COBIT Framework
What It Is and Why It Matters
COBIT (Control Objectives for Information and Related Technologies) is ISACA's flagship framework for the governance and management of enterprise information and technology. The current version, COBIT 2019, builds on its predecessors by offering a more flexible and customizable approach to IT governance. For CISA candidates, COBIT is critical because it provides the control objectives and governance structures that auditors frequently evaluate.
COBIT bridges the gap between business requirements, control needs, and technical considerations. It helps organizations create optimal value from IT by maintaining a balance between realizing benefits, optimizing risk levels, and managing resource use. As an IS auditor, you will use COBIT as a benchmark for assessing whether an organization's IT governance and management practices are adequate and effective.
Understanding COBIT is essential because CISA exam questions frequently reference its concepts, especially around governance versus management, the separation of roles and responsibilities, and how performance is measured and monitored.
Key Concepts and Terminology
COBIT 2019 Principles
- Provide Stakeholder Value: The governance system should meet stakeholder needs and create value through IT investments.
- Holistic Approach: Governance is built from several components that work together, not in isolation.
- Dynamic Governance System: The governance system should change as the enterprise's design factors evolve.
- Governance Distinct from Management: Governance sets direction and monitors performance, while management plans, builds, runs, and monitors activities.
- Tailored to Enterprise Needs: The governance system should be customized using design factors to fit the specific needs of the enterprise.
- End-to-End Governance System: Covers the full enterprise, not just the IT function.
Governance System Components
- Processes: Organized sets of practices and activities to achieve objectives. COBIT defines 40 governance and management objectives grouped under five domains.
- Organizational Structures: Decision-making entities such as the board, executive committees, and IT steering committees.
- Principles, Policies, and Frameworks: Translate desired behavior into practical guidance.
- Information: Produced and used by the governance system; includes both operational data and governance information.
- Culture, Ethics, and Behavior: The human factors that influence governance outcomes.
- People, Skills, and Competencies: Required to make good decisions, take corrective action, and successfully complete activities.
- Services, Infrastructure, and Applications: Technology and service capabilities that support governance and management.
COBIT 2019 Domains
- EDM (Evaluate, Direct, and Monitor): The governance domain, focused on board-level activities.
- APO (Align, Plan, and Organize): Strategic alignment and planning.
- BAI (Build, Acquire, and Implement): Solution development and implementation.
- DSS (Deliver, Service, and Support): Operational delivery and support.
- MEA (Monitor, Evaluate, and Assess): Performance monitoring and compliance assessment.
Design Factors
COBIT 2019 introduces design factors that influence the design of an organization's governance system. These include enterprise strategy, organizational size, risk profile, compliance requirements, IT's role in the enterprise, sourcing model, and technology adoption strategy. Design factors help tailor COBIT implementation to the specific context of the organization.
How This Appears on the CISA Exam
COBIT-related questions appear primarily in Domain 2 of the CISA exam. Common question types include:
- Identifying the distinction between governance and management activities, and determining which domain (EDM versus APO, BAI, DSS, MEA) a given activity belongs to.
- Understanding the role of the board versus management in IT governance.
- Recognizing COBIT governance components and how they interact.
- Applying COBIT principles to scenarios involving IT investment decisions, performance measurement, or risk optimization.
- Understanding how design factors influence the governance system.
A key distinction to remember: the board governs (evaluates, directs, monitors), while management manages (plans, builds, runs, monitors). Questions often test whether you can correctly assign responsibilities to the appropriate level.
Study Tips
- Focus on the governance versus management distinction; this is a recurring exam theme.
- Memorize the five COBIT domains (EDM, APO, BAI, DSS, MEA) and understand what each covers at a high level.
- Know the seven governance system components and be able to identify examples of each.
- Understand that COBIT is designed to be tailored, not adopted wholesale, and that design factors drive customization.
- Review how COBIT integrates with other frameworks like ITIL, ISO 27001, and NIST.
Related Subtopics
- IT governance structures and roles
- Enterprise architecture frameworks
- IT balanced scorecard
- Performance measurement and maturity models
- IT steering committees and governance bodies
- COBIT implementation and assessment approaches
Ready to Test Your Knowledge?
Practice exam questions on COBIT Framework and other IT Governance topics.
Start Practicing Free