12.3 APO Risk, Security, Data, and Quality
Key Takeaways
- APO11 Managed Quality defines quality requirements and monitors continual improvement across processes and enterprise outcomes.
- APO12 Managed Risk continually identifies, assesses, and reduces I&T risk within executive tolerance — it does not set board appetite.
- EDM03 is board risk appetite; APO12 is management of I&T risk; DSS05 is security services operations. Three altitudes, not one process.
- APO13 Managed Security defines, operates, and monitors an ISMS; DSS05 runs day-to-day security services. They are neighbors, not twins.
- APO14 Managed Data is new in COBIT 2019 and covers data assets across the life cycle from creation through archiving.
Quick Answer: The last four Align, Plan and Organize (APO) objectives plan how the enterprise will be good, safe, and data-literate. APO11 Managed Quality defines quality requirements and monitors continual improvement. APO12 Managed Risk continually identifies, assesses, and reduces I&T risk inside executive tolerance. APO13 Managed Security defines, operates, and monitors an information security management system (ISMS). APO14 Managed Data manages data assets across the life cycle and is new in COBIT 2019. Do not confuse EDM03 Ensured Risk Optimization (board risk appetite), APO12 (management of I&T risk), APO13 (the ISMS), and DSS05 Managed Security Services (security operations).
These four close the 14-objective APO list. Together with APO01–APO10 they are the entire plan domain of the core model. Foundation stems in the 23% Governance and Management Objectives domain often test the stack — which altitude owns appetite, which owns the I&T risk process, which owns the ISMS, and which owns the security tickets — more than they test a long definition.
The four official objectives
| ID | Official title | One-sentence purpose |
|---|---|---|
| APO11 | Managed Quality | Define and communicate quality requirements across processes and outcomes, then monitor and improve using proven practices. |
| APO12 | Managed Risk | Continually identify, assess, and reduce I&T-related risk within the tolerance set by executive management. |
| APO13 | Managed Security | Define, operate, and monitor an information security management system. |
| APO14 | Managed Data | Achieve and sustain effective management of enterprise data assets across the data life cycle — creation through delivery, maintenance, and archiving. |
APO11 Managed Quality
APO11 puts quality on purpose instead of inspecting it in at the end. Define and communicate quality requirements in processes, procedures, and related enterprise outcomes. Enable controls, ongoing monitoring, and proven practices and standards in continual improvement and efficiency.
For Northline Mutual, quality is not only defect counts in the mobile app. It is claim-decision quality, data quality feeding fraud scores, and process quality in the new straight-through path. APO11 is the management objective that says what “good” means and keeps improving it. It is not MEA01 Managed Performance and Conformance Monitoring (the monitor domain watching performance and conformance) and not BAI07 Managed IT Change Acceptance and Transitioning. Those consume quality requirements. APO11 is where those requirements are managed as a system.
APO12 Managed Risk
APO12 is the I&T risk management objective. Official purpose, almost word for word: continually identify, assess, and reduce I&T-related risk within tolerance levels set by enterprise executive management.
Three words do the exam work: continually, I&T-related, and within tolerance. APO12 is not a once-a-year risk-register workshop. It is not a quest to drive risk to zero. Tolerance comes from executives, themselves directed by the board’s appetite work in EDM03.
High-yield distinction: EDM03 versus APO12 versus DSS05
| ID | Official title | Layer | Job |
|---|---|---|---|
| EDM03 | Ensured Risk Optimization | Governance | The board evaluates I&T risk, directs risk appetite, and monitors whether residual risk stays acceptable as part of enterprise risk management. |
| APO12 | Managed Risk | Management (plan) | Management continually identifies, assesses, and treats I&T risk inside that appetite and tolerance, and keeps the I&T risk process running. |
| DSS05 | Managed Security Services | Management (run) | Operations protect the enterprise: identities, access, network and endpoint protection, malware, physical security — the security services. |
If the stem is a board paper that sets how much cyber and model risk the insurer will absorb, that is EDM03. If it is a quarterly I&T risk assessment that proposes treatments for the claims-engine vendor, that is APO12. If it is the team that resets access, patches the landing zone, and runs malware defense, that is DSS05. Same subject matter. Three altitudes.
APO13 Managed Security
APO13 is short on purpose in the official text and dense on the exam: define, operate, and monitor an information security management system. An ISMS is the management system for information security — policy, organization, risk-treatment planning, control selection, awareness, and monitoring that security remains fit. ISO/IEC 27001 is the standard many enterprises use to express an ISMS. COBIT does not retire ISO 27001; APO13 is how that ISMS is managed as a COBIT management objective.
APO13 versus DSS05
| Lens | APO13 Managed Security | DSS05 Managed Security Services |
|---|---|---|
| What it is | The ISMS — the management system for information security | The security services that operate day to day |
| Domain | APO (plan / organize) | Deliver, Service and Support (DSS) (run) |
| Typical work | Security policy, ISMS scope, control objectives, security roles, ISMS monitoring and improvement | Access administration, malware protection, network security, endpoint security, physical security operations |
| Failure mode | A binder of policies with no operating services | Busy tools and tickets with no ISMS — no managed system tying operations to policy and risk |
Northline can buy a security information and event management (SIEM) tool (a DSS05-flavored service) and still fail APO13 if nobody owns the ISMS: no defined security management system, no monitoring that the system works, no link back to APO12 risk treatments and EDM03 appetite. Conversely, a beautiful ISMS document that never reaches the people who grant access is APO13 theater.
APO13 and APO12 are neighbors, not twins. APO12 manages I&T risk of every kind — availability, vendor, project, information, compliance. APO13 is the security management system. Security risk flows through both. They do not merge into one “cyber objective.”
APO14 Managed Data
APO14 Managed Data is the objective you must flag as new in COBIT 2019. COBIT 5 had 37 processes. COBIT 2019 has 40 governance and management objectives. For Foundation purposes, remember at least this: data became its own management objective in 2019. Do not look for APO14 on a COBIT 5 process list, and do not treat data as a nameless subset of APO03 or of a warehouse job in DSS.
Official purpose: achieve and sustain effective management of the enterprise data assets across the data life cycle — from creation through delivery, maintenance, and archiving. Data is not a side effect of applications. It is an asset with a life cycle that APO14 manages.
Northline’s fraud-scoring platform fails if “data” is left inside APO03 Managed Enterprise Architecture as a layer drawing or inside DSS as a warehouse job. Architecture still has a data layer. APO14 is the management system for the asset: quality, lineage, ownership, retention, archiving, and life-cycle control. The data layer says how data fits. APO14 says how data is managed from birth to archive.
Closing the Northline chain
Bring the last four objectives back to the digital-insurer story:
- APO11 defines what a quality digital claim looks like — not only uptime, but decision quality and defect leakage — and monitors improvement after go-live.
- APO12 keeps a live I&T risk view of the vendor engine, the mobile channel, and model error, inside the tolerance executives set after the board’s EDM03 appetite.
- APO13 puts an ISMS around claimant data and the new cloud landing zone: policy, roles, control objectives, and ISMS monitoring.
- APO14 treats claims and policy data as assets with owners, creation rules, retention, and archive — a 2019-shaped answer the COBIT 5 syllabus would not have given its own ID.
That is the full APO set you now hold: APO01 framework, APO02 strategy, APO03 architecture, APO04 innovation, APO05 portfolio, APO06 budget and costs, APO07 human resources, APO08 relationships, APO09 service agreements, APO10 vendors, APO11 quality, APO12 risk, APO13 security, APO14 data. Fourteen Managed titles. Zero Ensured titles. The board still sits in EDM.
Exam traps
- EDM03 = APO12 = DSS05. Appetite versus I&T risk management versus security operations.
- APO13 = DSS05. ISMS versus security services.
- Forgetting APO14. It is new in 2019; data has its own objective.
- APO12 as risk elimination. Reduce within tolerance, not to zero.
- APO11 as testing only. Quality requirements and continual improvement across processes and outcomes, not a single test phase.
Prefer the answer that keeps these four official titles, keeps APO14 as a 2019 addition, and keeps risk and security stacked as EDM03 → APO12 / APO13 → DSS05.
A board sets I&T risk appetite, management continually identifies and treats I&T risk inside that tolerance, and operations run access control and malware protection. Which mapping is correct?
Which statement about APO13 Managed Security and APO14 Managed Data is correct?