COBIT Governance and Management Objectives

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Governance domain โ€” EDM (5 objectives)

Board-level. Evaluate stakeholder needs / conditions / options, Direct via policies, Monitor performance.

  • EDM01 Ensured Governance Framework Setting and Maintenance
  • EDM02 Ensured Benefits Delivery
  • EDM03 Ensured Risk Optimisation
  • EDM04 Ensured Resource Optimisation
  • EDM05 Ensured Stakeholder Engagement

Management domain โ€” APO (14 objectives)

Plan, organize:

  • APO01 Managed I&T Management Framework
  • APO02 Managed Strategy
  • APO03 Managed Enterprise Architecture
  • APO04 Managed Innovation
  • APO05 Managed Portfolio
  • APO06 Managed Budget and Costs
  • APO07 Managed Human Resources
  • APO08 Managed Relationships
  • APO09 Managed Service Agreements
  • APO10 Managed Vendors
  • APO11 Managed Quality
  • APO12 Managed Risk
  • APO13 Managed Security
  • APO14 Managed Data

Management domain โ€” BAI (11 objectives)

Build, acquire, implement:

  • BAI01 Managed Programs
  • BAI02 Managed Requirements Definition
  • BAI03 Managed Solutions Identification and Build
  • BAI04 Managed Availability and Capacity
  • BAI05 Managed Organisational Change
  • BAI06 Managed IT Changes
  • BAI07 Managed IT Change Acceptance and Transitioning
  • BAI08 Managed Knowledge
  • BAI09 Managed Assets
  • BAI10 Managed Configuration
  • BAI11 Managed Projects

Management domain โ€” DSS (6 objectives)

Deliver, service, support:

  • DSS01 Managed Operations
  • DSS02 Managed Service Requests and Incidents
  • DSS03 Managed Problems
  • DSS04 Managed Continuity
  • DSS05 Managed Security Services
  • DSS06 Managed Business Process Controls

Management domain โ€” MEA (4 objectives)

Monitor, evaluate, assess:

  • MEA01 Managed Performance and Conformance Monitoring
  • MEA02 Managed System of Internal Control
  • MEA03 Managed Compliance with External Requirements
  • MEA04 Managed Assurance

Per objective

Each of the 40 has:

  • Purpose statement
  • Description
  • Mapping to enterprise goals
  • Mapping to alignment goals
  • Governance/management practices โ€” typically 4-7 per objective
  • Activities per practice
  • Inputs and outputs (work products)
  • Capability levels 0-5

Capability levels

Per objective:

  • 0 Incomplete โ€” practice not implemented.
  • 1 Initial โ€” basic implementation.
  • 2 Managed โ€” performance managed.
  • 3 Defined โ€” standardized process.
  • 4 Quantitatively Managed โ€” metrics-driven.
  • 5 Optimising โ€” continuous improvement.

Similar to SPICE / CMMI scales.

Design factors application

Eleven design factors tailor governance system:

  • Risk profile โ†’ emphasis on EDM03, APO12.
  • I&T-related issues โ†’ specific BAI / DSS focus.
  • Compliance requirements โ†’ MEA03 emphasis.
  • Etc.

Tailoring produces priority order across the 40 objectives.

Focus areas

ISACA publishes focus-area guides extending COBIT for specific contexts:

  • Information Security โ€” emphasizes APO13, DSS05.
  • DevOps โ€” emphasizes BAI06, BAI07, DSS02.
  • SMB โ€” proportional tailoring.
  • Risk โ€” emphasizes EDM03, APO12.
  • Digital Transformation.

Cross-framework mapping

COBIT 2019 maps practices to:

  • ISO 27001 controls.
  • NIST CSF subcategories.
  • ITIL practices.
  • Other frameworks.

Cross-references support multi-framework implementations.

Bridge to ITIL

  • COBIT BAI04 โ†” ITIL Availability + Capacity Management.
  • COBIT BAI06 โ†” ITIL Change Enablement.
  • COBIT BAI09-10 โ†” ITIL IT Asset Management + Service Configuration Management.
  • COBIT DSS02 โ†” ITIL Incident + Service Request Management.
  • COBIT DSS03 โ†” ITIL Problem Management.
  • COBIT DSS04 โ†” ITIL Service Continuity Management.
  • COBIT DSS05 โ†” ITIL Information Security Management.

ITIL implements operationally; COBIT governs.

Bridge to ISO 27001

  • COBIT APO13 + DSS05 align with ISO 27001 ISMS substantively.
  • COBIT MEA03 supports ISO 27001 Cl 9.1 + A.5.31.
  • COBIT EDM emphasizes board-level oversight; ISO 27001 Cl 5.

SRE and AI-agent fit notes

For governance-strategy work:

  • COBIT vocabulary aligns with board-level conversations.
  • APO12 (Managed Risk) + APO13 (Managed Security) for cybersecurity governance.
  • APO04 (Managed Innovation) for AI-adoption governance.
  • BAI03 (Managed Solutions Identification and Build) for AI feature development.

Stefan-context implementation sketch

  • For governance-tier client work: COBIT vocabulary useful.
  • For implementation-tier: ITIL primary, COBIT-aware.

See also