COBIT is an IT governanceframework for businesses wanting to implement, monitor and improveIT management best practices. COBIT is the acronym for Control Objectives for Information and Related Technologies.
The COBIT framework was created byISACA to bridge the crucial gap between technical issues, business risks and control requirements.
COBIT can be implemented in any organization from any industry to ensure quality, control and reliability of information systems.
In the United States, COBIT is the most commonly used framework for achieving compliance with the Sarbanes-Oxley Act (SOX).
ISACA sets and develops guidance and controls for information governance, control, security and audit professionals.
The global organization sponsors and drives the COBIT framework. ISACA originally stood for "Information Systems Audit and Control Association," but the organization now simply goes by ISACA.
The original version of COBIT was published in 1996 for financial auditors to better navigate the growth of IT environments.
ISACA released a more comprehensive version in 1998 that covered areas beyond audit controls. Versions 3 and 4, released in the 2000s, included further management guidelines around cybersecurity.
Released in 2013, COBIT 5 focused on providing tools, best practices and objectives that were universally applicable to all enterprise IT operations.
COBIT 5 expanded on COBIT 4 by integrating related standards from the International Organization for Standardization (ISO), including IT Infrastructure Library (ITIL).
In 2019, ISACA announced the current COBIT version: COBIT 2019. This current version is a more generic, comprehensive and flexible tool that can be used by all enterprises regardless of their size or immediate goals.
It also better addresses rapidly changing technology and is designed to evolve with more frequent updates.
The goal of the COBIT framework is to provide a common language for IT professionals, business executives andcompliance auditors to communicate with each other about IT controls, goals, objectives and outcomes.
Without a common language, an enterprise under audit runs the risk of having to educate individual auditors about when, where, how and why specific IT controls were created.
COBIT incorporates more than just technical standards for IT managers. The framework supports business requirements through the combined application of IT, related sources and processes. Two main parameters provided are:
COBIT is based on five key principles for IT enterprise governance:
The framework also identifies seven aspects of governance that need to align in order to support the five principles above:
COBIT 2019 is not a cheat sheet but a generic tool to support business decisions.
All previous versions of COBIT faced a variety of criticism. They were thought to facilitate limited opportunities -- and sometimes even adverse results.
A major IT firm found that COBIT practices can lead to a "hot potato" situation wherein all stakeholders had passed on the tasks down the line.
Critics maintained that COBIT 5.0 encouraged paperwork and rote rules rather than merely promoting ITgovernance engagements and improving accountability.
Major changes between COBIT 5 and the latest version COBIT 2019 update include the following:
In this section, we'll examine how COBIT compares to other related frameworks.
COBIT and ITIL are both regarded as important analytical tools for governing IT services. The two frameworks, which overlap somewhat, can be used together quite effectively.
While the ITIL framework has a narrow focus on IT service management (ITSM), the COBIT framework has a broader, risk management focus that can be applied to almost any area of the business.
When an enterprise needs to document compliance, ITIL requires the use of third-party tools, such as the Tudor IT Process Assessment (TIPA). In contrast, COBIT audits are always conducted by ISACA Certified Information Systems Auditors (CISAs).
The Open Group Architecture Framework (TOGAF) is another governance, risk and compliance (GRC) framework that complements COBIT. The Open Group, an independent industry association, created and maintains TOGAF.
It builds on an earlier framework known as TAFIM, or Technical Architecture Framework for Information Management, originally devised by the U.S. Defense Department (DOD). In early 2009, The Open Group released TOGAF version 9.
The Open Group and others commonly leadTOGAF certification and educational programs today. Typically, enterprise architects lead the use of TOGAF within organizations.
ISACA offers COBIT certifications for information security, cloud computing and other IT professionals. They include COBIT Foundation, COBIT Design and Implementation and COBIT 5 certificates.
FWA delivers wireless broadband internet to remote regions, temporary setups and other locations not suitable for wired ...
The internet would be different today without DNS anchoring digital communications. Companies can take some basic steps to ensure...
Cisco's entrée into 102.4 Tbps silicon boasts in-place programmability and new AgenticOps features as enterprise AI ...
The current AI hype era resembles the dot-com bubble era in some ways, but there are significant differences as well.
Rimini Street's CIO explains how he deployed agentic AI for research and service -- and how an AI steering committee governs ...
Agentic AI is forcing CIOs to rethink IT strategy. Success depends on identifying key use cases, assessing data readiness, ...
With Windows 10 end of support now past, enterprises must evaluate whether to upgrade to Windows 11 based on hardware readiness, ...
Risk is no longer centered only in core systems. Identity, hiring, endpoints and partner platforms are where exposure ...
The Windows 10 end-of-support deadline forces IT teams to choose between Windows 11 migration, ESU enrollment and broader desktop...
Q4 cloud infrastructure service revenues reach $119.1 billion, bringing the 2025 total to $419 billion. See how much market share...
Will $5 trillion in AI infrastructure investment be enough? Cloud providers facing that question must also yield a return, ...
As IT leaders aggressively re-allocate capital to fund new AI initiatives, repatriation offers both savings and greater control, ...
Spain-based global telco reveals progress made in Autonomous Network Journey programme, closing last year with 12 Level 4 use ...
With AI agents increasingly acting as digital concierges for shoppers, verifying bot identities, securing the APIs they rely on ...
The UK Information Commissioner’s Office has won an important appeal relating to data protection obligations arising from a 2017-...



