Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: GRC Governance Frameworks

COBIT 2019

Also known as: COBIT, COBIT Framework, COBIT 2019 Framework
Simply put

COBIT 2019 is a framework created by ISACA for managing and governing an organization's information technology. It helps organizations align their IT activities with business goals, and is designed to work alongside other industry standards, guidelines, and regulations. In many organizations it is used as a reference model for structuring IT governance and management responsibilities.

Formal definition

COBIT 2019 is ISACA's framework for the governance and management of enterprise IT. According to the evidence, it is business-focused and is structured around a set of principles, enablers, and governance and management objectives (the evidence describes six principles, seven enablers, and 40 governance and management objectives organized across five domains). It is intended to be integrated with other standards, guidelines, and regulations rather than to replace them. As a voluntary framework, its adoption and scope of application vary by organization; specific structural details and edition-specific terminology should be verified against ISACA's primary publications.

Why it matters

As enterprises grow more dependent on information technology, the boundary between IT decisions and business outcomes has effectively disappeared. COBIT 2019 matters because it gives organizations a structured, business-focused reference model for who holds decision rights over IT, how IT objectives connect to enterprise objectives, and how governance responsibilities are separated from day-to-day management activities. For governance professionals, this distinction is central: COBIT positions the governance of enterprise IT as a board- and executive-level accountability, not merely an operational IT concern.

A further reason COBIT 2019 is significant is its explicit design to work alongside, rather than replace, other standards, guidelines, and regulations. Many organizations operate under overlapping obligations and frameworks, and a common reference model that can be integrated with existing requirements helps reduce fragmentation and duplicated effort across IT governance, risk, and compliance activities. This integrative intent is one of the characteristics ISACA emphasizes for the 2019 edition.

Because COBIT is a voluntary framework rather than a binding legal requirement, its value depends on how deliberately an organization tailors and adopts it. It does not, on its own, guarantee compliance with any regulation or eliminate IT-related risk; rather, it offers a way to organize governance and management objectives so that IT activities can be directed, monitored, and held accountable in a consistent manner. Organizations should confirm structural details and terminology against ISACA's primary publications before relying on them.

Who it's relevant to

Boards and executive leadership
COBIT 2019 frames the governance of enterprise IT as an accountability that sits with governing bodies and executives, distinct from operational management. It offers directors and senior leaders a structure for exercising oversight over IT-related decisions and for confirming that IT activities support enterprise objectives.
IT governance and management professionals
For those responsible for structuring IT governance and management, COBIT 2019 provides a reference model of governance and management objectives that can be used to assign responsibilities, clarify decision rights, and align IT activities with business goals. Its intended interoperability with other standards makes it useful where multiple frameworks coexist.
Risk and compliance functions
Risk managers and compliance officers may use COBIT 2019 as a common reference point when coordinating IT-related governance activities with existing regulatory obligations and internal policies. Because it is designed to integrate with, rather than replace, other standards and regulations, it can help reduce duplication; however, it does not by itself satisfy any specific legal requirement, and applicability should be assessed against jurisdiction- and sector-specific obligations.
Internal auditors and assurance providers
Internal auditors can reference COBIT 2019's governance and management objectives when evaluating whether IT governance and management responsibilities are defined and operating as intended. As with any voluntary framework, audit conclusions should be based on the organization's actual adopted scope and tailoring rather than on the framework in the abstract.

Inside COBIT

Governance and Management Objectives
COBIT 2019 organizes its content around a set of objectives grouped into governance objectives and management objectives. Governance objectives are typically associated with evaluating, directing, and monitoring, while management objectives are associated with planning, building, running, and monitoring activities. The framework distinguishes governance (setting direction and oversight) from management (executing activities within that direction).
Governance System Principles
COBIT 2019 articulates a set of principles for a governance system, including concepts such as providing stakeholder value, taking a holistic approach, being tailored to enterprise needs, distinguishing governance from management, and being dynamic. Practitioners should verify the exact principle wording against the primary COBIT 2019 publications, as summary phrasing varies.
Governance Framework Principles
In addition to principles for the governance system, COBIT 2019 describes principles for a governance framework itself, such as being based on a conceptual model, being open and flexible, and aligning with major related standards and frameworks. These describe the qualities of the framework rather than the governance system an enterprise implements.
Governance System Components (formerly enablers)
COBIT 2019 uses the concept of components that work together to build a governance system. These typically include processes; organizational structures; policies and procedures; information flows; culture, ethics and behavior; people, skills and competencies; and services, infrastructure and applications. The precise component set should be confirmed against the source, as terminology evolved from earlier editions.
Design Factors
COBIT 2019 introduces design factors, contextual elements such as enterprise strategy, goals, risk profile, IT-related issues, threat landscape, compliance requirements, role of IT, sourcing model, and enterprise size, that influence how an enterprise tailors its governance system. This tailoring emphasis is a distinguishing feature relative to some earlier editions.
Focus Areas
COBIT 2019 recognizes focus areas that address specific governance topics or contexts (for example, particular domains of interest), allowing the core guidance to be supplemented for specialized needs. The specific list of focus areas may expand over time, so it should be verified against current ISACA materials.
Goals Cascade
COBIT includes a goals cascade concept intended to translate stakeholder needs into enterprise goals, then into alignment goals (relating to information and technology), and into governance and management objectives. This is a mechanism for connecting stakeholder value to specific governance activities.
Capability and Maturity Concepts
COBIT 2019 provides a way to assess the capability of processes and to consider maturity at a focus-area level, supporting performance measurement and improvement. The exact scoring conventions should be confirmed against the primary publications rather than assumed.

Common questions

Answers to the questions practitioners most commonly ask about COBIT.

Is COBIT 2019 an IT security or cybersecurity framework?
Not primarily. COBIT 2019 is a governance and management framework for enterprise information and technology (I&T), addressing how I&T is directed and controlled to support enterprise objectives. It spans governance structures, processes, and management practices rather than serving as a dedicated security or cybersecurity control catalog. Organizations often align it with security-specific frameworks (for example, NIST or ISO/IEC 27000-series standards) to address technical security controls, but those are separate in scope. Applicability and integration approaches vary by organization; verify specifics against the primary COBIT materials.
Does COBIT 2019 make the earlier concept of governance versus management interchangeable, so the terms can be used loosely?
No. COBIT distinguishes governance from management as separate concerns. In COBIT's model, governance typically concerns evaluating stakeholder needs and setting direction, decision rights, and oversight, while management concerns planning, building, running, and monitoring activities in alignment with that direction. Treating the two as synonymous conflates the structures that direct and control an enterprise with the activities that execute against that direction. The precise terminology and component structure should be confirmed against current COBIT publications, as framework language evolves across editions.
How should an organization begin scoping a COBIT 2019 implementation?
Scoping typically starts by clarifying the enterprise goals and stakeholder needs that the I&T governance system is meant to support, then narrowing to the areas most relevant to those objectives rather than attempting to adopt the entire framework at once. COBIT provides the notion of design factors intended to help tailor a governance system to an enterprise's context. The specific design-factor set, tailoring steps, and terminology should be verified against the primary COBIT 2019 design guidance, and scope will vary by sector, size, and jurisdiction.
How does COBIT 2019 relate to other frameworks and standards already in use?
COBIT is often positioned as an overarching governance framework that can be mapped to, and used alongside, more specialized standards and frameworks, for example, IT service management, project management, information security, and risk management standards. Rather than replacing these, it is commonly used to provide a governance and management overlay that references them. The exact mappings and any alignment claims should be confirmed against current COBIT and the respective source publications, since such mappings change across editions.
Who typically owns or sponsors a COBIT 2019 implementation within an organization?
Because COBIT addresses both governance and management, sponsorship commonly involves governing bodies (such as a board or its committees) for the governance dimension and executive and IT leadership for the management dimension, with input from risk, compliance, and internal audit functions. Precise role definitions and responsibility assignments are context-dependent and should be tailored to the organization's structure; COBIT provides guidance on roles and responsibilities that should be verified against its primary materials.
How can an organization measure progress or performance under COBIT 2019?
COBIT 2019 includes a capability and performance management approach intended to assess how well governance and management objectives are being achieved and to support improvement over time. Organizations typically define target performance levels appropriate to their risk appetite and objectives, then assess current state against them. The specific rating scales, capability-level definitions, and assessment methods should be confirmed against the current COBIT performance management guidance, as these details differ across editions and are not universally binding requirements.

Common misconceptions

COBIT is an IT security or cybersecurity standard.
COBIT 2019 is a framework for the governance and management of enterprise information and technology as a whole. Security and cybersecurity are relevant topics that can be addressed through its objectives and focus areas, but the framework's scope is broader than security. Frameworks such as certain NIST or ISO/IEC standards address security more directly; COBIT is often used alongside them rather than as a substitute.
COBIT does not distinguish between governance and management.
A core premise of COBIT 2019 is that governance and management are distinct disciplines. Governance concerns evaluating stakeholder needs, setting direction, and monitoring, typically at the board or oversight level, while management concerns planning, building, running, and monitoring activities in line with the direction set by governance. Conflating the two runs counter to how the framework is structured.
Adopting COBIT guarantees regulatory compliance or eliminates IT-related risk.
COBIT is a voluntary framework and leading-practice reference, not a binding legal requirement in itself. Using it can support compliance and risk management efforts, but it does not by itself ensure adherence to any specific law or regulation, nor does any framework eliminate risk. Compliance obligations vary by jurisdiction and sector and require independent verification.

Best practices

Use COBIT 2019's design factors to tailor the governance system to your enterprise's strategy, risk profile, size, and regulatory context rather than adopting the full set of objectives uniformly.
Maintain a clear separation between governance activities (evaluate, direct, monitor) and management activities when assigning roles and decision rights, consistent with the framework's core distinction.
Apply the goals cascade to trace stakeholder needs through enterprise and alignment goals to specific governance and management objectives, so investments and controls remain connected to value.
Map COBIT objectives and components to related standards and frameworks already in use, such as relevant ISO or NIST references, to avoid duplication and to position COBIT as an integrating layer.
Assess process capability and focus-area maturity to establish a baseline and prioritize improvements, confirming scoring conventions against the current ISACA publications.
Verify specific requirements, terminology, and any compliance-relevant claims against the primary COBIT 2019 source documents and applicable regulations, seeking professional advice where legal interpretation is involved.
Application Security Isn’t Optional Anymore.