COBIT
Also known as: Control Objectives for Information and Related Technologies
ISACA framework for governance and management of enterprise IT.
COBIT is ISACA's framework for the governance and management of enterprise information and technology, distinguishing governance objectives (the responsibility of the board, evaluating, directing, and monitoring) from management objectives (the responsibility of executive management, planning, building, running, and monitoring). First published in 1996 as a control-objective audit framework, it expanded substantially through versions 4.1 (2007), 5 (2012), and the current COBIT 2019, which articulates 40 governance and management objectives organized across five domains, design factors for tailoring the framework to enterprise context, and a process capability scheme aligned with CMMI. COBIT is widely used as the umbrella governance reference at organizations that implement ITIL, ISO/IEC 27001, NIST CSF, or other operational frameworks beneath it.
Core components
- Governance and management objectives (40 in COBIT 2019)
- Five domains: Evaluate, Direct, Monitor (governance)
- Align, Plan, Organize
- Build, Acquire, Implement
- Deliver, Service, Support
- Monitor, Evaluate, Assess (management)
- Components (processes, structures, information flows, culture, skills, services, principles)
- Design factors for tailoring
- Process capability levels (0-5)
Primary use case
Enterprise IT governance reference; audit and assurance framework; umbrella structure integrating operational frameworks like ITIL, ISO/IEC 27001, and NIST CSF.
Common criticisms
- Volume of guidance creates implementation complexity
- substantial overlap with ITIL leads to dual-mapping work
- certification ecosystem incentivizes credentialing
- principles can become consultant-driven implementation
- full adoption rare in practice — most organizations use COBIT selectively as a mapping reference.
Lineage
- Siblings
- ITIL, TOGAF, CMMI, ISO/IEC 27001, NIST Cybersecurity Framework