AuditXYZ

Compliance Framework

COBIT 2019 — Control Objectives for Information and Related Technologies (COBIT)

COBIT 2019 is a leading IT governance framework that aligns IT with business objectives. Learn how its 40 governance and management objectives improve enterprise IT performance.

$25,000–$200,0006–18 months2019
Issuing BodyISACA (Information Systems Audit and Control Association)
First Published1996-01-01
Latest Version2019
Typical Cost$25,000–$200,000
Typical Timeline6–18 months
Audit RequiredNo
Audit FrequencyNo mandatory certification audit. ISACA offers assessments and organizations may conduct periodic capability evaluations.
Geographyglobal

COBIT 2019: IT Governance Framework Guide

COBIT (Control Objectives for Information and Related Technologies) is ISACA's flagship framework for enterprise IT governance and management. It provides a comprehensive structure for aligning IT strategy with business objectives, managing IT-related risks, and ensuring IT delivers value to the organization.

What COBIT Covers

COBIT 2019 defines 40 governance and management objectives organized into five domains. The Governance domain (EDM) covers evaluation, direction, and monitoring of IT at the board level. Four Management domains (APO, BAI, DSS, MEA) address planning, implementation, delivery, and monitoring of IT operations.

Each objective includes detailed management practices, activities, and capability levels ranging from 0 (Incomplete) to 5 (Optimizing). The framework also introduces design factors — contextual elements like enterprise strategy, IT-related risk profile, and compliance requirements — that help organizations tailor their governance system.

Who Needs COBIT

COBIT is particularly valuable for organizations where IT governance is a board-level concern: publicly traded companies, financial institutions, government agencies, and large enterprises with complex IT environments. IT auditors frequently reference COBIT when evaluating IT governance and controls.

The framework serves multiple audiences — boards of directors, C-suite executives, IT management, risk managers, and auditors — providing appropriate levels of detail for each.

COBIT vs. Other Frameworks

Unlike ISO 27001 or NIST CSF which focus specifically on security, COBIT addresses the full scope of IT governance including project delivery, service management, and strategic alignment. Many organizations use COBIT as an umbrella governance framework with ISO 27001 or NIST handling security-specific requirements underneath.

Implementation Approach

  1. Understand context — Assess design factors including enterprise strategy, goals, and risk profile
  2. Determine scope — Identify which governance and management objectives to prioritize
  3. Assess current capability — Rate each objective from 0 to 5
  4. Set target capability — Define desired maturity levels based on business needs
  5. Perform gap analysis — Compare current and target states
  6. Plan improvements — Develop a roadmap addressing the most critical gaps first
  7. Implement and measure — Deploy improvements and track progress using COBIT's performance management guidance

COBIT works best when implemented incrementally, focusing on the governance and management objectives most relevant to your organization's priorities rather than attempting to address all 40 objectives simultaneously.

The Five Domains Explained

EDM — Evaluate, Direct and Monitor (5 objectives) is the governance domain, operating at the board and executive level. It covers ensuring governance framework setting and maintenance, ensuring benefits delivery, ensuring risk optimization, ensuring resource optimization, and ensuring stakeholder engagement. EDM is where COBIT distinguishes itself from purely security-focused frameworks — it connects IT governance to business value and accountability.

APO — Align, Plan and Organize (14 objectives) addresses how IT strategy, enterprise architecture, risk management, innovation, and portfolio management are organized. APO objectives cover managing the framework, strategy, enterprise architecture, innovation, portfolio, budget, HR, relationships, service agreements, suppliers, quality, risk, and security. The APO domain is where most of the governance-to-operations translation occurs.

BAI — Build, Acquire and Implement (11 objectives) covers program management, requirements definition, solution identification, availability, capacity, organizational change, IT changes, configuration, knowledge, assets, and change. BAI objectives ensure that technology solutions are delivered reliably and aligned with business requirements.

DSS — Deliver, Service and Support (6 objectives) addresses managing operations, managed requests, managed problems, managed continuity, managed security services, and managed business process controls. DSS is where day-to-day IT operations connect to the governance framework established in EDM and APO.

MEA — Monitor, Evaluate and Assess (4 objectives) provides oversight: performance and conformance monitoring, internal control systems evaluation, compliance with external requirements, and assurance. MEA closes the governance loop by ensuring that what was planned and implemented is actually functioning.

Who Needs COBIT and When

Publicly traded companies with IT governance obligations — whether from Sarbanes-Oxley, stock exchange listing rules, or industry regulation — are the core COBIT audience. IT auditors and internal audit teams use COBIT as their primary IT governance assessment framework.

Financial institutions regulated by banking supervisors who require mature IT governance frameworks (EBA, FFIEC, APRA) find COBIT provides the structure auditors look for in examinations.

Large enterprises going through digital transformation use COBIT to govern IT investment decisions, manage program risk, and maintain board-level visibility into technology risk and performance.

Organizations under SOX compliance use COBIT to structure ITGC controls, assess IT management practices, and provide the governance context that makes ITGC testing coherent.

The framework is less suited to startups and small organizations where governance overhead outweighs benefit. For organizations under 100 employees, NIST CSF or CIS Controls are more practical starting points.

The Capability Model

COBIT 2019 uses a capability model ranging from 0 (Incomplete) to 5 (Optimizing) for each management practice within every governance and management objective. This replaces the older maturity model with a more actionable scale that separates capability from performance.

Most organizations target Level 3 (Established) for their most critical objectives as a balanced risk posture. Level 4 (Predictable) and Level 5 (Optimizing) require significant investment and are appropriate only for the highest-risk, highest-value objectives.

Costs and Timeline

ComponentLow EstimateHigh Estimate
Initial capability assessment$15,000$50,000
Framework design and scoping$10,000$30,000
Consulting / ISACA advisory$20,000$100,000
Documentation and training$10,000$40,000
Ongoing assessment (annual)$15,000$60,000
Total first-year$70,000$280,000

Timeline: 6 to 18 months for an initial implementation. Enterprise-wide deployments at complex organizations can take 24 to 36 months.

COBIT vs. ISO 27001 — About 55% overlap. ISO 27001 focuses specifically on information security management; COBIT covers the full scope of IT governance. Many organizations use COBIT as their IT governance umbrella and ISO 27001 for the security-specific management system underneath.

COBIT vs. COSO — About 50% overlap. COSO focuses on internal control for financial reporting; COBIT focuses on IT governance and management. For SOX compliance, organizations typically use COSO for the financial control framework and COBIT for IT general controls assessment.

COBIT vs. NIST CSF — About 60% overlap at the governance level. NIST CSF is cybersecurity-specific; COBIT is broader IT governance. Organizations using NIST CSF for cybersecurity and COBIT for IT governance are addressing complementary rather than competing concerns.

How Automation Helps

COBIT implementation requires extensive documentation of management practices, capability assessments, and improvement tracking across 40 objectives. Managing this manually at enterprise scale creates the kind of administrative burden that causes governance programs to atrophy between assessments.

LowerPlane supports COBIT governance objectives as part of its 50-plus framework library, providing a structured way to track capability levels, collect evidence for management practices, and generate assessment-ready reports. At $4,000/year entry pricing with a free tier, it lowers the operational cost of maintaining a COBIT program. AuditXYZ rates it 9.4/10. Compare at Best Compliance Automation Platforms.

Frequently Asked Questions

Is there a COBIT certification for organizations? No. COBIT does not have an organizational certification equivalent to ISO 27001. ISACA offers individual certifications (CISA, CGEIT, CRISC) and conducts assessments, but there is no COBIT certificate that organizations can present to customers or regulators.

How does COBIT relate to SOX compliance? COBIT is widely used as the IT governance framework for SOX Section 404 ITGC assessments. Auditors use COBIT objectives to evaluate whether IT management practices provide a reliable control environment for financial reporting. The mapping between COBIT 2019 and SOX ITGC expectations is well-established and widely documented.

What is the difference between COBIT 5 and COBIT 2019? COBIT 2019 restructured the framework with updated design factors, a revised capability model (replacing the previous maturity model with a scale aligned to ISO 33000), an increased number of focus areas, and improved guidance for implementing COBIT in context. Organizations still using COBIT 5 should plan a migration to the 2019 edition.

Do we need all 40 objectives? No. COBIT 2019 introduces design factors — contextual inputs like enterprise strategy, risk profile, industry, and regulatory requirements — that help prioritize which objectives matter most. A fintech startup and a large insurance company will have very different priority subsets of the 40 objectives.

Request a COBIT consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

NIST CSFMedium60%
ISO 27001Medium55%
COSOMedium50%

Get matched with a COBIT auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools