COBIT (Control Objectives for Information and Related Technologies)

Industry StandardGeneral Cybersecurity2019
ByDecipherU Editorial

COBIT is ISACA's IT governance and management framework that includes cybersecurity governance objectives. COBIT 2019 provides a governance system for enterprise IT, with 40 governance and management objectives across five domains. It helps organizations bridge the gap between business requirements, cybersecurity controls, and IT operations through a structured governance approach.

Quick Reference

EnactedCOBIT 1: 1996; COBIT 2019: November 2018
Enforcement BodyISACA (standard setting); voluntary adoption; referenced in regulatory guidance
PenaltiesNo direct penalties (voluntary framework); referenced by auditors and regulators
Applicable ToAny organization seeking structured IT governance; commonly used in financial services, healthcare, and government

Key Requirements

APO13 (Managed Security)

Define, operate, and monitor an information security management system that maintains the security of information and IT infrastructure

APO12 (Managed Risk)

Continually identify, assess, and reduce IT-related risk within risk tolerance levels set by enterprise management

DSS05 (Managed Security Services)

Protect enterprise information to maintain the level of information security risk acceptable to the enterprise in accordance with the security policy

EDM03 (Ensured Risk Optimization)

Ensure that IT-related enterprise risk does not exceed risk appetite and tolerance, the impact of IT risk to enterprise value is identified and managed

How Does COBIT Affect Cybersecurity Careers?

ISACA's CISA and CISM certifications align closely with COBIT. IT auditors at financial institutions frequently audit against COBIT governance objectives. GRC analysts use COBIT to establish cybersecurity governance structures that connect to business objectives. CISOs use COBIT alongside NIST CSF to demonstrate governance maturity to boards.

How Does COBIT Affect Cybersecurity Sales?

GRC platforms that support COBIT governance objectives and maturity assessments sell well to organizations in regulated industries. IT governance and board reporting tools align with COBIT's governance focus. Sales teams should understand that COBIT buyers are typically IT audit and governance professionals (the ISACA community).

Cybersecurity Roles That Work With COBIT

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of COBIT at the official source: https://www.isaca.org/resources/cobit

Frequently Asked Questions

COBIT is ISACA's IT governance and management framework that includes cybersecurity governance objectives. COBIT 2019 provides a governance system for enterprise IT, with 40 governance and management objectives across five domains. It helps organizations bridge the gap between business requirements, cybersecurity controls, and IT operations through a structured governance approach.

ISACA's CISA and CISM certifications align closely with COBIT. IT auditors at financial institutions frequently audit against COBIT governance objectives. GRC analysts use COBIT to establish cybersecurity governance structures that connect to business objectives. CISOs use COBIT alongside NIST CSF to demonstrate governance maturity to boards.

No direct penalties (voluntary framework); referenced by auditors and regulators

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?