# What is COBIT?

> COBIT is a framework published by ISACA, formerly the Information Systems Audit and Control Association, for governing and managing enterprise information and technology (I&T).

- Canonical URL: https://yellowcube.eu/glossary/cobit/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The name originated from “Control Objectives for Information and Related Technologies,” but current COBIT addresses the enterprise-wide governance system rather than only audit controls. It connects stakeholder needs and enterprise goals to governance and management objectives, practices, information flows, organizational structures, policies, skills, culture, and technology.

COBIT 2019 is the current framework. It distinguishes governance — evaluating stakeholder needs, directing priorities, and monitoring results — from management’s planning, building, operating, and monitoring activities. Design factors help an organization tailor priorities and target capability rather than implement every objective identically.

### Key points

- **Start with outcomes:** Identify stakeholder value, enterprise goals, risk, resource, assurance, and compliance needs before selecting governance and management objectives.
- **Design for context:** Use factors such as strategy, threat landscape, sourcing, size, role of information and technology, and implementation methods to shape a fit-for-purpose governance system.
- **Assign and improve:** Clarify decision rights and accountability, integrate practices into operating structures, assess capability and performance, and maintain an improvement roadmap with evidence.
- **Important limitation:** COBIT is guidance, not a law, technical security standard, or organizational certification. Adoption, a maturity score, or an individual credential does not prove control effectiveness, regulatory compliance, or sound governance.

### Related terms

[Data governance](<https://yellowcube.eu/glossary/data-governance/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Information security policy](<https://yellowcube.eu/glossary/information-security-policy/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Business continuity](<https://yellowcube.eu/glossary/business-continuity/>)

### Sources

[ISACA, COBIT](https://www.isaca.org/resources/cobit) · [ISACA, COBIT Fact Sheet](https://www.isaca.org/about-us/-/media/4fc9d51512c54465b95c418d1468baef.ashx) · [ISO/IEC 38500:2024, Governance of IT for the Organization](https://www.iso.org/standard/81684.html)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

