Framework

COBIT 2019

COBIT 2019 Governance & Management Objectives

40 requirements · 30 connected unified controls

Open COBIT 2019 in the map
Version
2019
Published
2018-11
Amendments
none

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

Evaluate, Direct and Monitor

RequirementUnified control and mapping
EDM01Ensured Governance Framework Setting and Maintenance
EDM02Ensured Benefits Delivery
EDM03Ensured Risk Optimization
EDM04Ensured Resource Optimization
UC-GOV-11 — Allocate adequate resources and budget for securityPartial

Remaining requirement: governance of optimization across all enterprise IT resources (people, technology, infrastructure), beyond security-scoped budget and personnel

EDM05Ensured Stakeholder Engagement
UC-GOV-21 — Communicate and report risk and control informationPartial

Remaining requirement: evaluating stakeholder engagement/reporting requirements and monitoring engagement effectiveness at the governance layer, beyond performing communication and reporting

Align, Plan and Organize

RequirementUnified control and mapping
APO01Managed I&T Management Framework
APO02Managed Strategy
APO03Managed Enterprise Architecture
UC-GOV-19 — Maintain enterprise security and privacy architecturePartial

Remaining requirement: EA vision and multi-domain (business/data/application/technology) reference architecture plus enterprise-architecture services, beyond security/privacy architecture

APO04Managed Innovation
UC-GOV-13 — Govern the technology investment portfolio for valuePartial

Remaining requirement: APO04 also requires technology-trend scanning and fostering an innovation-conducive environment

APO05Managed Portfolio
APO06Managed Budget and Costs
UC-GOV-11 — Allocate adequate resources and budget for securityPartial

Remaining requirement: full IT financial management including cost transparency and allocation models

APO07Managed Human Resources
UC-GOV-10 — Attract, develop, and retain competent personnelPartial

Remaining requirement: workforce capacity/utilization planning and contract-staff management, beyond attracting, developing, and retaining competent personnel

APO08Managed Relationships
UC-GOV-21 — Communicate and report risk and control informationPartial

Remaining requirement: active business-IT relationship and demand management beyond communication

APO09Managed Service Agreements
UC-TPRM-01 — Operate a third-party security risk management programPartial

Remaining requirement: service catalog definition and SLA lifecycle management

APO10Managed Vendors
UC-TPRM-01 — Operate a third-party security risk management programPartial

Remaining requirement: day-to-day vendor performance monitoring and contract administration

APO11Managed Quality
UC-GOV-22 — Assess control effectiveness and authorize systemsPartial

Remaining requirement: embedding quality management practices across processes, projects, and deliverables

APO12Managed Risk
UC-GOV-17 — Establish enterprise risk management strategy and appetitePartial

Remaining requirement: operational risk identification, assessment, and response processes

APO13Managed Security
APO14Managed Data
UC-GOV-20 — Govern data as an asset with accountable oversight bodiesPartial

Remaining requirement: operational data management - data-management strategy, business glossary/metadata, data-quality profiling and cleansing, archiving/backup - beyond governance policy and oversight bodies

Build, Acquire and Implement

RequirementUnified control and mapping
BAI01Managed Programs
UC-SDLC-02 — Plan and resource development programs and projectsPartial

Remaining requirement: BAI01 governs the enterprise programme/portfolio management practice; this development-scoped objective covers project-level planning and resourcing, not enterprise portfolio governance

BAI02Managed Requirements Definition
BAI03Managed Solutions Identification and Build
UC-SDLC-04 — Engineer systems with secure architecture and designPartial

Remaining requirement: full solution build, component, and maintenance life cycle satisfied by companion controls

BAI04Managed Availability and Capacity
BAI05Managed Organizational Change
BAI06Managed IT Changes
BAI07Managed IT Change Acceptance and Transitioning
BAI08Managed Knowledge
UC-SDLC-08 — Maintain current system documentation and knowledgePartial

Remaining requirement: enterprise-wide knowledge management extends beyond system documentation

BAI09Managed Assets
BAI10Managed Configuration
BAI11Managed Projects

Deliver, Service and Support

Monitor, Evaluate and Assess