT function
1.6 Communication of IT plans 1.4
1.7 Monitoring and 1.3
evaluating of IT plans
1.8 Assessment of existing 1.3
systems
PO2 Define the information architecture.
2.1 Information architecture 2.1
model
2.2 Corporate data dictionary 2.2
and data syntax rules
2.3 Data classification scheme 2.3
2.4 Security levels 2.3
PO3 Determine technological direction.
3.1 Technological 3.1
infrastructure planning
3.2 Monitor future trends 3.3
and regulations.
3.3 Technological 3.1
infrastructure contingency
3.4 Hardware and software 3.1, AI3.1
acquisition plans
3.5 Technology standards 3.4, 3.5
PO4 Define the IT organisation and
relationships.
4.1 IT planning or steering 4.3
committee
4.2 Organisational placement 4.4
of the IT function
4.3 Review of organisational 4.5
achievements
4.4 Roles and responsibilities 4.6
4.5 Responsibility for quality 4.7
assurance
4.6 Responsibility for 4.8
logical and physical security
4.7 Ownership and 4.9
custodianship
4.8 Data and system 4.9
ownership
4.9 Supervision 4.10
4.10 Segregation of duties 4.11
4.11 IT staffing 4.12
4.12 Job or position 4.6
descriptions for IT staff
4.13 Key IT personnel 4.13
4.14 Contracted staff 4.14
policies and procedures
4.15 Relationships 4.15
PO5 Manage the IT investment.
5.1 Annual IT operating 5.3
budget
COBIT 3
rd
Edition COBIT 4.1
5.2 Cost and benefit monitoring 5.4
5.3 Cost and benefit 1.1, 5.3, 5.4,
justification 5.5
PO6 Communicate management aims and
direction.
6.1 Positive information 6.1
control environment
6.2 Management’s 6.3, 6.4, 6.5
responsibility for policies
6.3 Communication of 6.3, 6.4, 6.5
organisation policies
6.4 Policy implementation 6.4
resources
6.5 Maintenance of policies 6.3, 6.4, 6.5
6.6 Compliance with policies, 6.3, 6.4, 6.5
procedures and standards
6.7 Quality commitment 6.3, 6.4, 6.5
6.8 Security and internal 6.2
control framework policy
6.9 Intellectual property rights 6.3, 6.4, 6.5
6.10 Issue-specific policies 6.3, 6.4, 6.5
6.11 Communication of IT 6.3, 6.4, 6.5
security awareness
PO7 Manage human resources.
7.1 Personnel recruitment 7.1
and promotion
7.2 Personnel qualifications 7.2
7.3 Roles and responsibilities 7.4
7.4 Personnel training 7.5
7.5 Cross-training or 7.6
staff backup
7.6 Personnel clearance
procedures 7.7
7.7 Employee job 7.8
performance evaluation
7.8 Job change and termination 7.8
PO8 Ensure compliance with external
requirements.
8.1 External requirements ME3.1
review
8.2 Practices and procedures ME3.2
for complying with
external requirements
8.3 Safety and ergonomic ME3.1
compliance
8.4 Privacy, intellectual ME3.1
property and data flow
8.5 Electronic commerce ME3.1
8.6 Compliance with ME3.1
insurance contracts
PO9 Assess risks.
9.1 Business risk 9.1, 9.2, 9.4
assessment
9.2 Risk assessment approach 9.4
9.3 Risk identification 9.3
9.4 Risk measurement 9.1, 9.2, 9.3, 9.4
9.5 Risk action plan 9.5
9.6 Risk acceptance 9.5
9.7 Safeguard selection 9.5
9.8 Risk assessment 9.1
committment
COBIT 3
rd
Edition COBIT 4.1
PO10 Manage projects.
10.1 Project management 10.2
framework
10.2 User department 10.4
participation in project
initiation
10.3 Project team membership 10.8
and responsibilities
10.4 Project definition 10.5
10.5 Project approval 10.6
10.6 Project phase approval 10.6
10.7 Project master plan 10.7
10.8 System quality 10.10
assurance plan
10.9 Planning of assurance 10.12
methods
10.10 Formal project risk 10.9
management
10.11 Test plan AI7.2
10.12 Training plan AI7.1
10.13 Post-implementation 10.14 (part)
review plan
PO11 Manage quality.
11.1 General quality plan 8.5
11.2 QA approach 8.1
11.3 QA planning 8.1
11.4 QA review of adherence 8.1, 8.2
to IT standards and
procedures
11.5 System development 8.2, 8.3
life cycle (SDLC) methodology
11.6 SDLC methodology for 8.2, 8.3
major changes to existing
technology
11.7 Updating of the SDLC 8.2, 8.3
methodology
11.8 Co-ordination and 8.2
communication
11.9 Acquisition and 8.2
maintenance framework for
the technology infrastructure
11.10 Third-party 8.2, DS2.3
implementor relationships
11.11 Programme AI4.2, AI4.3,
documentation standards AI4.4
11.12 Programme testing AI7.2, AI7.4
standards
11.13 System testing AI7.2, AI7.4
standards
11.14 Parallel/pilot testing AI7.2, AI7.4
11.15 System testing AI7.2, AI7.4
documentation
11.16 QA evaluation of 8.2
adherence to development
standards
11.17 QA review of the 8.2
achievement of IT objectives
11.18 Quality metrics 8.6
11.19 Reports of QA reviews 8.2
Cross-reference: C
OBI
T 3
rd
Edition to C
OBI
T 4.1