Conduct workshops and interviews with process owners (e.g., Security Officers, IT Operations Managers, Enterprise Architects). Do not rely on hearsay; ensure stakeholders provide evidence—such as policy documents, meeting minutes, or system logs—to back up their maturity claims. Step 3: Input Data into the XLS Tool
Which specific (e.g., EDM, APO, DSS) is your primary focus right now?
Use Excel's comment feature to explain why a specific rating was chosen, ensuring continuity for future auditors. Conclusion
COBIT 2019 rates individual process activities on a scale from 0 to 5:
Form a team to complete the assessment. The tool should not be completed by one person. Engage IT managers, process owners, and stakeholders who have a "ground-level" view of how processes are actually executed. 3. Conduct the Assessment (The "What" and "How")
Treat your COBIT 2019 Excel tool as a living document. Archive your baseline assessment, and update the spreadsheet quarterly or bi-annually to track your maturity trajectory and demonstrate governance ROI to the board of directors.
Reporting outputs to include
0% to 15% achievement of the capability criteria. P (Partially Achieved): >15% to 50% achievement. L (Largely Achieved): >50% to 85% achievement. F (Fully Achieved): >85% to 100% achievement.
Once the data is entered, the XLS tool usually visualizes the results. The output should look like this:
Dedicated tabs for EDM, APO, BAI, DSS, and MEA where assessors score individual process activities.