GRCCopilot
Sign In
ISACA

COBIT 2019 Governance and Management Framework

The leading IT governance and management framework linking cybersecurity and IT to business objectives

Start Assessment Create Free Account
21
Controls
63
Questions
Active
Status
May 2031
Expires

About this Framework

COBIT 2019 (Control Objectives for Information and Related Technologies) provides a comprehensive framework for IT governance and management, enabling organisations to balance realising value from IT investments with optimising risk and resource use. Published by ISACA, COBIT 2019 introduces design factors allowing tailored governance systems aligned to enterprise context, risk profile and strategic goals. It is widely used by auditors, IT leaders and boards for assurance, governance oversight and digital transformation alignment.

Key Control Domains

Evaluate, Direct and Monitor (EDM)
Align, Plan and Organise (APO)
Build, Acquire and Implement (BAI)
Deliver, Service and Support (DSS)
Monitor, Evaluate and Assess (MEA)

Who Needs This?

  • Enterprise boards and executive leadership
  • IT governance committees and CIOs
  • Internal audit and assurance professionals
  • Organisations aligning with CISA/CRISC frameworks
  • Large enterprises with complex IT ecosystems

Compliance Benefits

  • Bridges cybersecurity to business value creation
  • Recognised by ISACA-certified auditors globally
  • Flexible design factors for any organisational context
  • Maps to ISO 38500, NIST CSF and ISO 27001

Official Reference

ISACA COBIT 2019 Resources
https://www.isaca.org/resources/cobit

Assessment Details

Issuer / AuthorityISACA
FrameworkCOBIT 2019 Governance and Management Framework
Controls21
Questions63
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2031

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/cobit-2019-governance-and-management-framework

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.