COBIT 2019
COBIT 2019 is an IT governance and management framework published by ISACA that helps organisations create optimal value from IT by maintaining a balance between realising benefits and optimising risk levels and resource use. It defines 40 governance and management objectives across 5 domains, with a focus area model that allows tailoring to specific enterprise needs including DevOps, cloud computing, and small enterprises.
Overview
What is COBIT 2019?
COBIT 2019 (Control Objectives for Information and Related Technologies) is a comprehensive IT governance and management framework published by ISACA. It provides a structured approach for organisations to govern and manage their enterprise information and technology, ensuring alignment with business objectives. COBIT is primarily used by IT leadership, CIOs, audit teams, and governance professionals to establish accountability, measure performance, and manage risk across all technology-related activities.
What are the 5 COBIT 2019 domains?
COBIT 2019 organises its 40 governance and management objectives into 5 domains:
- Evaluate, Direct, and Monitor (EDM): 5 governance objectives covering the board's role in setting direction, evaluating performance, and ensuring compliance. Covers governance framework, benefits delivery, risk optimisation, resource optimisation, and stakeholder engagement.
- Align, Plan, and Organise (APO): 14 management objectives addressing strategy, architecture, innovation, portfolio management, budget, human resources, relationships, service agreements, managed risk, security, and data quality.
- Build, Acquire, and Implement (BAI): 11 management objectives covering programme and project management, requirements definition, solutions identification, availability and capacity, change management, and change acceptance.
- Deliver, Service, and Support (DSS): 6 management objectives addressing operations management, service requests, problems, continuity, security services, and business process controls.
- Monitor, Evaluate, and Assess (MEA): 4 management objectives covering performance and conformance monitoring, internal control assessment, and compliance with external requirements.
How does COBIT relate to ITIL?
COBIT and ITIL are complementary: COBIT focuses on IT governance (what should be done and why), while ITIL focuses on IT service management (how to do it). COBIT provides the governance framework that sets direction and evaluates performance, while ITIL provides the detailed practices for delivering and managing IT services. Many organisations use COBIT as the governance layer with ITIL as the service management layer beneath it. Our database maps COBIT 2019 to 287 other frameworks.
What are COBIT capability levels?
COBIT 2019 uses a capability model based on CMMI with six levels for each governance or management objective:
- Level 0 (Incomplete): The process is not implemented or fails to achieve its purpose
- Level 1 (Performed): The process achieves its purpose but is not well managed
- Level 2 (Managed): The process is managed (planned, monitored, adjusted) and work products are controlled
- Level 3 (Established): A defined process is used based on a standard process and contributes to defined outcomes
- Level 4 (Predictable): The process operates within defined limits using quantitative management
- Level 5 (Optimising): The process is continuously improved to meet current and projected business goals
Key Controls
| ID | Control |
|---|---|
| EDM01 | Ensured Governance Framework |
| EDM03 | Ensured Risk Optimisation |
| APO01 | Managed I&T Management Framework |
| APO12 | Managed Risk |
| APO13 | Managed Security |
| BAI06 | Managed IT Changes |
| DSS01 | Managed Operations |
| MEA01 | Managed Performance and Conformance Monitoring |
Domains
Compare COBIT 2019
Compare COBIT 2019
Frequently Asked Questions
What is COBIT 2019?
How many controls does COBIT 2019 have?
Where does COBIT 2019 apply?
What frameworks does COBIT 2019 map to?
How do I get started with COBIT 2019 compliance?
How ready are you for COBIT 2019?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.