IT Governance and COBIT 2019 for DISA
COBIT 2019 is the vocabulary of Module 2. Learn the structure, then the traps that come from old COBIT 5 notes.
COBIT 2019 is ISACA's framework for the governance and management of enterprise information and technology (I&T). It is the backbone of Module 2 of the ISA 3.0 course, and the vocabulary the Assessment Test uses whenever it asks who should decide, approve or monitor something about IT.
For an auditor, COBIT is a benchmark. It tells you what good governance of IT looks like, so you can compare a client's board committees, policies and processes against it and report the gaps. It replaced COBIT 5, which ISACA describes COBIT 2019 as an evolution of; if your notes talk about "enablers" and five principles, they are COBIT 5 notes.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Five Domains and 40 Objectives
COBIT 2019's core model has 40 governance and management objectives, grouped into one governance domain and four management domains.
EDM: Evaluate, Direct and Monitor
Type
Governance
What it covers
The board evaluates strategic options, directs senior management and monitors achievement
APO: Align, Plan and Organise
Type
Management
What it covers
The organisation's strategy and supporting activities for I&T, including risk (APO12 Managed Risk)
BAI: Build, Acquire and Implement
Type
Management
What it covers
Defining, acquiring and implementing I&T solutions and integrating them into business processes
DSS: Deliver, Service and Support
Type
Management
What it covers
Operational delivery and support of I&T services
MEA: Monitor, Evaluate and Assess
Type
Management
What it covers
Performance monitoring and conformance with internal targets, internal control objectives and external requirements
| Domain | Type | What it covers |
|---|---|---|
| EDM: Evaluate, Direct and Monitor | Governance | The board evaluates strategic options, directs senior management and monitors achievement |
| APO: Align, Plan and Organise | Management | The organisation's strategy and supporting activities for I&T, including risk (APO12 Managed Risk) |
| BAI: Build, Acquire and Implement | Management | Defining, acquiring and implementing I&T solutions and integrating them into business processes |
| DSS: Deliver, Service and Support | Management | Operational delivery and support of I&T services |
| MEA: Monitor, Evaluate and Assess | Management | Performance monitoring and conformance with internal targets, internal control objectives and external requirements |
Terms the Exam Expects You to Know
- Governance vs management
- Governance (board) evaluates stakeholder needs, sets direction and monitors performance and compliance. Management (executives under the CEO) plans, builds, runs and monitors activities in line with that direction. COBIT keeps the two distinct.
- Six governance system principles
- Provide stakeholder value; end-to-end governance system; tailored to enterprise needs; holistic approach; governance distinct from management; dynamic governance system.
- Seven components
- Processes; organisational structures; principles, policies and procedures; information; culture, ethics and behaviour; people, skills and competencies; services, infrastructure and applications. COBIT 5 called these enablers.
- Design factors and focus areas
- Design factors (enterprise strategy and goals, risk profile, threat landscape, compliance requirements, role of IT, technology adoption strategy, enterprise size and so on) tailor the governance system. Focus areas are add-on guides for a topic such as information security, DevOps or I&T risk.
- Goals cascade
- Stakeholder drivers translate into enterprise goals, then alignment goals, then the governance and management objectives that matter most for this enterprise.
Using COBIT on an Engagement
A typical use: a private bank's audit committee asks for an independent view of IT governance before a core banking upgrade.
- 1
Understand context and strategy
Read the board-approved IT strategy, risk appetite and regulatory obligations. This mirrors step 1 of COBIT's four-step design guide.
- 2
Scope the objectives that matter
A core banking upgrade puts BAI (building and implementing the change), APO12 (risk) and DSS (keeping services running) in scope ahead of objectives with little bearing on the upgrade.
- 3
Test the components
Is there a board-level IT strategy committee with a charter? Are policies approved and current? Do processes produce evidence, such as risk registers and change records?
- 4
Rate capability and report
COBIT 2019 lets you report with capability or maturity measures. Tie every gap to a governance or management objective so the board can see whose job it is.
Quick practice on audit concepts. No signup.
COBIT and Indian Regulation
For banks, RBI's Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (31 July 2026) name the IT governance focus areas as strategic alignment, risk management, resource management, performance management and business continuity/DR management. COBIT gives you the detailed practices behind those headings; the RBI Directions give you the mandatory structure.
How the DISA Assessment Test Tests This
Expect short scenario MCQs, often worded "primary", "best" or "most important". The common traps:
- check_circleMixing up governance and management. Setting direction and monitoring is EDM (board); approving and running projects is management.
- check_circleAnswering with COBIT 5 terms. "Enablers" and the five COBIT 5 principles belong to the old framework.
- check_circlePicking the IT answer when the question asks about value. COBIT's first principle is stakeholder value, so the best answer usually ties IT back to business objectives.
- check_circleTreating COBIT as certifiable. It is a framework you assess against, not a standard an organisation gets certified to.
FAQs
How many governance and management objectives are there in COBIT 2019?expand_more
Forty, grouped into five domains: EDM for governance, and APO, BAI, DSS and MEA for management.
What is the difference between COBIT 5 and COBIT 2019?expand_more
COBIT 2019 builds on COBIT 5 but renames enablers as components, restates the principles (six for the governance system), adds design factors and focus areas for tailoring, and lets you measure processes by capability or maturity.
Which COBIT domain covers governance?expand_more
Only EDM (Evaluate, Direct and Monitor). The other four domains are management domains.
Is ISO/IEC 38500 the same as COBIT?expand_more
No. ISO/IEC 38500 (current edition 2024) sets high-level principles for the governing body on the use of IT. COBIT is far more detailed and covers management practices too. The ISA 3.0 material refers to the 2015 edition.
Next steps
- COBIT vs ISO vs ITILarrow_forward
- IT Committeesarrow_forward
- IT Risk Managementarrow_forward
- Syllabusarrow_forward
Assessment Test format, timed and scored.
