COBIT 2019: IT Governance Framework Guide
COBIT (Control Objectives for Information and Related Technologies) is ISACA's flagship framework for enterprise IT governance and management. It provides a comprehensive structure for aligning IT strategy with business objectives, managing IT-related risks, and ensuring IT delivers value to the organization.
What COBIT Covers
COBIT 2019 defines 40 governance and management objectives organized into five domains. The Governance domain (EDM) covers evaluation, direction, and monitoring of IT at the board level. Four Management domains (APO, BAI, DSS, MEA) address planning, implementation, delivery, and monitoring of IT operations.
Each objective includes detailed management practices, activities, and capability levels ranging from 0 (Incomplete) to 5 (Optimizing). The framework also introduces design factors — contextual elements like enterprise strategy, IT-related risk profile, and compliance requirements — that help organizations tailor their governance system.
Who Needs COBIT
COBIT is particularly valuable for organizations where IT governance is a board-level concern: publicly traded companies, financial institutions, government agencies, and large enterprises with complex IT environments. IT auditors frequently reference COBIT when evaluating IT governance and controls.
The framework serves multiple audiences — boards of directors, C-suite executives, IT management, risk managers, and auditors — providing appropriate levels of detail for each.
COBIT vs. Other Frameworks
Unlike ISO 27001 or NIST CSF which focus specifically on security, COBIT addresses the full scope of IT governance including project delivery, service management, and strategic alignment. Many organizations use COBIT as an umbrella governance framework with ISO 27001 or NIST handling security-specific requirements underneath.
Implementation Approach
- Understand context — Assess design factors including enterprise strategy, goals, and risk profile
- Determine scope — Identify which governance and management objectives to prioritize
- Assess current capability — Rate each objective from 0 to 5
- Set target capability — Define desired maturity levels based on business needs
- Perform gap analysis — Compare current and target states
- Plan improvements — Develop a roadmap addressing the most critical gaps first
- Implement and measure — Deploy improvements and track progress using COBIT's performance management guidance
COBIT works best when implemented incrementally, focusing on the governance and management objectives most relevant to your organization's priorities rather than attempting to address all 40 objectives simultaneously.
The Five Domains Explained
EDM — Evaluate, Direct and Monitor (5 objectives) is the governance domain, operating at the board and executive level. It covers ensuring governance framework setting and maintenance, ensuring benefits delivery, ensuring risk optimization, ensuring resource optimization, and ensuring stakeholder engagement. EDM is where COBIT distinguishes itself from purely security-focused frameworks — it connects IT governance to business value and accountability.
APO — Align, Plan and Organize (14 objectives) addresses how IT strategy, enterprise architecture, risk management, innovation, and portfolio management are organized. APO objectives cover managing the framework, strategy, enterprise architecture, innovation, portfolio, budget, HR, relationships, service agreements, suppliers, quality, risk, and security. The APO domain is where most of the governance-to-operations translation occurs.
BAI — Build, Acquire and Implement (11 objectives) covers program management, requirements definition, solution identification, availability, capacity, organizational change, IT changes, configuration, knowledge, assets, and change. BAI objectives ensure that technology solutions are delivered reliably and aligned with business requirements.
DSS — Deliver, Service and Support (6 objectives) addresses managing operations, managed requests, managed problems, managed continuity, managed security services, and managed business process controls. DSS is where day-to-day IT operations connect to the governance framework established in EDM and APO.
MEA — Monitor, Evaluate and Assess (4 objectives) provides oversight: performance and conformance monitoring, internal control systems evaluation, compliance with external requirements, and assurance. MEA closes the governance loop by ensuring that what was planned and implemented is actually functioning.
Who Needs COBIT and When
Publicly traded companies with IT governance obligations — whether from Sarbanes-Oxley, stock exchange listing rules, or industry regulation — are the core COBIT audience. IT auditors and internal audit teams use COBIT as their primary IT governance assessment framework.
Financial institutions regulated by banking supervisors who require mature IT governance frameworks (EBA, FFIEC, APRA) find COBIT provides the structure auditors look for in examinations.
Large enterprises going through digital transformation use COBIT to govern IT investment decisions, manage program risk, and maintain board-level visibility into technology risk and performance.
Organizations under SOX compliance use COBIT to structure ITGC controls, assess IT management practices, and provide the governance context that makes ITGC testing coherent.
The framework is less suited to startups and small organizations where governance overhead outweighs benefit. For organizations under 100 employees, NIST CSF or CIS Controls are more practical starting points.
The Capability Model
COBIT 2019 uses a capability model ranging from 0 (Incomplete) to 5 (Optimizing) for each management practice within every governance and management objective. This replaces the older maturity model with a more actionable scale that separates capability from performance.
Most organizations target Level 3 (Established) for their most critical objectives as a balanced risk posture. Level 4 (Predictable) and Level 5 (Optimizing) require significant investment and are appropriate only for the highest-risk, highest-value objectives.
Costs and Timeline
| Component | Low Estimate | High Estimate |
|---|---|---|
| Initial capability assessment | $15,000 | $50,000 |
| Framework design and scoping | $10,000 | $30,000 |
| Consulting / ISACA advisory | $20,000 | $100,000 |
| Documentation and training | $10,000 | $40,000 |
| Ongoing assessment (annual) | $15,000 | $60,000 |
| Total first-year | $70,000 | $280,000 |
Timeline: 6 to 18 months for an initial implementation. Enterprise-wide deployments at complex organizations can take 24 to 36 months.
How COBIT Compares to Related Frameworks
COBIT vs. ISO 27001 — About 55% overlap. ISO 27001 focuses specifically on information security management; COBIT covers the full scope of IT governance. Many organizations use COBIT as their IT governance umbrella and ISO 27001 for the security-specific management system underneath.
COBIT vs. COSO — About 50% overlap. COSO focuses on internal control for financial reporting; COBIT focuses on IT governance and management. For SOX compliance, organizations typically use COSO for the financial control framework and COBIT for IT general controls assessment.
COBIT vs. NIST CSF — About 60% overlap at the governance level. NIST CSF is cybersecurity-specific; COBIT is broader IT governance. Organizations using NIST CSF for cybersecurity and COBIT for IT governance are addressing complementary rather than competing concerns.
How Automation Helps
COBIT implementation requires extensive documentation of management practices, capability assessments, and improvement tracking across 40 objectives. Managing this manually at enterprise scale creates the kind of administrative burden that causes governance programs to atrophy between assessments.
LowerPlane supports COBIT governance objectives as part of its 50-plus framework library, providing a structured way to track capability levels, collect evidence for management practices, and generate assessment-ready reports. At $4,000/year entry pricing with a free tier, it lowers the operational cost of maintaining a COBIT program. AuditXYZ rates it 9.4/10. Compare at Best Compliance Automation Platforms.
Frequently Asked Questions
Is there a COBIT certification for organizations? No. COBIT does not have an organizational certification equivalent to ISO 27001. ISACA offers individual certifications (CISA, CGEIT, CRISC) and conducts assessments, but there is no COBIT certificate that organizations can present to customers or regulators.
How does COBIT relate to SOX compliance? COBIT is widely used as the IT governance framework for SOX Section 404 ITGC assessments. Auditors use COBIT objectives to evaluate whether IT management practices provide a reliable control environment for financial reporting. The mapping between COBIT 2019 and SOX ITGC expectations is well-established and widely documented.
What is the difference between COBIT 5 and COBIT 2019? COBIT 2019 restructured the framework with updated design factors, a revised capability model (replacing the previous maturity model with a scale aligned to ISO 33000), an increased number of focus areas, and improved guidance for implementing COBIT in context. Organizations still using COBIT 5 should plan a migration to the 2019 edition.
Do we need all 40 objectives? No. COBIT 2019 introduces design factors — contextual inputs like enterprise strategy, risk profile, industry, and regulatory requirements — that help prioritize which objectives matter most. A fintech startup and a large insurance company will have very different priority subsets of the 40 objectives.