Monitor and Evaluate
Main Description

COBIT® V4.1 IT Process Name

COBIT V4.1 Detailed Control Objectives

PRM-IT IT Process Name(s)

ME 1

Evaluate IT Performance

ME1.1

Monitoring Approach

(See Note 3)

ME1.2

Definition and Collection of Monitoring Data

ME1.3

Monitoring Method

ME1.4

Performance Assessment

ME1.5

Board and Executive Reporting

ME1.6

Remedial Actions

ME 2

Monitor and Evaluate Internal Control

ME2.1

Monitoring of Internal Control Framework

ME2.2

Supervisory Review

ME2.3

Control Exceptions

ME2.4

Control Self-Assessment

(See Note 4)

ME2.5

Assurance of Internal Control

(See Note 5)



ME2.6

Internal Control at Third Parties

ME2.7

Remedial Actions

ME 3

Ensure Regulatory Compliance

ME3.1

Identification of External Legal, Regulatory and Contractual Compliance Requirements

ME3.2

Optimization of Response to Regulatory Requirements

ME3.3

Evaluation of Compliance with Regulatory Requirements

ME3.4

Positive Assurance of Compliance

ME3.5

Integrated Reporting

ME 4

Provide IT Governance

ME4.1

Establishment of an IT Governance Framework

ME4.2

Strategic Alignment

ME4.3

Value Delivery

ME4.4

Resource Management

ME4.5

Risk Management

ME4.6

Performance Measurement

ME4.7

Independent Assurance

(See Note 6)





Notes:

  1. See the "Establish Process Framework" activity in each process.
  2. See the "Evaluate Process Performance" activity in each process. 
  3. Plus the closed loop individual process activity data flows and final ‘Evaluate process Performance’ activity in most Axx-level Sub-processes. 
  4. PRM-IT does not address specific techniques, such as self-assessment. However the A1 Process Group and processes A13 & A14 do imply continuous programs of evaluation. 
  5. PRM-IT does not address specific sourcing alternatives related to external assurance reviews as discussed in this control objective.
  6. PRM-IT does not address specific sourcing alternatives related to external assurance reviews as discussed in this control objective.