ACTIVITIES

Generic Activities

The four activities that apply to every control in the catalog, stated once rather than repeated seventy-eight times.

ASOM-Fed v6.1 · Unclassified / Illustrative · agency-agnostic reference framework · built from public sources only

Applies to every control · v4.0

Four activities apply to all seventy-eight controls. They are stated once here rather than repeated sixty times, and an assessor should treat them as in scope for any control being examined. This mirrors the economy COBIT applies to its own generic practices, and it prevents the same requirement drifting into four different wordings across eleven family documents.


GA1 — Approach

Design the control approach for achieving this control and maintain the set of activities that implement it. Record the design decision, its rationale, and the date it was last reviewed.

Capability level 3. Assessment — examine the recorded approach and its review date.


GA2 — Accountability and responsibility

Assign accountability for the control as a whole and responsibility for each of its activities against the six roles. Confirm the holders have the authority and the resources to execute, and escalate where they do not.

Capability level 2. Assessment — examine the assignment; interview a sample of holders to confirm acceptance and sufficiency of authority.


GA3 — Communication and understanding

Ensure the way the activities implement the control is communicated to those who must perform it, and confirm by sampling that performers can state what the control requires of them.

Capability level 3. Assessment — interview a sample of performers; test whether they can state the requirement without reference to the document.


GA4 — Threshold approval provenance

Where a control defines a threshold, floor, period or target date, obtain the accountable authority's approval of that value and record the date of approval relative to the date of first measurement.

Capability level 3. Assessment — examine the approval record; determine whether the value was approved before or after the first measurement against it.

Rationale. A threshold set after the first measurement will be set wherever the organization already passes. That produces a governed-looking metric that has never once reported a problem, and it is indistinguishable in the record from a genuine risk appetite unless the sequence is captured. Recording the provenance does not forbid setting a threshold late — programs often must — but it makes the distinction visible to anyone reading the result.

Controls in scope. Every control defining a quantitative or temporal bound, including but not limited to:

ControlBound
KT-2Minimum effective coverage floor
TA-3Minimum acceptable temporal advantage ratio
CE-1Cycle cadence interval
CE-5Backlog target dates
CG-4Findings disposition period
RC-1Recovery time and recovery point objectives
RC-5Reconstitution exercise cadence
WF-5Separation and revocation tempo
LC-5Supplier severance period

TA-3 already carries this requirement inline as activity 4; it is retained there because the post-hoc threshold problem is most acute for the framework's signature metric, and the duplication is deliberate emphasis rather than drift.