04 COBIT 2019
COBIT 2019 is a framework for the governance and management of enterprise information and technology.
Where frameworks such as:
NIST CSFfocus on cybersecurity outcomes, and:
CIS Controlsfocus on practical cybersecurity safeguards, COBIT takes a broader enterprise view.
It helps organizations answer questions such as:
Are Technology InvestmentsSupporting Business Goals?
Who Is Accountablefor Technology Decisions?
Are Risks Being Managed?
Are Controls Effective?
Are Technology ServicesDelivering Value?
Are We MeetingRegulatory Requirements?
How Do We MeasureTechnology Performance?
How Does LeadershipGovern Informationand Technology?COBIT connects:
Enterprise Strategy ↓Stakeholder Needs ↓Governance ↓Information & Technology ↓Management Objectives ↓Controls ↓Performance ↓Business ValueLearning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the purpose of COBIT 2019.
-
distinguish governance from management.
-
understand the COBIT governance system.
-
understand governance and management objectives.
-
understand the EDM domain.
-
understand the APO domain.
-
understand the BAI domain.
-
understand the DSS domain.
-
understand the MEA domain.
-
understand COBIT principles.
-
understand governance components.
-
understand design factors.
-
understand focus areas.
-
understand goals cascade.
-
understand enterprise goals.
-
understand alignment goals.
-
understand capability levels.
-
understand performance management.
-
understand risk and compliance integration.
-
understand assurance.
-
map COBIT to enterprise controls.
-
build a COBIT-based governance model.
-
design COBIT dashboards.
-
understand how COBIT integrates with NIST, ISO, ITIL, and other frameworks.
1. What Is COBIT?
Section titled “1. What Is COBIT?”COBIT is a framework designed to help enterprises govern and manage information and technology.
At a high level:
Stakeholder Needs ↓Enterprise Objectives ↓Governance ↓Management ↓Technology ↓Business OutcomesCOBIT is broader than cybersecurity.
It considers areas such as:
IT Strategy
Risk
Compliance
Security
Architecture
Projects
Operations
Service Delivery
Data
Vendors
Performance
Assurance2. Why COBIT Exists
Section titled “2. Why COBIT Exists”Technology has become fundamental to most organizations.
Businesses depend on:
Cloud Services
Applications
Data
Networks
Automation
AI
Cybersecurity
Third Parties
Digital ServicesWithout strong governance:
Technology Investment ↓Disconnected Decisions ↓Uncontrolled Risk ↓Poor Performance ↓Limited Business ValueCOBIT helps create:
Alignment
Accountability
Risk Governance
Performance
Control
Assurance3. Governance vs Management
Section titled “3. Governance vs Management”One of the most important COBIT concepts is the difference between:
Governanceand:
Management4. Governance
Section titled “4. Governance”Governance is primarily concerned with:
Evaluate
Direct
MonitorLeadership evaluates stakeholder needs, directs priorities, and monitors outcomes.
Conceptually:
Stakeholder Needs ↓Evaluate ↓Direct ↓Monitor5. Management
Section titled “5. Management”Management focuses on:
Plan
Build
Run
MonitorManagement executes the direction established by governance.
6. Simple Difference
Section titled “6. Simple Difference”Governance asks:
Are We Doingthe Right Things?Management asks:
Are We DoingThings Right?Both are required.
7. COBIT Governance and Management Domains
Section titled “7. COBIT Governance and Management Domains”COBIT organizes objectives into five domains:
EDM
APO
BAI
DSS
MEA8. Domain Overview
Section titled “8. Domain Overview”EDMEvaluate, Directand Monitor
APOAlign, Planand Organize
BAIBuild, Acquireand Implement
DSSDeliver, Serviceand Support
MEAMonitor, Evaluateand Assess9. Governance Domain — EDM
Section titled “9. Governance Domain — EDM”EDM represents governance activities.
It focuses on:
Evaluate
Direct
MonitorExamples include:
Governance Framework
Benefits Delivery
Risk Optimization
Resource Optimization
Stakeholder Engagement10. EDM — Evaluate
Section titled “10. EDM — Evaluate”Leadership evaluates:
Stakeholder Expectations
Strategic Priorities
Risk
Value
Resources
Performance11. EDM — Direct
Section titled “11. EDM — Direct”Leadership sets:
Policies
Priorities
Accountability
Risk Direction
Investment Direction12. EDM — Monitor
Section titled “12. EDM — Monitor”Leadership monitors:
Performance
Risk
Compliance
Benefits
Resource Use13. EDM Example
Section titled “13. EDM Example”Executive leadership wants to move critical customer systems to cloud.
Governance evaluates:
Business Benefits
Cyber Risk
Cost
Regulatory Impact
ResilienceThen directs:
Cloud Strategy
Risk Requirements
Funding
AccountabilityAnd monitors:
Migration Progress
Cloud Risk
Cost
Service Availability
Compliance14. Management Domain — APO
Section titled “14. Management Domain — APO”APO stands for:
Align, Planand OrganizeThis domain focuses on setting up the management structures required to execute enterprise direction.
Areas may include:
Strategy
Architecture
Innovation
Portfolio
Budget
Human Resources
Relationships
Service Agreements
Vendors
Risk
Security
Data15. APO and Strategy
Section titled “15. APO and Strategy”Technology strategy should align with business strategy.
Conceptually:
Business Strategy ↓Technology Strategy ↓Initiatives ↓Projects16. Strategy Misalignment
Section titled “16. Strategy Misalignment”Weak:
Business WantsCloud Agilitywhile:
IT StrategyOnly SupportsOn-Premises SystemsCOBIT encourages alignment.
17. Enterprise Architecture
Section titled “17. Enterprise Architecture”Architecture connects:
Business
Applications
Data
TechnologyA strong architecture approach improves:
Consistency
Integration
Security
Resilience
Cost Management18. Portfolio Management
Section titled “18. Portfolio Management”Organizations must prioritize investments.
Example portfolio:
Cloud Migration
Zero Trust
ERP Upgrade
AI Program
Security ModernizationGovernance should determine:
Priority
Value
Risk
Cost
Dependencies19. Budget and Cost Management
Section titled “19. Budget and Cost Management”Technology resources should be allocated based on:
Business Value
Risk
Strategy
Operational Need20. Human Resources
Section titled “20. Human Resources”Technology governance also depends on:
Skills
Roles
Responsibilities
Capacity
Training21. Relationship Management
Section titled “21. Relationship Management”IT must maintain effective relationships with:
Business Teams
Customers
Partners
Suppliers
Executives22. Service Agreements
Section titled “22. Service Agreements”Technology services should have defined expectations such as:
Availability
Performance
Support
Recovery
Security23. Vendor Management
Section titled “23. Vendor Management”External providers should be governed across:
Selection
Contracting
Performance
Security
Risk
Exit24. Risk Management
Section titled “24. Risk Management”COBIT connects technology risk with enterprise risk.
Technology Event ↓Business Impact ↓Enterprise Risk25. Security Management
Section titled “25. Security Management”Security should align with:
Business Objectives
Risk Appetite
Legal Requirements
Technology Strategy26. Data Management
Section titled “26. Data Management”Data is treated as a critical enterprise resource.
Governance should consider:
Ownership
Quality
Classification
Privacy
Security
Lifecycle27. Management Domain — BAI
Section titled “27. Management Domain — BAI”BAI stands for:
Build, Acquireand ImplementThis domain covers changes and solutions.
Typical areas include:
Programs
Projects
Requirements
Solution Development
Availability
Capacity
Change
Knowledge
Assets
Configuration28. Program Management
Section titled “28. Program Management”Large initiatives may include:
Cloud Transformation
Cybersecurity Program
ERP Modernization
Data Platform
AI TransformationPrograms need:
Governance
Funding
Risk
Benefits
Ownership29. Project Management
Section titled “29. Project Management”Projects should manage:
Scope
Schedule
Budget
Quality
Risk
Resources30. Requirements Management
Section titled “30. Requirements Management”Technology solutions should reflect:
Business Requirements
Security Requirements
Privacy Requirements
Compliance Requirements
Operational Requirements31. Build vs Buy
Section titled “31. Build vs Buy”Organizations may choose:
Build Internally
Buy Product
Use SaaS
OutsourceGovernance should evaluate:
Cost
Risk
Capability
Dependency
Security
Strategic Fit32. Change Management
Section titled “32. Change Management”Changes should follow:
Request ↓Assess ↓Approve ↓Test ↓Implement ↓Validate33. Poor Change Management
Section titled “33. Poor Change Management”Uncontrolled changes can create:
Outage
Security Vulnerability
Compliance Failure
Data Loss34. Configuration Management
Section titled “34. Configuration Management”Organizations should maintain accurate information about:
Systems
Applications
Assets
Dependencies
Configurations35. Knowledge Management
Section titled “35. Knowledge Management”Critical operational knowledge should not exist only:
InsideOne Person's HeadMaintain:
Documentation
Runbooks
Architecture
Procedures
Lessons Learned36. Management Domain — DSS
Section titled “36. Management Domain — DSS”DSS stands for:
Deliver, Serviceand SupportIt focuses on operating technology services.
Areas may include:
Operations
Service Requests
Incidents
Problems
Continuity
Security Services
Business Process Controls37. IT Operations
Section titled “37. IT Operations”Operations teams manage:
Infrastructure
Applications
Jobs
Monitoring
Backups
Cloud Services38. Service Requests
Section titled “38. Service Requests”Examples:
Password Reset
Software Request
Access Request
Device Requestshould follow defined workflows.
39. Incident Management
Section titled “39. Incident Management”An incident is:
Unplanned Disruptionor Degradationof ServiceExamples:
Application Outage
Authentication Failure
Network Issue
Cloud Service Failure40. Incident Lifecycle
Section titled “40. Incident Lifecycle”Detect ↓Log ↓Classify ↓Prioritize ↓Resolve ↓Close41. Problem Management
Section titled “41. Problem Management”Problem management focuses on:
UnderlyingRoot CauseExample:
Repeated DatabaseOutages ↓Root Cause ↓Storage CapacityIssue42. Continuity
Section titled “42. Continuity”Technology services need resilience.
Consider:
RTO
RPO
Backups
Failover
Recovery
Testing43. Security Services
Section titled “43. Security Services”Operational security may include:
SOC
IAM
Vulnerability Management
Endpoint Security
Cloud Security
Incident Response44. Business Process Controls
Section titled “44. Business Process Controls”Technology often supports financial and operational controls.
Examples:
Payment Approval
Segregation of Duties
Automated Reconciliation
Transaction Validation45. Management Domain — MEA
Section titled “45. Management Domain — MEA”MEA stands for:
Monitor, Evaluateand AssessIt focuses on evaluating performance, control effectiveness, and compliance.
Areas include:
Performance Monitoring
Internal Control
Compliance
Assurance46. Performance Monitoring
Section titled “46. Performance Monitoring”Organizations should monitor:
Service Performance
Project Performance
Risk
Control Health
Investment Benefits47. Internal Control Monitoring
Section titled “47. Internal Control Monitoring”Evaluate whether controls are:
Designed Properly
Implemented
Operating Effectively48. Compliance Monitoring
Section titled “48. Compliance Monitoring”Assess compliance with:
Laws
Regulations
Contracts
Policies
Standards49. Assurance
Section titled “49. Assurance”Assurance may be provided by:
Internal Audit
External Audit
Independent Assessors
Compliance Reviews50. COBIT Goals Cascade
Section titled “50. COBIT Goals Cascade”The Goals Cascade helps connect stakeholder needs to specific governance and management objectives.
Conceptually:
Stakeholder Drivers ↓Stakeholder Needs ↓Enterprise Goals ↓Alignment Goals ↓Governance &Management Objectives51. Enterprise Goals
Section titled “51. Enterprise Goals”Enterprise goals may include:
Business Value
Risk Optimization
Regulatory Compliance
Customer Service
Operational Continuity
Innovation52. Alignment Goals
Section titled “52. Alignment Goals”Alignment goals connect technology with enterprise goals.
Examples:
Technology RiskManaged
IT ServicesReliable
SecurityAdequate
Technology CostsOptimized53. Goals Cascade Example
Section titled “53. Goals Cascade Example”Enterprise goal:
Maintain CustomerTrustAlignment goal:
Information Securityand PrivacyManagement objectives:
Manage Security
Manage Risk
Manage Data
Manage Services54. Governance System Principles
Section titled “54. Governance System Principles”A strong governance system should:
Provide Stakeholder Value
Take a Holistic Approach
Adapt to Enterprise Needs
Separate Governancefrom Management55. Holistic Approach
Section titled “55. Holistic Approach”Governance is more than:
PoliciesIt includes:
Processes
Structures
Information
People
Culture
Technology56. Governance Components
Section titled “56. Governance Components”COBIT describes components that support the governance system.
Examples include:
Processes
Organizational Structures
Policies and Procedures
Information
Culture and Behavior
People and Skills
Services and Infrastructure57. Processes
Section titled “57. Processes”Processes define:
Activities
Inputs
Outputs
Responsibilities58. Organizational Structures
Section titled “58. Organizational Structures”Examples:
Board
Risk Committee
Architecture Board
Security Committee
Change Advisory Board59. Policies and Procedures
Section titled “59. Policies and Procedures”Provide:
Direction
Consistency
Control
Expectations60. Information
Section titled “60. Information”Good governance depends on:
Accurate
Relevant
Complete
Timelyinformation.
61. Culture and Behavior
Section titled “61. Culture and Behavior”Technology governance can fail even with strong processes if organizational culture encourages:
Bypassing Controls
Ignoring Risk
Poor Accountability62. People and Skills
Section titled “62. People and Skills”Governance requires appropriate:
Competence
Experience
Capacity
Training63. Services and Infrastructure
Section titled “63. Services and Infrastructure”Governance also depends on the technology that supports operations.
64. Design Factors
Section titled “64. Design Factors”COBIT recognizes that organizations should not implement identical governance models.
Design factors help customize the governance system.
65. Examples of Design Factors
Section titled “65. Examples of Design Factors”Consider:
Enterprise Strategy
Enterprise Goals
Risk Profile
Technology Issues
Threat Landscape
Compliance Requirements
Role of IT
Sourcing Model
Implementation Methods
Technology Adoption66. Enterprise Strategy
Section titled “66. Enterprise Strategy”Strategy may emphasize:
Growth
Innovation
Cost Leadership
Customer Service
StabilityGovernance should reflect those priorities.
67. Risk Profile
Section titled “67. Risk Profile”Organizations with high:
Cyber Risk
Privacy Risk
Operational Risk
Third-Party Riskmay need stronger governance around those areas.
68. Threat Landscape
Section titled “68. Threat Landscape”A defense or financial organization may face more sophisticated threats than a small local business.
Governance should adapt accordingly.
69. Compliance Requirements
Section titled “69. Compliance Requirements”Organizations operating across regulated sectors may require stronger:
Control
Audit
Documentation
Assurance70. Role of IT
Section titled “70. Role of IT”In some organizations:
IT Supportsthe BusinessIn others:
TechnologyIS the BusinessThis significantly changes governance requirements.
71. Sourcing Model
Section titled “71. Sourcing Model”Consider:
Internal IT
Cloud
SaaS
Outsourcing
Managed ServicesMore outsourcing increases governance needs around suppliers.
72. Focus Areas
Section titled “72. Focus Areas”COBIT can support specific focus areas.
Examples might include:
Cybersecurity
Digital Transformation
Cloud
Privacy
DevOps
Risk73. COBIT Performance Management
Section titled “73. COBIT Performance Management”Organizations need to understand how well governance and management objectives are performing.
This includes:
Capability
Performance
Outcomes
Metrics74. Capability Levels
Section titled “74. Capability Levels”Capability can be considered progressively.
Conceptually:
Incomplete ↓Performed ↓Managed ↓Defined ↓Quantitatively Managed ↓OptimizingOrganizations should use their approved COBIT performance approach when making formal assessments.
75. Capability Is Not Just Documentation
Section titled “75. Capability Is Not Just Documentation”A process may be well documented but still:
Fail OperationallyAssessment should consider actual performance.
76. Example — Change Management
Section titled “76. Example — Change Management”Level of capability might improve from:
Ad Hoc Changesto:
Defined Processthen:
Measured ChangePerformanceand eventually:
Continuous Improvement77. COBIT Metrics
Section titled “77. COBIT Metrics”Potential metrics include:
IT Service Availability
Project Success
Security Incidents
Risk Appetite Breaches
Change Failure Rate
Vendor Performance
Audit Findings
Control Effectiveness78. KPI Example
Section titled “78. KPI Example”Successful Changes─────────────── × 100Total Changes79. KRI Example
Section titled “79. KRI Example”Critical TechnologyRisks Above Appetite80. KCI Example
Section titled “80. KCI Example”Privileged AccessReviews Completed81. COBIT and Enterprise Risk
Section titled “81. COBIT and Enterprise Risk”COBIT should connect technology risk to business impact.
Example:
Cloud Outage ↓Customer PlatformUnavailable ↓Revenue Loss ↓Customer Impact82. Technology Risk Register
Section titled “82. Technology Risk Register”A risk record may include:
Risk
Business Objective
Technology Dependency
Owner
Controls
Residual Risk
Treatment83. Risk Optimization
Section titled “83. Risk Optimization”Governance does not attempt to eliminate all risk.
It seeks:
RiskAligned withEnterprise Appetite84. Example
Section titled “84. Example”Business wants rapid digital innovation.
A zero-risk approach might:
Stop AllNew Technologywhich may damage business strategy.
Instead:
Innovation +Managed Riskis the goal.
85. COBIT and Compliance
Section titled “85. COBIT and Compliance”COBIT helps establish:
Compliance Ownership
Monitoring
Control Framework
Assurance
Reporting86. Compliance Operating Model
Section titled “86. Compliance Operating Model”Requirements ↓Controls ↓Owners ↓Monitoring ↓Assessment ↓Reporting87. COBIT and Internal Audit
Section titled “87. COBIT and Internal Audit”Internal Audit may use COBIT when evaluating:
IT Governance
Risk Management
IT Operations
Change Management
Security
Service Delivery88. Three Lines Perspective
Section titled “88. Three Lines Perspective”A simplified model:
1st LineTechnology Operations
2nd LineRisk / Compliance
3rd LineInternal Audit89. First Line
Section titled “89. First Line”Owns and operates:
Technology
Processes
Controls
Risk90. Second Line
Section titled “90. Second Line”Provides:
Oversight
Risk Framework
Compliance Guidance
Monitoring91. Third Line
Section titled “91. Third Line”Provides:
Independent Assurance92. COBIT and Security Governance
Section titled “92. COBIT and Security Governance”Security governance should connect:
Business Objectives ↓Cyber Risk ↓Security Strategy ↓Controls ↓Metrics ↓Executive Oversight93. Example Security Governance
Section titled “93. Example Security Governance”Leadership defines:
Risk AppetiteSecurity translates this into:
Security RequirementsTechnology implements:
ControlsGRC monitors:
Risk & ComplianceAudit provides:
Independent Assurance94. COBIT and Cloud Governance
Section titled “94. COBIT and Cloud Governance”Cloud governance can use COBIT to structure:
Cloud Strategy
Architecture
Risk
Security
Cost
Vendors
Operations
Performance95. Cloud Example
Section titled “95. Cloud Example”Enterprise objective:
ImproveTime to MarketTechnology strategy:
Cloud AdoptionRisks:
Cloud Misconfiguration
Cost Overrun
Vendor Lock-In
Data ExposureGovernance must balance:
Value
Risk
Resources96. COBIT and Third-Party Governance
Section titled “96. COBIT and Third-Party Governance”Outsourcing does not remove governance accountability.
Organizations should manage:
Supplier Selection
Contract
Security
Performance
Risk
Exit97. Vendor Dashboard
Section titled “97. Vendor Dashboard”Potential metrics:
Critical Vendors
SLA Breaches
High-Risk Findings
Security Incidents
Contracts Near Expiry98. COBIT and NIST CSF
Section titled “98. COBIT and NIST CSF”Simplified:
COBIT ↓Enterprise Governanceof Informationand TechnologyNIST CSF ↓CybersecurityRisk OutcomesThey can complement each other.
99. Example Integration
Section titled “99. Example Integration”COBIT:
Manage Securitymay align with NIST CSF areas such as:
Govern
Protect
Detect
Respond
Recover100. COBIT and NIST RMF
Section titled “100. COBIT and NIST RMF”COBIT provides broader technology governance.
RMF provides a detailed security and privacy risk lifecycle for systems.
Conceptually:
COBITEnterprise Technology Governance ↓RMFSystem Risk Management101. COBIT and CIS Controls
Section titled “101. COBIT and CIS Controls”COBIT provides governance and management structure.
CIS provides practical cybersecurity safeguards.
COBIT ↓Security Governance ↓CIS Controls ↓Operational Safeguards102. COBIT and ISO 27001
Section titled “102. COBIT and ISO 27001”COBIT:
EnterpriseTechnology GovernanceISO 27001:
Information SecurityManagement SystemBoth can exist within the same enterprise governance architecture.
103. COBIT and ITIL
Section titled “103. COBIT and ITIL”COBIT focuses heavily on:
Governance
Control
Objectives
AccountabilityITIL focuses heavily on:
IT ServiceManagement PracticesThey can complement each other.
104. Example
Section titled “104. Example”COBIT may establish:
Manage ServiceRequests and Incidentswhile ITIL provides detailed service-management practices.
105. COBIT Assessment
Section titled “105. COBIT Assessment”A practical assessment may follow:
Define Scope ↓Understand Enterprise Goals ↓Identify Objectives ↓Assess Current Capability ↓Identify Gaps ↓Assess Risk ↓Create Improvement Plan106. Step 1 — Define Scope
Section titled “106. Step 1 — Define Scope”Examples:
Enterprise IT
Cybersecurity
Cloud Governance
IT Risk
IT Operations
Digital Transformation107. Step 2 — Identify Stakeholder Needs
Section titled “107. Step 2 — Identify Stakeholder Needs”Ask:
What Doesthe BusinessExpect from IT?Examples:
Reliability
Innovation
Security
Compliance
Cost Efficiency108. Step 3 — Identify Enterprise Goals
Section titled “108. Step 3 — Identify Enterprise Goals”Example:
Customer Trust
Revenue Growth
Operational Resilience
Regulatory Compliance109. Step 4 — Identify Alignment Goals
Section titled “109. Step 4 — Identify Alignment Goals”Translate enterprise goals into technology expectations.
Example:
Operational Resilience ↓Reliable TechnologyServices110. Step 5 — Identify COBIT Objectives
Section titled “110. Step 5 — Identify COBIT Objectives”Determine which governance and management objectives are most relevant.
111. Step 6 — Assess Current Capability
Section titled “111. Step 6 — Assess Current Capability”Use a consistent assessment model.
Possible status:
Weak
Developing
Established
Managed
Optimizedfor internal training purposes.
112. Step 7 — Collect Evidence
Section titled “112. Step 7 — Collect Evidence”Examples:
Policies
Process Documentation
Committee Minutes
Metrics
Risk Registers
Tickets
Audit Reports
Dashboards113. Step 8 — Identify Gaps
Section titled “113. Step 8 — Identify Gaps”Example:
Objective:Manage Risk
Current:Technology risks trackedindependently by teams
Target:Enterprise technologyrisk register
Gap:No centralizedrisk governance114. Step 9 — Assess Business Impact
Section titled “114. Step 9 — Assess Business Impact”Ask:
What HappensIf the GapRemains?115. Step 10 — Build Improvement Roadmap
Section titled “115. Step 10 — Build Improvement Roadmap”Document:
Gap
Risk
Action
Owner
Priority
Due Date
Metric116. Example Improvement Register
Section titled “116. Example Improvement Register”| Gap | Risk | Action | Priority |
|---|---|---|---|
| IT risks fragmented | Poor executive visibility | Centralize risk register | High |
| Changes inconsistently approved | Outage/security risk | Standardize change process | High |
| Vendor metrics missing | Third-party risk | Build vendor dashboard | Medium |
| IT strategy outdated | Business misalignment | Refresh strategy | High |
117. COBIT Governance Dashboard
Section titled “117. COBIT Governance Dashboard”An executive dashboard could include:
Technology Value
Technology Risk
Service Performance
Project Performance
Compliance
Control Health
Vendor Risk118. Example Dashboard
Section titled “118. Example Dashboard”ENTERPRISE I&T GOVERNANCE
Critical Technology Risks 5
Risk Appetite Breaches 3
Critical Services Meeting SLA 96%
Major Projects On Track 82%
Critical Audit Findings 4
High-Risk Vendors 7119. Benefits Reporting
Section titled “119. Benefits Reporting”Governance should answer:
Did the InvestmentDeliver the ExpectedBusiness Value?Example:
Cloud migration target:
Deployment Time5 Days → 1 HourActual:
5 Days → 3 HoursBenefits are significant but below target.
120. Resource Optimization
Section titled “120. Resource Optimization”Organizations should understand whether:
People
Technology
Budget
Dataare being used effectively.
121. Example Resource Risk
Section titled “121. Example Resource Risk”Only One EngineerUnderstandsCritical PlatformThis creates:
Key Person Risk122. Common Mistake — Treat COBIT as an IT Checklist
Section titled “122. Common Mistake — Treat COBIT as an IT Checklist”COBIT is primarily about:
Governance
Management
Alignment
Value
Risknot simply technical control completion.
123. Common Mistake — IT Owns Governance
Section titled “123. Common Mistake — IT Owns Governance”Governance ultimately involves:
Executive Leadership
Board
Business Managementnot only the IT department.
124. Common Mistake — Confuse Governance and Management
Section titled “124. Common Mistake — Confuse Governance and Management”Executives should not necessarily perform operational IT management.
Management should not independently define enterprise governance direction.
125. Common Mistake — Too Many Objectives at Once
Section titled “125. Common Mistake — Too Many Objectives at Once”Prioritize based on:
Enterprise Goals
Risk
Design Factors
Business Need126. Common Mistake — No Business Alignment
Section titled “126. Common Mistake — No Business Alignment”Avoid:
IT StrategyDisconnectedfrom Business Strategy127. Common Mistake — Measure Activity Instead of Value
Section titled “127. Common Mistake — Measure Activity Instead of Value”Weak:
100 ProjectsCompletedBetter:
Projects DeliveredExpected BusinessBenefits128. Common Mistake — Risk Reporting Without Business Impact
Section titled “128. Common Mistake — Risk Reporting Without Business Impact”Avoid:
15 IT RisksExplain:
Which BusinessObjectives AreThreatened?129. Common Mistake — Outsource Responsibility
Section titled “129. Common Mistake — Outsource Responsibility”Vendor Manages Itdoes not mean:
Enterprise HasNo Accountability130. Common Mistake — Ignore Culture
Section titled “130. Common Mistake — Ignore Culture”A perfect process can fail if employees routinely bypass it.
131. Common Mistake — Audit Owns Controls
Section titled “131. Common Mistake — Audit Owns Controls”Audit should generally provide independent assurance rather than operate management controls.
132. Common Mistake — Capability Score Becomes the Objective
Section titled “132. Common Mistake — Capability Score Becomes the Objective”Higher capability should support:
Better Outcomes
Lower Risk
Higher Valuenot simply better scores.
133. End-to-End Example — Cloud Transformation
Section titled “133. End-to-End Example — Cloud Transformation”Business goal:
AccelerateDigital ServicesGovernance evaluates:
Value
Risk
Investment
Strategic Fitand directs cloud adoption.
Management establishes:
Cloud Strategy
Architecture
Security
Risk
Vendor ModelTeams:
Build Landing Zone
Migrate Applications
Implement ControlsOperations manage:
Cloud Services
Incidents
Security
AvailabilityManagement evaluates:
Performance
Risk
Compliance
Benefits134. End-to-End Example — Cybersecurity Governance
Section titled “134. End-to-End Example — Cybersecurity Governance”Enterprise risk:
RansomwareGovernance:
Risk Appetite
Security Strategy
InvestmentManagement:
EDR
MFA
Backups
SOC
Incident ResponseMonitoring:
KRIs
KCIs
Incidents
Recovery TestsAssurance:
Internal Audit135. End-to-End Example — IT Service Outage
Section titled “135. End-to-End Example — IT Service Outage”Business objective:
MaintainCustomer AvailabilityTechnology event:
Database FailureDSS:
Incident ResponseBAI:
Permanent Architecture FixMEA:
Review Availability MetricsEDM:
Monitor Riskand Resilience136. End-to-End Example — Vendor Risk
Section titled “136. End-to-End Example — Vendor Risk”Critical provider:
Cloud ProviderAPO:
Vendor Governance
Risk Requirements
ContractDSS:
Monitor ServicePerformanceMEA:
Assess Complianceand RiskEDM:
Monitor StrategicDependency137. Enterprise COBIT Operating Model
Section titled “137. Enterprise COBIT Operating Model”Board / Executives ↓EDMGovernance ↓Enterprise Goals ↓Alignment Goals ↓APOPlanning ↓BAIChange ↓DSSOperations ↓MEAMonitoring ↓Governance Reporting138. COBIT Implementation Roadmap
Section titled “138. COBIT Implementation Roadmap”A practical roadmap may follow:
Phase 1Understand Business Context
Phase 2Identify Stakeholder Needs
Phase 3Define Enterprise Goals
Phase 4Assess Design Factors
Phase 5Prioritize COBIT Objectives
Phase 6Assess Current Capability
Phase 7Identify Gaps
Phase 8Build Improvement Plan
Phase 9Implement Governance
Phase 10Monitor & Improve139. Phase 1 — Business Context
Section titled “139. Phase 1 — Business Context”Understand:
Strategy
Business Model
Technology Dependence
Regulation
Risk140. Phase 2 — Stakeholder Needs
Section titled “140. Phase 2 — Stakeholder Needs”Identify expectations of:
Board
Executives
Customers
Regulators
Employees
Partners141. Phase 3 — Enterprise Goals
Section titled “141. Phase 3 — Enterprise Goals”Define measurable business goals.
142. Phase 4 — Design Factors
Section titled “142. Phase 4 — Design Factors”Assess:
Risk Profile
Threat Landscape
Compliance
Sourcing
Technology Strategy143. Phase 5 — Prioritize Objectives
Section titled “143. Phase 5 — Prioritize Objectives”Select the most relevant COBIT governance and management objectives.
144. Phase 6 — Assess Capability
Section titled “144. Phase 6 — Assess Capability”Determine current performance.
145. Phase 7 — Identify Gaps
Section titled “145. Phase 7 — Identify Gaps”Compare:
Current vsTarget146. Phase 8 — Improvement Plan
Section titled “146. Phase 8 — Improvement Plan”Assign:
Action
Owner
Budget
Due Date
Metric147. Phase 9 — Implement
Section titled “147. Phase 9 — Implement”Update:
Structures
Processes
Policies
Technology
Metrics148. Phase 10 — Monitor
Section titled “148. Phase 10 — Monitor”Use:
Performance
Risk
Audit
Compliance
Benefitsto drive continuous improvement.
COBIT Governance Assessment Checklist
Section titled “COBIT Governance Assessment Checklist”Governance — EDM
Section titled “Governance — EDM”-
stakeholder needs understood.
-
governance responsibilities assigned.
-
benefits monitored.
-
enterprise technology risk monitored.
-
resources optimized.
-
stakeholder reporting established.
Align, Plan & Organize — APO
Section titled “Align, Plan & Organize — APO”-
IT strategy aligned with business.
-
enterprise architecture maintained.
-
portfolio governance established.
-
budgets governed.
-
skills and capacity managed.
-
vendor management established.
-
risk management established.
-
security governance established.
-
data governance established.
Build, Acquire & Implement — BAI
Section titled “Build, Acquire & Implement — BAI”-
programs governed.
-
projects managed.
-
requirements documented.
-
solution risk assessed.
-
changes controlled.
-
configuration maintained.
-
knowledge documented.
-
benefits tracked.
Deliver, Service & Support — DSS
Section titled “Deliver, Service & Support — DSS”-
operations monitored.
-
service requests managed.
-
incidents managed.
-
root causes managed.
-
continuity maintained.
-
security services operated.
-
operational controls monitored.
Monitor, Evaluate & Assess — MEA
Section titled “Monitor, Evaluate & Assess — MEA”-
performance monitored.
-
internal controls assessed.
-
compliance evaluated.
-
assurance activities established.
-
findings tracked.
-
management actions monitored.
COBIT Deliverables
Section titled “COBIT Deliverables”After completing this lesson, you should be able to create:
01 COBIT Governance Scope
02 Stakeholder Needs Register
03 Enterprise Goals Map
04 Alignment Goals Map
05 COBIT Objective Mapping
06 Design Factor Assessment
07 IT Governance RACI
08 Technology Risk Register
09 Technology Strategy Assessment
10 Enterprise Architecture Governance Model
11 IT Portfolio Register
12 Vendor Governance Register
13 Change Governance Assessment
14 IT Service Governance Assessment
15 IT Control Framework
16 Technology Performance Dashboard
17 COBIT Capability Assessment
18 COBIT Gap Register
19 COBIT Improvement Roadmap
20 Executive I&T Governance DashboardPractical Activity — Build a Goals Cascade
Section titled “Practical Activity — Build a Goals Cascade”Scenario:
Business Goal:Improve CustomerDigital ExperienceIdentify:
Stakeholder Need
Enterprise Goal
Alignment Goal
Relevant COBIT ObjectivesThen explain how technology governance supports the business goal.
Practical Activity — Assess Technology Risk Governance
Section titled “Practical Activity — Assess Technology Risk Governance”Your organization has:
AWS
Azure
Microsoft 365
Customer SaaS
Critical VendorsTechnology risks are currently stored in separate spreadsheets.
Assess:
Current State
Risk
Governance Gap
Target State
Owner
PriorityDesign a centralized technology risk-governance model.
Practical Activity — Assess Change Governance
Section titled “Practical Activity — Assess Change Governance”Current state:
Developers CanDeploy Directlyto ProductionIncidents show:
25% of ProductionOutages Follow ChangesDetermine:
Governance Concern
Relevant Management Objective
Control Improvements
KPI
KRIPractical Activity — Build an Executive Governance Dashboard
Section titled “Practical Activity — Build an Executive Governance Dashboard”Include:
Technology Value
Technology Risk
Service Availability
Project Performance
Control Health
Compliance
Vendor Risk
Audit FindingsThen identify:
What RequiresExecutive Decision?COBIT GRC Mindset
Section titled “COBIT GRC Mindset”When applying COBIT, ask:
What Doesthe BusinessNeed from Technology?
Who Arethe Stakeholders?
What EnterpriseGoals Matter?
How DoesTechnology SupportThose Goals?
Who GovernsTechnology?
Who ManagesTechnology?
Are Governanceand ManagementClearly Separated?
Are TechnologyInvestments DeliveringBusiness Value?
Are TechnologyRisks Within Appetite?
Are ResourcesUsed Effectively?
Is TechnologyStrategy Alignedwith Business Strategy?
Is ArchitectureGoverned?
Are ProgramsDelivering Benefits?
Are ProjectsControlled?
Are ChangesManaged?
Are ServicesReliable?
Are IncidentsHandled?
Are Root CausesAddressed?
Can CriticalServices Recover?
Are SecurityServices Effective?
Are VendorsGoverned?
Are ControlsOperating?
Are ComplianceRequirements Met?
Is AssuranceIndependent?
Are MetricsUseful?
Are We MeasuringActivity?
Or Are WeMeasuring Value?
Are TechnologyDecisions SupportingEnterprise Strategy?
Can LeadershipTrust the Information?
Is GovernanceDriving BetterBusiness Outcomes?That is the mindset of a GRC professional using COBIT 2019.
Key Takeaways
Section titled “Key Takeaways”-
COBIT 2019 is a framework for governance and management of enterprise information and technology.
-
COBIT is broader than cybersecurity and includes strategy, architecture, projects, operations, risk, compliance, service delivery, and assurance.
-
Governance and management are distinct.
-
Governance evaluates stakeholder needs, directs priorities, and monitors outcomes.
-
Management plans, builds, operates, and monitors activities to achieve governance direction.
-
EDM represents governance.
-
APO focuses on alignment, planning, and organization.
-
BAI focuses on building, acquiring, implementing, and managing change.
-
DSS focuses on delivering and supporting technology services.
-
MEA focuses on monitoring, evaluating, compliance, controls, and assurance.
-
COBIT’s Goals Cascade connects stakeholder needs to enterprise goals, alignment goals, and governance or management objectives.
-
Governance should focus on stakeholder value.
-
Technology strategy should align with business strategy.
-
COBIT uses a holistic governance system involving processes, structures, information, people, culture, and technology.
-
Design factors help tailor governance to the organization.
-
Technology governance should reflect enterprise strategy, risk profile, threat landscape, compliance, sourcing, and technology dependence.
-
Capability assessment should support business outcomes rather than become a scoring exercise.
-
Technology risk should be connected to business impact.
-
Risk optimization means managing risk within enterprise appetite, not eliminating all risk.
-
Outsourcing does not remove enterprise accountability.
-
Internal Audit should provide independent assurance rather than own management controls.
-
COBIT can complement NIST CSF, NIST RMF, CIS Controls, ISO 27001, and ITIL.
-
Executive reporting should connect technology value, risk, performance, compliance, and management action.
-
COBIT should be treated as an enterprise governance system rather than an IT checklist.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is COBIT 2019?
-
What is the primary purpose of COBIT?
-
What is the difference between governance and management?
-
What does EDM stand for?
-
What happens in the EDM domain?
-
What does APO stand for?
-
What activities belong to APO?
-
What does BAI stand for?
-
What activities belong to BAI?
-
What does DSS stand for?
-
What activities belong to DSS?
-
What does MEA stand for?
-
What activities belong to MEA?
-
What is the COBIT Goals Cascade?
-
What are stakeholder needs?
-
What are enterprise goals?
-
What are alignment goals?
-
What are governance components?
-
Why is culture important to governance?
-
What are COBIT design factors?
-
Why should governance systems be customized?
-
What is a technology risk profile?
-
How does sourcing affect governance?
-
What is capability assessment?
-
Why should capability scores not become the primary objective?
-
How does COBIT support enterprise risk management?
-
What is risk optimization?
-
How does COBIT support compliance?
-
How can COBIT support Internal Audit?
-
What is the difference between first, second, and third lines?
-
How does COBIT support cybersecurity governance?
-
How can COBIT support cloud governance?
-
How does COBIT support third-party governance?
-
How does COBIT differ from NIST CSF?
-
How does COBIT complement NIST RMF?
-
How can CIS Controls complement COBIT?
-
How can COBIT and ISO 27001 work together?
-
How can COBIT and ITIL complement one another?
-
What should a COBIT executive dashboard contain?
-
What makes a COBIT governance program effective?
What’s Next?
Section titled “What’s Next?”➡️ Next: 05 — ISO 31000 Risk Management
In the next lesson, you will move from governance of enterprise information and technology into a broader enterprise risk-management framework.
You will learn how ISO 31000 structures risk management around:
Leadership & Commitment ↓Integration ↓Design ↓Implementation ↓Evaluation ↓Improvementand how the risk-management process connects:
Scope & Context ↓Risk Identification ↓Risk Analysis ↓Risk Evaluation ↓Risk Treatment ↓Monitoring & Review ↓Communication & ConsultationThe focus will be on understanding how organizations create a consistent enterprise approach for identifying, evaluating, treating, monitoring, and communicating risk across cybersecurity, technology, operational, third-party, privacy, compliance, financial, and strategic domains.
➡️ Next: 05 — ISO 31000 Risk Management