Framework
COBIT 2019
COBIT 2019 Governance & Management Objectives
40 requirements · 30 connected unified controls
Open COBIT 2019 in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
Evaluate, Direct and Monitor
| Requirement | Unified control and mapping |
|---|---|
| EDM01Ensured Governance Framework Setting and Maintenance | |
| EDM02Ensured Benefits Delivery | |
| EDM03Ensured Risk Optimization | |
| EDM04Ensured Resource Optimization | UC-GOV-11 — Allocate adequate resources and budget for securityPartial Remaining requirement: governance of optimization across all enterprise IT resources (people, technology, infrastructure), beyond security-scoped budget and personnel |
| EDM05Ensured Stakeholder Engagement | UC-GOV-21 — Communicate and report risk and control informationPartial Remaining requirement: evaluating stakeholder engagement/reporting requirements and monitoring engagement effectiveness at the governance layer, beyond performing communication and reporting |
Align, Plan and Organize
| Requirement | Unified control and mapping |
|---|---|
| APO01Managed I&T Management Framework | |
| APO02Managed Strategy | |
| APO03Managed Enterprise Architecture | UC-GOV-19 — Maintain enterprise security and privacy architecturePartial Remaining requirement: EA vision and multi-domain (business/data/application/technology) reference architecture plus enterprise-architecture services, beyond security/privacy architecture |
| APO04Managed Innovation | UC-GOV-13 — Govern the technology investment portfolio for valuePartial Remaining requirement: APO04 also requires technology-trend scanning and fostering an innovation-conducive environment |
| APO05Managed Portfolio | |
| APO06Managed Budget and Costs | UC-GOV-11 — Allocate adequate resources and budget for securityPartial Remaining requirement: full IT financial management including cost transparency and allocation models |
| APO07Managed Human Resources | UC-GOV-10 — Attract, develop, and retain competent personnelPartial Remaining requirement: workforce capacity/utilization planning and contract-staff management, beyond attracting, developing, and retaining competent personnel |
| APO08Managed Relationships | UC-GOV-21 — Communicate and report risk and control informationPartial Remaining requirement: active business-IT relationship and demand management beyond communication |
| APO09Managed Service Agreements | UC-TPRM-01 — Operate a third-party security risk management programPartial Remaining requirement: service catalog definition and SLA lifecycle management |
| APO10Managed Vendors | UC-TPRM-01 — Operate a third-party security risk management programPartial Remaining requirement: day-to-day vendor performance monitoring and contract administration |
| APO11Managed Quality | UC-GOV-22 — Assess control effectiveness and authorize systemsPartial Remaining requirement: embedding quality management practices across processes, projects, and deliverables |
| APO12Managed Risk | UC-GOV-17 — Establish enterprise risk management strategy and appetitePartial Remaining requirement: operational risk identification, assessment, and response processes |
| APO13Managed Security | |
| APO14Managed Data | UC-GOV-20 — Govern data as an asset with accountable oversight bodiesPartial Remaining requirement: operational data management - data-management strategy, business glossary/metadata, data-quality profiling and cleansing, archiving/backup - beyond governance policy and oversight bodies |
Build, Acquire and Implement
| Requirement | Unified control and mapping |
|---|---|
| BAI01Managed Programs | UC-SDLC-02 — Plan and resource development programs and projectsPartial Remaining requirement: BAI01 governs the enterprise programme/portfolio management practice; this development-scoped objective covers project-level planning and resourcing, not enterprise portfolio governance |
| BAI02Managed Requirements Definition | |
| BAI03Managed Solutions Identification and Build | UC-SDLC-04 — Engineer systems with secure architecture and designPartial Remaining requirement: full solution build, component, and maintenance life cycle satisfied by companion controls |
| BAI04Managed Availability and Capacity | |
| BAI05Managed Organizational Change | |
| BAI06Managed IT Changes | |
| BAI07Managed IT Change Acceptance and Transitioning | |
| BAI08Managed Knowledge | UC-SDLC-08 — Maintain current system documentation and knowledgePartial Remaining requirement: enterprise-wide knowledge management extends beyond system documentation |
| BAI09Managed Assets | |
| BAI10Managed Configuration | |
| BAI11Managed Projects |
Deliver, Service and Support
| Requirement | Unified control and mapping |
|---|---|
| DSS01Managed Operations | |
| DSS02Managed Service Requests and Incidents | |
| DSS03Managed Problems | |
| DSS04Managed Continuity | UC-BCDR-01 — Maintain business continuity and disaster recovery plansPartial Remaining requirement: continuity testing, training, and post-incident review satisfied by companion controls |
| DSS05Managed Security Services | UC-BCDR-13 — Operate continuous security protection servicesPartial Remaining requirement: also identity/logical access, physical access, and sensitive-document/output-device controls |
| DSS06Managed Business Process Controls |
Monitor, Evaluate and Assess
| Requirement | Unified control and mapping |
|---|---|
| MEA01Managed Performance and Conformance Monitoring | |
| MEA02Managed System of Internal Control | |
| MEA03Managed Compliance With External Requirements | |
| MEA04Managed Assurance |