Applies to every control · v4.0
Four activities apply to all seventy-eight controls. They are stated once here rather than repeated sixty times, and an assessor should treat them as in scope for any control being examined. This mirrors the economy COBIT applies to its own generic practices, and it prevents the same requirement drifting into four different wordings across eleven family documents.
GA1 — Approach
Design the control approach for achieving this control and maintain the set of activities that implement it. Record the design decision, its rationale, and the date it was last reviewed.
Capability level 3. Assessment — examine the recorded approach and its review date.
GA2 — Accountability and responsibility
Assign accountability for the control as a whole and responsibility for each of its activities against the six roles. Confirm the holders have the authority and the resources to execute, and escalate where they do not.
Capability level 2. Assessment — examine the assignment; interview a sample of holders to confirm acceptance and sufficiency of authority.
GA3 — Communication and understanding
Ensure the way the activities implement the control is communicated to those who must perform it, and confirm by sampling that performers can state what the control requires of them.
Capability level 3. Assessment — interview a sample of performers; test whether they can state the requirement without reference to the document.
GA4 — Threshold approval provenance
Where a control defines a threshold, floor, period or target date, obtain the accountable authority's approval of that value and record the date of approval relative to the date of first measurement.
Capability level 3. Assessment — examine the approval record; determine whether the value was approved before or after the first measurement against it.
Rationale. A threshold set after the first measurement will be set wherever the organization already passes. That produces a governed-looking metric that has never once reported a problem, and it is indistinguishable in the record from a genuine risk appetite unless the sequence is captured. Recording the provenance does not forbid setting a threshold late — programs often must — but it makes the distinction visible to anyone reading the result.
Controls in scope. Every control defining a quantitative or temporal bound, including but not limited to:
| Control | Bound |
|---|---|
KT-2 | Minimum effective coverage floor |
TA-3 | Minimum acceptable temporal advantage ratio |
CE-1 | Cycle cadence interval |
CE-5 | Backlog target dates |
CG-4 | Findings disposition period |
RC-1 | Recovery time and recovery point objectives |
RC-5 | Reconstitution exercise cadence |
WF-5 | Separation and revocation tempo |
LC-5 | Supplier severance period |
TA-3 already carries this requirement inline as activity 4; it is retained there because the post-hoc threshold problem is most acute for the framework's signature metric, and the duplication is deliberate emphasis rather than drift.