IT Governance Frameworks: COBIT 2019 Explained
A detailed overview of the COBIT 2019 framework, its principles, governance components, and relevance to the CISA exam.
COBIT 2019 (Control Objectives for Information and Related Technologies) is one of the most important IT governance frameworks for CISA candidates. Developed by ISACA, COBIT provides a comprehensive framework for the governance and management of enterprise information and technology. Understanding COBIT 2019 is essential for both the exam and professional practice.
What Is COBIT 2019?
COBIT 2019 is an evolution of earlier COBIT versions, designed to address modern enterprise IT challenges including digital transformation, cloud computing, and evolving regulatory requirements. It provides a flexible framework that organizations can tailor to their specific needs and context.
COBIT 2019 Principles
The framework is built on six principles for a governance system:
- Provide stakeholder value: The governance system should create value for all stakeholders
- Holistic approach: Governance requires multiple interacting components working together
- Dynamic governance system: The governance system should adapt as changes in design factors occur
- Governance distinct from management: Governance ensures stakeholder needs are evaluated; management plans, builds, runs, and monitors activities
- Tailored to enterprise needs: The governance system should be customized using design factors
- End-to-end governance system: Governance covers the full enterprise, not just the IT function
Governance and Management Objectives
COBIT 2019 organizes objectives into two domains:
Governance Objectives (EDM)
The Evaluate, Direct, and Monitor (EDM) domain contains five governance objectives that define what the governing body does:
- EDM01: Ensured governance framework setting and maintenance
- EDM02: Ensured benefits delivery
- EDM03: Ensured risk optimization
- EDM04: Ensured resource optimization
- EDM05: Ensured stakeholder engagement
Management Objectives
Management objectives are grouped into four domains:
- APO (Align, Plan, and Organize): 14 objectives covering strategy, architecture, risk, and resource management
- BAI (Build, Acquire, and Implement): 11 objectives covering solution development, change management, and transition
- DSS (Deliver, Service, and Support): 6 objectives covering operations, service requests, and security
- MEA (Monitor, Evaluate, and Assess): 4 objectives covering performance monitoring, internal controls, and compliance
Components of the Governance System
COBIT 2019 identifies seven components (previously called enablers) that support the governance system:
- Processes
- Organizational structures
- Principles, policies, and frameworks
- Information
- Culture, ethics, and behavior
- People, skills, and competencies
- Services, infrastructure, and applications
Design Factors
COBIT 2019 introduces design factors that help organizations tailor the governance system. These include enterprise strategy, goals, risk profile, IT-related issues, threat landscape, compliance requirements, role of IT, sourcing model, IT implementation methods, technology adoption strategy, and enterprise size.
CISA Exam Tips
For the CISA exam, focus on understanding the distinction between governance (EDM) and management (APO, BAI, DSS, MEA). Know the six principles and seven components. Questions often test whether a given activity falls under governance or management, and which COBIT domain applies to a specific scenario.