Skip to content

04 COBIT 2019

COBIT 2019 is a framework for the governance and management of enterprise information and technology.

Where frameworks such as:

NIST CSF

focus on cybersecurity outcomes, and:

CIS Controls

focus on practical cybersecurity safeguards, COBIT takes a broader enterprise view.

It helps organizations answer questions such as:

Are Technology Investments
Supporting Business Goals?
Who Is Accountable
for Technology Decisions?
Are Risks Being Managed?
Are Controls Effective?
Are Technology Services
Delivering Value?
Are We Meeting
Regulatory Requirements?
How Do We Measure
Technology Performance?
How Does Leadership
Govern Information
and Technology?

COBIT connects:

Enterprise Strategy
Stakeholder Needs
Governance
Information & Technology
Management Objectives
Controls
Performance
Business Value

By the end of this lesson, you will be able to:

  • Explain the purpose of COBIT 2019.

  • distinguish governance from management.

  • understand the COBIT governance system.

  • understand governance and management objectives.

  • understand the EDM domain.

  • understand the APO domain.

  • understand the BAI domain.

  • understand the DSS domain.

  • understand the MEA domain.

  • understand COBIT principles.

  • understand governance components.

  • understand design factors.

  • understand focus areas.

  • understand goals cascade.

  • understand enterprise goals.

  • understand alignment goals.

  • understand capability levels.

  • understand performance management.

  • understand risk and compliance integration.

  • understand assurance.

  • map COBIT to enterprise controls.

  • build a COBIT-based governance model.

  • design COBIT dashboards.

  • understand how COBIT integrates with NIST, ISO, ITIL, and other frameworks.

COBIT is a framework designed to help enterprises govern and manage information and technology.

At a high level:

Stakeholder Needs
Enterprise Objectives
Governance
Management
Technology
Business Outcomes

COBIT is broader than cybersecurity.

It considers areas such as:

IT Strategy
Risk
Compliance
Security
Architecture
Projects
Operations
Service Delivery
Data
Vendors
Performance
Assurance

Technology has become fundamental to most organizations.

Businesses depend on:

Cloud Services
Applications
Data
Networks
Automation
AI
Cybersecurity
Third Parties
Digital Services

Without strong governance:

Technology Investment
Disconnected Decisions
Uncontrolled Risk
Poor Performance
Limited Business Value

COBIT helps create:

Alignment
Accountability
Risk Governance
Performance
Control
Assurance

One of the most important COBIT concepts is the difference between:

Governance

and:

Management

Governance is primarily concerned with:

Evaluate
Direct
Monitor

Leadership evaluates stakeholder needs, directs priorities, and monitors outcomes.

Conceptually:

Stakeholder Needs
Evaluate
Direct
Monitor

Management focuses on:

Plan
Build
Run
Monitor

Management executes the direction established by governance.

Governance asks:

Are We Doing
the Right Things?

Management asks:

Are We Doing
Things Right?

Both are required.

7. COBIT Governance and Management Domains

Section titled “7. COBIT Governance and Management Domains”

COBIT organizes objectives into five domains:

EDM
APO
BAI
DSS
MEA
EDM
Evaluate, Direct
and Monitor
APO
Align, Plan
and Organize
BAI
Build, Acquire
and Implement
DSS
Deliver, Service
and Support
MEA
Monitor, Evaluate
and Assess

EDM represents governance activities.

It focuses on:

Evaluate
Direct
Monitor

Examples include:

Governance Framework
Benefits Delivery
Risk Optimization
Resource Optimization
Stakeholder Engagement

Leadership evaluates:

Stakeholder Expectations
Strategic Priorities
Risk
Value
Resources
Performance

Leadership sets:

Policies
Priorities
Accountability
Risk Direction
Investment Direction

Leadership monitors:

Performance
Risk
Compliance
Benefits
Resource Use

Executive leadership wants to move critical customer systems to cloud.

Governance evaluates:

Business Benefits
Cyber Risk
Cost
Regulatory Impact
Resilience

Then directs:

Cloud Strategy
Risk Requirements
Funding
Accountability

And monitors:

Migration Progress
Cloud Risk
Cost
Service Availability
Compliance

APO stands for:

Align, Plan
and Organize

This domain focuses on setting up the management structures required to execute enterprise direction.

Areas may include:

Strategy
Architecture
Innovation
Portfolio
Budget
Human Resources
Relationships
Service Agreements
Vendors
Risk
Security
Data

Technology strategy should align with business strategy.

Conceptually:

Business Strategy
Technology Strategy
Initiatives
Projects

Weak:

Business Wants
Cloud Agility

while:

IT Strategy
Only Supports
On-Premises Systems

COBIT encourages alignment.

Architecture connects:

Business
Applications
Data
Technology

A strong architecture approach improves:

Consistency
Integration
Security
Resilience
Cost Management

Organizations must prioritize investments.

Example portfolio:

Cloud Migration
Zero Trust
ERP Upgrade
AI Program
Security Modernization

Governance should determine:

Priority
Value
Risk
Cost
Dependencies

Technology resources should be allocated based on:

Business Value
Risk
Strategy
Operational Need

Technology governance also depends on:

Skills
Roles
Responsibilities
Capacity
Training

IT must maintain effective relationships with:

Business Teams
Customers
Partners
Suppliers
Executives

Technology services should have defined expectations such as:

Availability
Performance
Support
Recovery
Security

External providers should be governed across:

Selection
Contracting
Performance
Security
Risk
Exit

COBIT connects technology risk with enterprise risk.

Technology Event
Business Impact
Enterprise Risk

Security should align with:

Business Objectives
Risk Appetite
Legal Requirements
Technology Strategy

Data is treated as a critical enterprise resource.

Governance should consider:

Ownership
Quality
Classification
Privacy
Security
Lifecycle

BAI stands for:

Build, Acquire
and Implement

This domain covers changes and solutions.

Typical areas include:

Programs
Projects
Requirements
Solution Development
Availability
Capacity
Change
Knowledge
Assets
Configuration

Large initiatives may include:

Cloud Transformation
Cybersecurity Program
ERP Modernization
Data Platform
AI Transformation

Programs need:

Governance
Funding
Risk
Benefits
Ownership

Projects should manage:

Scope
Schedule
Budget
Quality
Risk
Resources

Technology solutions should reflect:

Business Requirements
Security Requirements
Privacy Requirements
Compliance Requirements
Operational Requirements

Organizations may choose:

Build Internally
Buy Product
Use SaaS
Outsource

Governance should evaluate:

Cost
Risk
Capability
Dependency
Security
Strategic Fit

Changes should follow:

Request
Assess
Approve
Test
Implement
Validate

Uncontrolled changes can create:

Outage
Security Vulnerability
Compliance Failure
Data Loss

Organizations should maintain accurate information about:

Systems
Applications
Assets
Dependencies
Configurations

Critical operational knowledge should not exist only:

Inside
One Person's Head

Maintain:

Documentation
Runbooks
Architecture
Procedures
Lessons Learned

DSS stands for:

Deliver, Service
and Support

It focuses on operating technology services.

Areas may include:

Operations
Service Requests
Incidents
Problems
Continuity
Security Services
Business Process Controls

Operations teams manage:

Infrastructure
Applications
Jobs
Monitoring
Backups
Cloud Services

Examples:

Password Reset
Software Request
Access Request
Device Request

should follow defined workflows.

An incident is:

Unplanned Disruption
or Degradation
of Service

Examples:

Application Outage
Authentication Failure
Network Issue
Cloud Service Failure
Detect
Log
Classify
Prioritize
Resolve
Close

Problem management focuses on:

Underlying
Root Cause

Example:

Repeated Database
Outages
Root Cause
Storage Capacity
Issue

Technology services need resilience.

Consider:

RTO
RPO
Backups
Failover
Recovery
Testing

Operational security may include:

SOC
IAM
Vulnerability Management
Endpoint Security
Cloud Security
Incident Response

Technology often supports financial and operational controls.

Examples:

Payment Approval
Segregation of Duties
Automated Reconciliation
Transaction Validation

MEA stands for:

Monitor, Evaluate
and Assess

It focuses on evaluating performance, control effectiveness, and compliance.

Areas include:

Performance Monitoring
Internal Control
Compliance
Assurance

Organizations should monitor:

Service Performance
Project Performance
Risk
Control Health
Investment Benefits

Evaluate whether controls are:

Designed Properly
Implemented
Operating Effectively

Assess compliance with:

Laws
Regulations
Contracts
Policies
Standards

Assurance may be provided by:

Internal Audit
External Audit
Independent Assessors
Compliance Reviews

The Goals Cascade helps connect stakeholder needs to specific governance and management objectives.

Conceptually:

Stakeholder Drivers
Stakeholder Needs
Enterprise Goals
Alignment Goals
Governance &
Management Objectives

Enterprise goals may include:

Business Value
Risk Optimization
Regulatory Compliance
Customer Service
Operational Continuity
Innovation

Alignment goals connect technology with enterprise goals.

Examples:

Technology Risk
Managed
IT Services
Reliable
Security
Adequate
Technology Costs
Optimized

Enterprise goal:

Maintain Customer
Trust

Alignment goal:

Information Security
and Privacy

Management objectives:

Manage Security
Manage Risk
Manage Data
Manage Services

A strong governance system should:

Provide Stakeholder Value
Take a Holistic Approach
Adapt to Enterprise Needs
Separate Governance
from Management

Governance is more than:

Policies

It includes:

Processes
Structures
Information
People
Culture
Technology

COBIT describes components that support the governance system.

Examples include:

Processes
Organizational Structures
Policies and Procedures
Information
Culture and Behavior
People and Skills
Services and Infrastructure

Processes define:

Activities
Inputs
Outputs
Responsibilities

Examples:

Board
Risk Committee
Architecture Board
Security Committee
Change Advisory Board

Provide:

Direction
Consistency
Control
Expectations

Good governance depends on:

Accurate
Relevant
Complete
Timely

information.

Technology governance can fail even with strong processes if organizational culture encourages:

Bypassing Controls
Ignoring Risk
Poor Accountability

Governance requires appropriate:

Competence
Experience
Capacity
Training

Governance also depends on the technology that supports operations.

COBIT recognizes that organizations should not implement identical governance models.

Design factors help customize the governance system.

Consider:

Enterprise Strategy
Enterprise Goals
Risk Profile
Technology Issues
Threat Landscape
Compliance Requirements
Role of IT
Sourcing Model
Implementation Methods
Technology Adoption

Strategy may emphasize:

Growth
Innovation
Cost Leadership
Customer Service
Stability

Governance should reflect those priorities.

Organizations with high:

Cyber Risk
Privacy Risk
Operational Risk
Third-Party Risk

may need stronger governance around those areas.

A defense or financial organization may face more sophisticated threats than a small local business.

Governance should adapt accordingly.

Organizations operating across regulated sectors may require stronger:

Control
Audit
Documentation
Assurance

In some organizations:

IT Supports
the Business

In others:

Technology
IS the Business

This significantly changes governance requirements.

Consider:

Internal IT
Cloud
SaaS
Outsourcing
Managed Services

More outsourcing increases governance needs around suppliers.

COBIT can support specific focus areas.

Examples might include:

Cybersecurity
Digital Transformation
Cloud
Privacy
DevOps
Risk

Organizations need to understand how well governance and management objectives are performing.

This includes:

Capability
Performance
Outcomes
Metrics

Capability can be considered progressively.

Conceptually:

Incomplete
Performed
Managed
Defined
Quantitatively Managed
Optimizing

Organizations should use their approved COBIT performance approach when making formal assessments.

A process may be well documented but still:

Fail Operationally

Assessment should consider actual performance.

Level of capability might improve from:

Ad Hoc Changes

to:

Defined Process

then:

Measured Change
Performance

and eventually:

Continuous Improvement

Potential metrics include:

IT Service Availability
Project Success
Security Incidents
Risk Appetite Breaches
Change Failure Rate
Vendor Performance
Audit Findings
Control Effectiveness
Successful Changes
─────────────── × 100
Total Changes
Critical Technology
Risks Above Appetite
Privileged Access
Reviews Completed

COBIT should connect technology risk to business impact.

Example:

Cloud Outage
Customer Platform
Unavailable
Revenue Loss
Customer Impact

A risk record may include:

Risk
Business Objective
Technology Dependency
Owner
Controls
Residual Risk
Treatment

Governance does not attempt to eliminate all risk.

It seeks:

Risk
Aligned with
Enterprise Appetite

Business wants rapid digital innovation.

A zero-risk approach might:

Stop All
New Technology

which may damage business strategy.

Instead:

Innovation
+
Managed Risk

is the goal.

COBIT helps establish:

Compliance Ownership
Monitoring
Control Framework
Assurance
Reporting
Requirements
Controls
Owners
Monitoring
Assessment
Reporting

Internal Audit may use COBIT when evaluating:

IT Governance
Risk Management
IT Operations
Change Management
Security
Service Delivery

A simplified model:

1st Line
Technology Operations
2nd Line
Risk / Compliance
3rd Line
Internal Audit

Owns and operates:

Technology
Processes
Controls
Risk

Provides:

Oversight
Risk Framework
Compliance Guidance
Monitoring

Provides:

Independent Assurance

Security governance should connect:

Business Objectives
Cyber Risk
Security Strategy
Controls
Metrics
Executive Oversight

Leadership defines:

Risk Appetite

Security translates this into:

Security Requirements

Technology implements:

Controls

GRC monitors:

Risk & Compliance

Audit provides:

Independent Assurance

Cloud governance can use COBIT to structure:

Cloud Strategy
Architecture
Risk
Security
Cost
Vendors
Operations
Performance

Enterprise objective:

Improve
Time to Market

Technology strategy:

Cloud Adoption

Risks:

Cloud Misconfiguration
Cost Overrun
Vendor Lock-In
Data Exposure

Governance must balance:

Value
Risk
Resources

Outsourcing does not remove governance accountability.

Organizations should manage:

Supplier Selection
Contract
Security
Performance
Risk
Exit

Potential metrics:

Critical Vendors
SLA Breaches
High-Risk Findings
Security Incidents
Contracts Near Expiry

Simplified:

COBIT
Enterprise Governance
of Information
and Technology
NIST CSF
Cybersecurity
Risk Outcomes

They can complement each other.

COBIT:

Manage Security

may align with NIST CSF areas such as:

Govern
Protect
Detect
Respond
Recover

COBIT provides broader technology governance.

RMF provides a detailed security and privacy risk lifecycle for systems.

Conceptually:

COBIT
Enterprise Technology Governance
RMF
System Risk Management

COBIT provides governance and management structure.

CIS provides practical cybersecurity safeguards.

COBIT
Security Governance
CIS Controls
Operational Safeguards

COBIT:

Enterprise
Technology Governance

ISO 27001:

Information Security
Management System

Both can exist within the same enterprise governance architecture.

COBIT focuses heavily on:

Governance
Control
Objectives
Accountability

ITIL focuses heavily on:

IT Service
Management Practices

They can complement each other.

COBIT may establish:

Manage Service
Requests and Incidents

while ITIL provides detailed service-management practices.

A practical assessment may follow:

Define Scope
Understand Enterprise Goals
Identify Objectives
Assess Current Capability
Identify Gaps
Assess Risk
Create Improvement Plan

Examples:

Enterprise IT
Cybersecurity
Cloud Governance
IT Risk
IT Operations
Digital Transformation

107. Step 2 — Identify Stakeholder Needs

Section titled “107. Step 2 — Identify Stakeholder Needs”

Ask:

What Does
the Business
Expect from IT?

Examples:

Reliability
Innovation
Security
Compliance
Cost Efficiency

Example:

Customer Trust
Revenue Growth
Operational Resilience
Regulatory Compliance

Translate enterprise goals into technology expectations.

Example:

Operational Resilience
Reliable Technology
Services

Determine which governance and management objectives are most relevant.

Use a consistent assessment model.

Possible status:

Weak
Developing
Established
Managed
Optimized

for internal training purposes.

Examples:

Policies
Process Documentation
Committee Minutes
Metrics
Risk Registers
Tickets
Audit Reports
Dashboards

Example:

Objective:
Manage Risk
Current:
Technology risks tracked
independently by teams
Target:
Enterprise technology
risk register
Gap:
No centralized
risk governance

Ask:

What Happens
If the Gap
Remains?

115. Step 10 — Build Improvement Roadmap

Section titled “115. Step 10 — Build Improvement Roadmap”

Document:

Gap
Risk
Action
Owner
Priority
Due Date
Metric
Gap Risk Action Priority
IT risks fragmented Poor executive visibility Centralize risk register High
Changes inconsistently approved Outage/security risk Standardize change process High
Vendor metrics missing Third-party risk Build vendor dashboard Medium
IT strategy outdated Business misalignment Refresh strategy High

An executive dashboard could include:

Technology Value
Technology Risk
Service Performance
Project Performance
Compliance
Control Health
Vendor Risk
ENTERPRISE I&T GOVERNANCE
Critical Technology Risks 5
Risk Appetite Breaches 3
Critical Services Meeting SLA 96%
Major Projects On Track 82%
Critical Audit Findings 4
High-Risk Vendors 7

Governance should answer:

Did the Investment
Deliver the Expected
Business Value?

Example:

Cloud migration target:

Deployment Time
5 Days → 1 Hour

Actual:

5 Days → 3 Hours

Benefits are significant but below target.

Organizations should understand whether:

People
Technology
Budget
Data

are being used effectively.

Only One Engineer
Understands
Critical Platform

This creates:

Key Person Risk

122. Common Mistake — Treat COBIT as an IT Checklist

Section titled “122. Common Mistake — Treat COBIT as an IT Checklist”

COBIT is primarily about:

Governance
Management
Alignment
Value
Risk

not simply technical control completion.

123. Common Mistake — IT Owns Governance

Section titled “123. Common Mistake — IT Owns Governance”

Governance ultimately involves:

Executive Leadership
Board
Business Management

not only the IT department.

124. Common Mistake — Confuse Governance and Management

Section titled “124. Common Mistake — Confuse Governance and Management”

Executives should not necessarily perform operational IT management.

Management should not independently define enterprise governance direction.

125. Common Mistake — Too Many Objectives at Once

Section titled “125. Common Mistake — Too Many Objectives at Once”

Prioritize based on:

Enterprise Goals
Risk
Design Factors
Business Need

126. Common Mistake — No Business Alignment

Section titled “126. Common Mistake — No Business Alignment”

Avoid:

IT Strategy
Disconnected
from Business Strategy

127. Common Mistake — Measure Activity Instead of Value

Section titled “127. Common Mistake — Measure Activity Instead of Value”

Weak:

100 Projects
Completed

Better:

Projects Delivered
Expected Business
Benefits

128. Common Mistake — Risk Reporting Without Business Impact

Section titled “128. Common Mistake — Risk Reporting Without Business Impact”

Avoid:

15 IT Risks

Explain:

Which Business
Objectives Are
Threatened?

129. Common Mistake — Outsource Responsibility

Section titled “129. Common Mistake — Outsource Responsibility”
Vendor Manages It

does not mean:

Enterprise Has
No Accountability

A perfect process can fail if employees routinely bypass it.

131. Common Mistake — Audit Owns Controls

Section titled “131. Common Mistake — Audit Owns Controls”

Audit should generally provide independent assurance rather than operate management controls.

132. Common Mistake — Capability Score Becomes the Objective

Section titled “132. Common Mistake — Capability Score Becomes the Objective”

Higher capability should support:

Better Outcomes
Lower Risk
Higher Value

not simply better scores.

133. End-to-End Example — Cloud Transformation

Section titled “133. End-to-End Example — Cloud Transformation”

Business goal:

Accelerate
Digital Services

Governance evaluates:

Value
Risk
Investment
Strategic Fit

and directs cloud adoption.

Management establishes:

Cloud Strategy
Architecture
Security
Risk
Vendor Model

Teams:

Build Landing Zone
Migrate Applications
Implement Controls

Operations manage:

Cloud Services
Incidents
Security
Availability

Management evaluates:

Performance
Risk
Compliance
Benefits

134. End-to-End Example — Cybersecurity Governance

Section titled “134. End-to-End Example — Cybersecurity Governance”

Enterprise risk:

Ransomware

Governance:

Risk Appetite
Security Strategy
Investment

Management:

EDR
MFA
Backups
SOC
Incident Response

Monitoring:

KRIs
KCIs
Incidents
Recovery Tests

Assurance:

Internal Audit

135. End-to-End Example — IT Service Outage

Section titled “135. End-to-End Example — IT Service Outage”

Business objective:

Maintain
Customer Availability

Technology event:

Database Failure

DSS:

Incident Response

BAI:

Permanent Architecture Fix

MEA:

Review Availability Metrics

EDM:

Monitor Risk
and Resilience

Critical provider:

Cloud Provider

APO:

Vendor Governance
Risk Requirements
Contract

DSS:

Monitor Service
Performance

MEA:

Assess Compliance
and Risk

EDM:

Monitor Strategic
Dependency
Board / Executives
EDM
Governance
Enterprise Goals
Alignment Goals
APO
Planning
BAI
Change
DSS
Operations
MEA
Monitoring
Governance Reporting

A practical roadmap may follow:

Phase 1
Understand Business Context
Phase 2
Identify Stakeholder Needs
Phase 3
Define Enterprise Goals
Phase 4
Assess Design Factors
Phase 5
Prioritize COBIT Objectives
Phase 6
Assess Current Capability
Phase 7
Identify Gaps
Phase 8
Build Improvement Plan
Phase 9
Implement Governance
Phase 10
Monitor & Improve

Understand:

Strategy
Business Model
Technology Dependence
Regulation
Risk

Identify expectations of:

Board
Executives
Customers
Regulators
Employees
Partners

Define measurable business goals.

Assess:

Risk Profile
Threat Landscape
Compliance
Sourcing
Technology Strategy

Select the most relevant COBIT governance and management objectives.

Determine current performance.

Compare:

Current
vs
Target

Assign:

Action
Owner
Budget
Due Date
Metric

Update:

Structures
Processes
Policies
Technology
Metrics

Use:

Performance
Risk
Audit
Compliance
Benefits

to drive continuous improvement.

  • stakeholder needs understood.

  • governance responsibilities assigned.

  • benefits monitored.

  • enterprise technology risk monitored.

  • resources optimized.

  • stakeholder reporting established.

  • IT strategy aligned with business.

  • enterprise architecture maintained.

  • portfolio governance established.

  • budgets governed.

  • skills and capacity managed.

  • vendor management established.

  • risk management established.

  • security governance established.

  • data governance established.

  • programs governed.

  • projects managed.

  • requirements documented.

  • solution risk assessed.

  • changes controlled.

  • configuration maintained.

  • knowledge documented.

  • benefits tracked.

  • operations monitored.

  • service requests managed.

  • incidents managed.

  • root causes managed.

  • continuity maintained.

  • security services operated.

  • operational controls monitored.

  • performance monitored.

  • internal controls assessed.

  • compliance evaluated.

  • assurance activities established.

  • findings tracked.

  • management actions monitored.

After completing this lesson, you should be able to create:

01 COBIT Governance Scope
02 Stakeholder Needs Register
03 Enterprise Goals Map
04 Alignment Goals Map
05 COBIT Objective Mapping
06 Design Factor Assessment
07 IT Governance RACI
08 Technology Risk Register
09 Technology Strategy Assessment
10 Enterprise Architecture Governance Model
11 IT Portfolio Register
12 Vendor Governance Register
13 Change Governance Assessment
14 IT Service Governance Assessment
15 IT Control Framework
16 Technology Performance Dashboard
17 COBIT Capability Assessment
18 COBIT Gap Register
19 COBIT Improvement Roadmap
20 Executive I&T Governance Dashboard

Practical Activity — Build a Goals Cascade

Section titled “Practical Activity — Build a Goals Cascade”

Scenario:

Business Goal:
Improve Customer
Digital Experience

Identify:

Stakeholder Need
Enterprise Goal
Alignment Goal
Relevant COBIT Objectives

Then explain how technology governance supports the business goal.

Practical Activity — Assess Technology Risk Governance

Section titled “Practical Activity — Assess Technology Risk Governance”

Your organization has:

AWS
Azure
Microsoft 365
Customer SaaS
Critical Vendors

Technology risks are currently stored in separate spreadsheets.

Assess:

Current State
Risk
Governance Gap
Target State
Owner
Priority

Design a centralized technology risk-governance model.

Practical Activity — Assess Change Governance

Section titled “Practical Activity — Assess Change Governance”

Current state:

Developers Can
Deploy Directly
to Production

Incidents show:

25% of Production
Outages Follow Changes

Determine:

Governance Concern
Relevant Management Objective
Control Improvements
KPI
KRI

Practical Activity — Build an Executive Governance Dashboard

Section titled “Practical Activity — Build an Executive Governance Dashboard”

Include:

Technology Value
Technology Risk
Service Availability
Project Performance
Control Health
Compliance
Vendor Risk
Audit Findings

Then identify:

What Requires
Executive Decision?

When applying COBIT, ask:

What Does
the Business
Need from Technology?
Who Are
the Stakeholders?
What Enterprise
Goals Matter?
How Does
Technology Support
Those Goals?
Who Governs
Technology?
Who Manages
Technology?
Are Governance
and Management
Clearly Separated?
Are Technology
Investments Delivering
Business Value?
Are Technology
Risks Within Appetite?
Are Resources
Used Effectively?
Is Technology
Strategy Aligned
with Business Strategy?
Is Architecture
Governed?
Are Programs
Delivering Benefits?
Are Projects
Controlled?
Are Changes
Managed?
Are Services
Reliable?
Are Incidents
Handled?
Are Root Causes
Addressed?
Can Critical
Services Recover?
Are Security
Services Effective?
Are Vendors
Governed?
Are Controls
Operating?
Are Compliance
Requirements Met?
Is Assurance
Independent?
Are Metrics
Useful?
Are We Measuring
Activity?
Or Are We
Measuring Value?
Are Technology
Decisions Supporting
Enterprise Strategy?
Can Leadership
Trust the Information?
Is Governance
Driving Better
Business Outcomes?

That is the mindset of a GRC professional using COBIT 2019.

  • COBIT 2019 is a framework for governance and management of enterprise information and technology.

  • COBIT is broader than cybersecurity and includes strategy, architecture, projects, operations, risk, compliance, service delivery, and assurance.

  • Governance and management are distinct.

  • Governance evaluates stakeholder needs, directs priorities, and monitors outcomes.

  • Management plans, builds, operates, and monitors activities to achieve governance direction.

  • EDM represents governance.

  • APO focuses on alignment, planning, and organization.

  • BAI focuses on building, acquiring, implementing, and managing change.

  • DSS focuses on delivering and supporting technology services.

  • MEA focuses on monitoring, evaluating, compliance, controls, and assurance.

  • COBIT’s Goals Cascade connects stakeholder needs to enterprise goals, alignment goals, and governance or management objectives.

  • Governance should focus on stakeholder value.

  • Technology strategy should align with business strategy.

  • COBIT uses a holistic governance system involving processes, structures, information, people, culture, and technology.

  • Design factors help tailor governance to the organization.

  • Technology governance should reflect enterprise strategy, risk profile, threat landscape, compliance, sourcing, and technology dependence.

  • Capability assessment should support business outcomes rather than become a scoring exercise.

  • Technology risk should be connected to business impact.

  • Risk optimization means managing risk within enterprise appetite, not eliminating all risk.

  • Outsourcing does not remove enterprise accountability.

  • Internal Audit should provide independent assurance rather than own management controls.

  • COBIT can complement NIST CSF, NIST RMF, CIS Controls, ISO 27001, and ITIL.

  • Executive reporting should connect technology value, risk, performance, compliance, and management action.

  • COBIT should be treated as an enterprise governance system rather than an IT checklist.

Before continuing, make sure you can answer:

  1. What is COBIT 2019?

  2. What is the primary purpose of COBIT?

  3. What is the difference between governance and management?

  4. What does EDM stand for?

  5. What happens in the EDM domain?

  6. What does APO stand for?

  7. What activities belong to APO?

  8. What does BAI stand for?

  9. What activities belong to BAI?

  10. What does DSS stand for?

  11. What activities belong to DSS?

  12. What does MEA stand for?

  13. What activities belong to MEA?

  14. What is the COBIT Goals Cascade?

  15. What are stakeholder needs?

  16. What are enterprise goals?

  17. What are alignment goals?

  18. What are governance components?

  19. Why is culture important to governance?

  20. What are COBIT design factors?

  21. Why should governance systems be customized?

  22. What is a technology risk profile?

  23. How does sourcing affect governance?

  24. What is capability assessment?

  25. Why should capability scores not become the primary objective?

  26. How does COBIT support enterprise risk management?

  27. What is risk optimization?

  28. How does COBIT support compliance?

  29. How can COBIT support Internal Audit?

  30. What is the difference between first, second, and third lines?

  31. How does COBIT support cybersecurity governance?

  32. How can COBIT support cloud governance?

  33. How does COBIT support third-party governance?

  34. How does COBIT differ from NIST CSF?

  35. How does COBIT complement NIST RMF?

  36. How can CIS Controls complement COBIT?

  37. How can COBIT and ISO 27001 work together?

  38. How can COBIT and ITIL complement one another?

  39. What should a COBIT executive dashboard contain?

  40. What makes a COBIT governance program effective?

➡️ Next: 05 — ISO 31000 Risk Management

In the next lesson, you will move from governance of enterprise information and technology into a broader enterprise risk-management framework.

You will learn how ISO 31000 structures risk management around:

Leadership & Commitment
Integration
Design
Implementation
Evaluation
Improvement

and how the risk-management process connects:

Scope & Context
Risk Identification
Risk Analysis
Risk Evaluation
Risk Treatment
Monitoring & Review
Communication & Consultation

The focus will be on understanding how organizations create a consistent enterprise approach for identifying, evaluating, treating, monitoring, and communicating risk across cybersecurity, technology, operational, third-party, privacy, compliance, financial, and strategic domains.

➡️ Next: 05 — ISO 31000 Risk Management