Governance domain โ EDM (5 objectives)
Board-level. Evaluate stakeholder needs / conditions / options, Direct via policies, Monitor performance.
- EDM01 Ensured Governance Framework Setting and Maintenance
- EDM02 Ensured Benefits Delivery
- EDM03 Ensured Risk Optimisation
- EDM04 Ensured Resource Optimisation
- EDM05 Ensured Stakeholder Engagement
Management domain โ APO (14 objectives)
Plan, organize:
- APO01 Managed I&T Management Framework
- APO02 Managed Strategy
- APO03 Managed Enterprise Architecture
- APO04 Managed Innovation
- APO05 Managed Portfolio
- APO06 Managed Budget and Costs
- APO07 Managed Human Resources
- APO08 Managed Relationships
- APO09 Managed Service Agreements
- APO10 Managed Vendors
- APO11 Managed Quality
- APO12 Managed Risk
- APO13 Managed Security
- APO14 Managed Data
Management domain โ BAI (11 objectives)
Build, acquire, implement:
- BAI01 Managed Programs
- BAI02 Managed Requirements Definition
- BAI03 Managed Solutions Identification and Build
- BAI04 Managed Availability and Capacity
- BAI05 Managed Organisational Change
- BAI06 Managed IT Changes
- BAI07 Managed IT Change Acceptance and Transitioning
- BAI08 Managed Knowledge
- BAI09 Managed Assets
- BAI10 Managed Configuration
- BAI11 Managed Projects
Management domain โ DSS (6 objectives)
Deliver, service, support:
- DSS01 Managed Operations
- DSS02 Managed Service Requests and Incidents
- DSS03 Managed Problems
- DSS04 Managed Continuity
- DSS05 Managed Security Services
- DSS06 Managed Business Process Controls
Management domain โ MEA (4 objectives)
Monitor, evaluate, assess:
- MEA01 Managed Performance and Conformance Monitoring
- MEA02 Managed System of Internal Control
- MEA03 Managed Compliance with External Requirements
- MEA04 Managed Assurance
Per objective
Each of the 40 has:
- Purpose statement
- Description
- Mapping to enterprise goals
- Mapping to alignment goals
- Governance/management practices โ typically 4-7 per objective
- Activities per practice
- Inputs and outputs (work products)
- Capability levels 0-5
Capability levels
Per objective:
- 0 Incomplete โ practice not implemented.
- 1 Initial โ basic implementation.
- 2 Managed โ performance managed.
- 3 Defined โ standardized process.
- 4 Quantitatively Managed โ metrics-driven.
- 5 Optimising โ continuous improvement.
Similar to SPICE / CMMI scales.
Design factors application
Eleven design factors tailor governance system:
- Risk profile โ emphasis on EDM03, APO12.
- I&T-related issues โ specific BAI / DSS focus.
- Compliance requirements โ MEA03 emphasis.
- Etc.
Tailoring produces priority order across the 40 objectives.
Focus areas
ISACA publishes focus-area guides extending COBIT for specific contexts:
- Information Security โ emphasizes APO13, DSS05.
- DevOps โ emphasizes BAI06, BAI07, DSS02.
- SMB โ proportional tailoring.
- Risk โ emphasizes EDM03, APO12.
- Digital Transformation.
Cross-framework mapping
COBIT 2019 maps practices to:
- ISO 27001 controls.
- NIST CSF subcategories.
- ITIL practices.
- Other frameworks.
Cross-references support multi-framework implementations.
Bridge to ITIL
- COBIT BAI04 โ ITIL Availability + Capacity Management.
- COBIT BAI06 โ ITIL Change Enablement.
- COBIT BAI09-10 โ ITIL IT Asset Management + Service Configuration Management.
- COBIT DSS02 โ ITIL Incident + Service Request Management.
- COBIT DSS03 โ ITIL Problem Management.
- COBIT DSS04 โ ITIL Service Continuity Management.
- COBIT DSS05 โ ITIL Information Security Management.
ITIL implements operationally; COBIT governs.
Bridge to ISO 27001
- COBIT APO13 + DSS05 align with ISO 27001 ISMS substantively.
- COBIT MEA03 supports ISO 27001 Cl 9.1 + A.5.31.
- COBIT EDM emphasizes board-level oversight; ISO 27001 Cl 5.
SRE and AI-agent fit notes
For governance-strategy work:
- COBIT vocabulary aligns with board-level conversations.
- APO12 (Managed Risk) + APO13 (Managed Security) for cybersecurity governance.
- APO04 (Managed Innovation) for AI-adoption governance.
- BAI03 (Managed Solutions Identification and Build) for AI feature development.
Stefan-context implementation sketch
- For governance-tier client work: COBIT vocabulary useful.
- For implementation-tier: ITIL primary, COBIT-aware.