COBIT

Also known as: Control Objectives for Information and Related Technologies

framework · governance and compliance · regulatory-standard

ISACA framework for governance and management of enterprise IT.

COBIT is ISACA's framework for the governance and management of enterprise information and technology, distinguishing governance objectives (the responsibility of the board, evaluating, directing, and monitoring) from management objectives (the responsibility of executive management, planning, building, running, and monitoring). First published in 1996 as a control-objective audit framework, it expanded substantially through versions 4.1 (2007), 5 (2012), and the current COBIT 2019, which articulates 40 governance and management objectives organized across five domains, design factors for tailoring the framework to enterprise context, and a process capability scheme aligned with CMMI. COBIT is widely used as the umbrella governance reference at organizations that implement ITIL, ISO/IEC 27001, NIST CSF, or other operational frameworks beneath it.

Originators

ISACA (Information Systems Audit and Control Association, now ISACA) high

Year / Decade

1996 (v1); 2019 (current) high

Primary sources

ISACA (2019). COBIT 2019 Framework: Introduction and Methodology, ISACA (2019). COBIT 2019 Framework: Governance and Management Objectives high

Core components

Primary use case

Enterprise IT governance reference; audit and assurance framework; umbrella structure integrating operational frameworks like ITIL, ISO/IEC 27001, and NIST CSF.

Common criticisms

Lineage

Siblings
ITIL, TOGAF, CMMI, ISO/IEC 27001, NIST Cybersecurity Framework