COBIT Framework Implementation
COBIT is ISACA’s framework for the governance and management of enterprise information and technology. There is no organisational COBIT certificate. ISACA certifies individuals, and the value to an enterprise comes from implementation, not from a certificate on the wall.
What COBIT Is and Who Publishes It
COBIT is published by ISACA, the professional association that also owns the CISA, CISM and CMMI programmes. It is a framework for the governance and management of enterprise information and technology, and it deliberately separates the two. Governance is the board level activity of evaluating stakeholder needs, setting direction and monitoring performance. Management is the executive activity of planning, building, running and monitoring in line with that direction.
The current version is COBIT 2019, published by ISACA in 2018. It replaced the enabler based structure of COBIT 5 with a governance system built from components and tailored using design factors.
The Five Domains and Forty Objectives
COBIT 2019 organises 40 governance and management objectives into five domains. The domain names are ISACA’s own and are given here as published:
- Evaluate, Direct and Monitor (EDM), the governance domain, covering the board level activities of setting and monitoring the governance framework, benefits delivery, risk, resource optimisation and stakeholder engagement.
- Align, Plan and Organize (APO), covering strategy, enterprise architecture, innovation, portfolio, budget, human resources, relationships, service agreements, suppliers, quality, risk, security and data.
- Build, Acquire and Implement (BAI), covering programmes, requirements definition, solution identification, availability and capacity, organisational change, changes, assets, configuration and projects.
- Deliver, Service and Support (DSS), covering operations, service requests and incidents, problems, continuity, security services and business process controls.
- Monitor, Evaluate and Assess (MEA), covering performance and conformance monitoring, the system of internal control, compliance with external requirements and assurance.
Each objective is supported by components: processes, organisational structures, information flows, people and skills, policies and procedures, culture and behaviour, and services and infrastructure. Design factors such as enterprise strategy, risk profile, threat landscape, compliance requirements, sourcing model and technology adoption strategy are used to decide which objectives matter most in a given enterprise.
Certification: Individuals Yes, Organisations No
This is where COBIT is most often misrepresented. ISACA certifies people. It does not run an organisational certification scheme for COBIT.
- There is no accredited certification body scheme for COBIT, no two stage audit and no surveillance cycle. Those belong to ISO management system standards.
- ISACA offers individual credentials, including the COBIT Foundation Certificate, which tests understanding of the framework, and the COBIT Design and Implementation Certificate, which addresses designing and implementing a tailored governance system.
- What an enterprise can obtain is an assessment of its governance and management objectives against COBIT capability levels, producing a rated baseline and an improvement roadmap. That is an assessment report, not a certificate.
Where a board wants an externally certified management system alongside COBIT, the usual companions are ISO/IEC 27001 for information security and ISO/IEC 20000-1 for service management. ISO/IEC 38500 provides principles for the governance of information technology for the organisation, but it is a guidance standard and is not certifiable either.
How Univate Implements COBIT
- Establish the drivers. Board expectations, regulatory obligations, audit findings and business strategy determine which objectives are in scope. Implementing all forty is almost never the right answer.
- Apply the design factors. Enterprise strategy, goals, risk profile, threat landscape, compliance requirements, role of IT, sourcing model, methods and technology adoption are used to produce a tailored governance system design.
- Baseline current capability. Selected objectives are assessed against the capability levels so that improvement targets are grounded in evidence.
- Build the components. Decision rights, committee structures, policies, process definitions, information flows, metrics and role descriptions, implemented in the operating model rather than written and shelved.
- Monitor and improve. Performance reporting to the board, periodic reassessment and integration with internal audit so that governance stays live.
Points Worth Being Careful About
- Treat COBIT as a framework to tailor, not a checklist to adopt. The design factors exist precisely so that scope reflects the enterprise.
- Capability levels describe process capability. They are not a maturity badge and should not be reported to a board as if they were an external rating.
- COBIT does not replace ITIL, ISO/IEC 20000-1 or ISO/IEC 27001. It sits above them and tells you which outcomes matter and who is accountable.
- Governance work fails when decision rights are not changed. If the same people make the same decisions the same way afterwards, no framework has been implemented.
- Be wary of any provider offering COBIT certification for your organisation. ISACA certifies individuals, and an organisational COBIT certificate is not a thing that exists.
COBIT Questions We Are Asked Most Often
Can a company be COBIT certified?
No. ISACA does not operate an organisational certification scheme for COBIT and no accreditation body oversees one. ISACA certifies individuals through credentials such as the COBIT Foundation Certificate and the COBIT Design and Implementation Certificate. An enterprise can be assessed against COBIT capability levels, which produces an assessment report rather than a certificate.
What is the current version of COBIT?
COBIT 2019, published by ISACA in 2018. It contains 40 governance and management objectives grouped into five domains and introduced design factors for tailoring the governance system.
What are the five COBIT 2019 domains?
Evaluate, Direct and Monitor, which is the governance domain, then the four management domains: Align, Plan and Organize, Build, Acquire and Implement, Deliver, Service and Support, and Monitor, Evaluate and Assess.
How does COBIT relate to ISO/IEC 27001?
COBIT covers the governance and management of enterprise information and technology as a whole, including but not limited to security. ISO/IEC 27001 specifies requirements for an information security management system and is certifiable. Many enterprises use COBIT to set direction and accountability, and ISO/IEC 27001 to obtain a certificate for the security management system.
Does COBIT replace CMMI?
No. CMMI is a capability improvement model appraised by ISACA certified Lead Appraisers, with benchmark appraisal results published in ISACA’s Performance Appraisal Resource System. COBIT is a governance framework. They are complementary and both are owned by ISACA.
Tell us what is driving the governance requirement, whether that is a board mandate, a regulator, an audit finding or a merger. We will design a COBIT based governance system scoped to those drivers rather than to the whole framework.
Related Services & Resources
Univate supports certification, assessment and compliance programmes for organisations operating across international markets. Talk to our team about scope, effort and the route that genuinely applies to your organisation.








