Skip to content

COBIT

What is COBIT?

Control Objectives for Information and Related Technologies, an IT governance framework by ISACA. COBIT 2019 provides 40 governance and management objectives across five domains.

Governance

What the standards actually require on cobit

Requirements naming cobit across 6 standards, quoted from the control text.

COBIT 201940 controls

Managed risk. Control from COBIT 2019 framework, domain: APO - Align, Plan and Organize.

COBIT-APO12 · Managed risk

FTC Safeguards Rule crosswalk to comprehensive cybersecurity + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (Qualified Individual + Board reporting + program governance) + IDENTIFY (314.4(b) risk assessment + 314.4(c)(2) data inventory) + PROTECT (314.4(c)...

FTC-Safeguards-Crosswalk-NIST-ISO-SOC · Crosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 2

GAMP 5 crosswalk to general IT + security + medical device frameworks. NIST CSF 2.0: GxP-system IT general controls map to GOVERN + IDENTIFY (inventory + supplier risk) + PROTECT (access controls + encryption + secure dev) + DETECT (monitoring + audit trails)...

GAMP5-CrossMapping-NIST-ISO · Crosswalk to NIST CSF, ISO 27001/27017, ISO 13485 (Medical Devices) and ITIL

Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST...

IRSPub1075-CoordNIST80053-FedRAMP-FISMA-CJIS-SSACDS-StateRevAgencies-PrivacyAct-SOC2-Industry · IRS Pub 1075 Coordination - NIST SP 800-53 Rev 5 + FedRAMP + FISMA + 26 USC 6103 + FBI CJIS + SSA CDS + State Revenue Agencies + Privacy Act + SOC 2 + Industry Frameworks + Federal Sectoral

Implement IT Audit + Third-Party Risk Management per MAS TRM Chapters 14 + 15 + MAS Notice 658 on Outsourcing. Chapter 14 IT Audit - IT audit charter approved by Board Audit Committee + IT audit plan risk-based + IT audit methodology + IT auditor competency (C...

MAS-TRM-Third-Party-IT-Audit-Chapters-14-15-Outsourcing-Notice-658-Concentration-Risk-Exit-Strategy · MAS TRM Third Party + IT Audit + Chapters 14-15 + Outsourcing + Notice 658 + Concentration Risk + Exit Strategy

Per SOX 404 + COBIT: ITGC including access management + change management + computer operations + program development + backup + recovery.

SOX404-4 · IT General Controls (ITGC) - Access, Change, Operations

Questions people ask about cobit

What is COBIT?
Control Objectives for Information and Related Technologies, an IT governance framework by ISACA. COBIT 2019 provides 40 governance and management objectives across five domains.
Why is COBIT important for compliance?
COBIT is a key concept in Governance. Understanding cobit helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to COBIT?
Key concepts related to COBIT include ITIL. Understanding these interconnected concepts provides a more comprehensive view of Governance requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address COBIT?
COBIT appears in the requirement text of COBIT 2019, FTC GLBA Safeguards Rule (16 CFR Part 314), GAMP 5 - Good Automated Manufacturing Practice, IRS Publication 1075, Monetary Authority of Singapore Technology Risk Management Guidelines. Across these standards we have identified 45 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about COBIT?
Explore our compliance framework pages to see how cobit applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how COBIT applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.