Back to Frameworks

COBIT 2019

International
v2019
10 domains
68 controls

Control Objectives for Information and Related Technologies - governance framework for enterprise IT management

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

APO - Align, Plan and Organize

14 controls

Management domain for overall organization, strategy, and supporting activities for IT

Controls in the APO - Align, Plan and Organize domain of COBIT 201914 controls
CodeTitle
COBIT-APO01Managed IT management framework
COBIT-APO02Managed strategy
COBIT-APO03Managed enterprise architecture
COBIT-APO04Managed innovation
COBIT-APO05Managed portfolio
COBIT-APO06Managed budget and costs
COBIT-APO07Managed human resources
COBIT-APO08Managed relationships
COBIT-APO09Managed service agreements
COBIT-APO10Managed vendors
COBIT-APO11Managed quality
COBIT-APO12Managed risk
COBIT-APO13Managed security
COBIT-APO14Managed data

Align, Plan and Organize

9 controls
Controls in the Align, Plan and Organize domain of COBIT 20199 controls
CodeTitle
APO01Managed I&T Management Framework
APO02Managed Strategy
APO07Managed Human Resources
APO08Managed Relationships
APO09Managed Service Agreements
APO10Managed Vendors
APO12Managed Risk
APO13Managed Security
APO14Managed Data

BAI - Build, Acquire and Implement

11 controls

Management domain for definition, acquisition, and implementation of IT solutions

Controls in the BAI - Build, Acquire and Implement domain of COBIT 201911 controls
CodeTitle
COBIT-BAI01Managed programs
COBIT-BAI02Managed requirements definition
COBIT-BAI03Managed solutions identification and build
COBIT-BAI04Managed availability and capacity
COBIT-BAI05Managed organizational change
COBIT-BAI06Managed IT changes
COBIT-BAI07Managed IT change acceptance and transitioning
COBIT-BAI08Managed knowledge
COBIT-BAI09Managed assets
COBIT-BAI10Managed configuration
COBIT-BAI11Managed projects

Build, Acquire and Implement

8 controls
Controls in the Build, Acquire and Implement domain of COBIT 20198 controls
CodeTitle
BAI01Managed Programs
BAI02Managed Requirements Definition
BAI03Managed Solutions Identification and Build
BAI06Managed IT Changes
BAI07Managed IT Change Acceptance and Transitioning
BAI08Managed Knowledge
BAI09Managed Assets
BAI10Managed Configuration

DSS - Deliver, Service and Support

6 controls

Management domain for operational delivery and support of IT services

Controls in the DSS - Deliver, Service and Support domain of COBIT 20196 controls
CodeTitle
COBIT-DSS01Managed operations
COBIT-DSS02Managed service requests and incidents
COBIT-DSS03Managed problems
COBIT-DSS04Managed continuity
COBIT-DSS05Managed security services
COBIT-DSS06Managed business process controls

Deliver, Service and Support

3 controls
Controls in the Deliver, Service and Support domain of COBIT 20193 controls
CodeTitle
DSS01Managed Operations
DSS02Managed Service Requests and Incidents
DSS05Managed Security Services

EDM - Evaluate, Direct and Monitor

5 controls

Governance domain ensuring stakeholder value delivery, risk optimization, and resource optimization

Controls in the EDM - Evaluate, Direct and Monitor domain of COBIT 20195 controls
CodeTitle
COBIT-EDM01Ensured governance framework setting and maintenance
COBIT-EDM02Ensured benefits delivery
COBIT-EDM03Ensured risk optimization
COBIT-EDM04Ensured resource optimization
COBIT-EDM05Ensured stakeholder engagement

Evaluate, Direct and Monitor

5 controls
Controls in the Evaluate, Direct and Monitor domain of COBIT 20195 controls
CodeTitle
EDM01Ensured Governance Framework Setting and Maintenance
EDM02Ensured Benefits Delivery
EDM03Ensured Risk Optimization
EDM04Ensured Resource Optimization
EDM05Ensured Stakeholder Engagement

MEA - Monitor, Evaluate and Assess

4 controls

Management domain for performance monitoring, internal control assessment, and compliance

Controls in the MEA - Monitor, Evaluate and Assess domain of COBIT 20194 controls
CodeTitle
COBIT-MEA01Managed performance and conformance monitoring
COBIT-MEA02Managed system of internal control
COBIT-MEA03Managed compliance with external requirements
COBIT-MEA04Managed assurance

Monitor, Evaluate and Assess

3 controls
Controls in the Monitor, Evaluate and Assess domain of COBIT 20193 controls
CodeTitle
MEA01Managed Performance and Conformance Monitoring
MEA02Managed System of Internal Control
MEA03Managed Compliance with External Requirements

Your Compliance Coverage

If you comply with COBIT 2019, you already cover:

Maps to 170 other frameworks

68 total controls
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|2 target controls covered
3%
PSD2 SCA
2 source controls mapped|2 target controls covered
3%
OSFI B-13
2 source controls mapped|3 target controls covered
3%
Open Banking Security
2 source controls mapped|3 target controls covered
3%
O-RAN WG11 Security Specification
2 source controls mapped|3 target controls covered
3%
3%
MTCS (Singapore)
2 source controls mapped|2 target controls covered
3%
Monetary Authority of Singapore Technology Risk Management Guidelines
2 source controls mapped|3 target controls covered
3%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
2 source controls mapped|2 target controls covered
3%
HKMA SPM
2 source controls mapped|2 target controls covered
3%
HKMA Cyber Resilience Assessment Framework (C-RAF)
2 source controls mapped|2 target controls covered
3%
GLBA
2 source controls mapped|2 target controls covered
3%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|2 target controls covered
3%
ISO/IEC 38500:2024 - Governance of IT
2 source controls mapped|4 target controls covered
3%
ISO/IEC 27031:2011
2 source controls mapped|3 target controls covered
3%
ISO/IEC 27007:2020
2 source controls mapped|2 target controls covered
3%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|3 target controls covered
3%
IEC 62351 - Power Systems Communication Security
2 source controls mapped|3 target controls covered
3%
ISO/IEC 25012:2008 - Data Quality Model
2 source controls mapped|3 target controls covered
3%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|3 target controls covered
3%
PCI SSF
2 source controls mapped|4 target controls covered
3%
SSAE 18 - Attestation Standards (SOC Reporting)
2 source controls mapped|3 target controls covered
3%
SOC 2
2 source controls mapped|5 target controls covered
3%
PCI P2PE
2 source controls mapped|4 target controls covered
3%
PCI PIN Security
2 source controls mapped|4 target controls covered
3%
NIST Cybersecurity Framework 2.0
2 source controls mapped|5 target controls covered
3%
FFIEC IT Examination Handbook
2 source controls mapped|4 target controls covered
3%
APRA CPS 234
2 source controls mapped|4 target controls covered
3%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
1%
WCAG 2.2
1 source controls mapped|1 target controls covered
1%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
1%
UK Gambling Commission - Cyber Resilience Requirements
1 source controls mapped|2 target controls covered
1%
UK GDPR (UK General Data Protection Regulation)
1 source controls mapped|1 target controls covered
1%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
1 source controls mapped|1 target controls covered
1%
UK Bribery Act 2010
1 source controls mapped|1 target controls covered
1%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|3 target controls covered
1%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|2 target controls covered
1%
SLSA
1 source controls mapped|1 target controls covered
1%
SIG (Shared Assessments)
1 source controls mapped|1 target controls covered
1%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
1%
PTES
1 source controls mapped|1 target controls covered
1%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|3 target controls covered
1%
Philippines Cybercrime Prevention Act (RA 10175)
1 source controls mapped|1 target controls covered
1%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|2 target controls covered
1%
OWASP Top 10:2025
1 source controls mapped|1 target controls covered
1%
OWASP SAMM
1 source controls mapped|1 target controls covered
1%
OWASP MASVS
1 source controls mapped|1 target controls covered
1%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|2 target controls covered
1%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
1%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|1 target controls covered
1%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|2 target controls covered
1%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
1%
NIST SP 800-92
1 source controls mapped|1 target controls covered
1%
NIST SP 800-88
1 source controls mapped|1 target controls covered
1%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
1%
NIST SP 800-61
1 source controls mapped|1 target controls covered
1%
NIST SP 800-146
1 source controls mapped|1 target controls covered
1%
NIST SP 800-145
1 source controls mapped|1 target controls covered
1%
NIST SP 800-144
1 source controls mapped|1 target controls covered
1%
NIST SP 800-137
1 source controls mapped|1 target controls covered
1%
NIST SP 800-123
1 source controls mapped|1 target controls covered
1%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
1%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|3 target controls covered
1%
Nebraska Data Privacy Act
1 source controls mapped|3 target controls covered
1%
MITRE D3FEND
1 source controls mapped|1 target controls covered
1%
MITRE ATT&CK
1 source controls mapped|1 target controls covered
1%
South Korea PIPA
1 source controls mapped|1 target controls covered
1%
ITU Radio Regulations and Space Security Standards
1 source controls mapped|1 target controls covered
1%
ITAR - International Traffic in Arms Regulations
1 source controls mapped|1 target controls covered
1%
Israel Protection of Privacy Law (5741-1981)
1 source controls mapped|2 target controls covered
1%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
1%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|2 target controls covered
1%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
1%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|2 target controls covered
1%
IATA Operational Safety Audit (IOSA) Standards Manual
1 source controls mapped|1 target controls covered
1%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
1%
GAMP 5 - Good Automated Manufacturing Practice
1 source controls mapped|2 target controls covered
1%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
1%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|1 target controls covered
1%
FedRAMP Rev 5
1 source controls mapped|2 target controls covered
1%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
1%
FATF Recommendation 16 - Virtual Asset Travel Rule
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|4 target controls covered
1%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|3 target controls covered
1%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
1%
ISO/IEC 27400:2022
1 source controls mapped|3 target controls covered
1%
ISO/IEC 27011:2024
1 source controls mapped|3 target controls covered
1%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
1%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|2 target controls covered
1%
1%
ISO 19011
1 source controls mapped|2 target controls covered
1%
1%
ISO 31000:2018
1 source controls mapped|1 target controls covered
1%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 30111:2019
1 source controls mapped|3 target controls covered
1%
ISO/IEC 29147:2018
1 source controls mapped|3 target controls covered
1%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
1%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|3 target controls covered
1%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
1%
ISO/IEC 27014:2020
1 source controls mapped|3 target controls covered
1%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|2 target controls covered
1%
Barbados Data Protection Act 2019
1 source controls mapped|1 target controls covered
1%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|3 target controls covered
1%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|3 target controls covered
1%
Azure Security Benchmark
1 source controls mapped|1 target controls covered
1%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
1%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|2 target controls covered
1%
FedRAMP High
1 source controls mapped|1 target controls covered
1%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
1%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
1%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
1%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
1%
AWS Well-Architected Security Pillar
1 source controls mapped|1 target controls covered
1%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
1 source controls mapped|3 target controls covered
1%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|1 target controls covered
1%
IEC 62304:2015 Medical Device Software Lifecycle Processes
1 source controls mapped|3 target controls covered
1%
ISO 56002
1 source controls mapped|4 target controls covered
1%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|3 target controls covered
1%
ISO 39001:2012 - Road Traffic Safety Management
1 source controls mapped|3 target controls covered
1%
ISO 37002:2021 - Whistleblowing Management Systems
1 source controls mapped|3 target controls covered
1%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
1 source controls mapped|3 target controls covered
1%
ISO/IEC 27006:2024
1 source controls mapped|3 target controls covered
1%
ISO 27017
1 source controls mapped|1 target controls covered
1%
ISO 37000:2021 - Governance of Organizations
1 source controls mapped|3 target controls covered
1%
ISO 8000 - Data Quality
1 source controls mapped|2 target controls covered
1%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|3 target controls covered
1%
AS9100D - Aerospace Quality Management System
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27003:2017
1 source controls mapped|1 target controls covered
1%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|2 target controls covered
1%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 23894:2023
1 source controls mapped|3 target controls covered
1%
ISO/SAE 21434
1 source controls mapped|1 target controls covered
1%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|1 target controls covered
1%
ISO 22320:2018
1 source controls mapped|3 target controls covered
1%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|2 target controls covered
1%
NIST SP 800-190
1 source controls mapped|1 target controls covered
1%
ISO 27043
1 source controls mapped|1 target controls covered
1%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|2 target controls covered
1%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
1%
ISO 27018
1 source controls mapped|1 target controls covered
1%
ISO 26262:2018 - Functional Safety for Road Vehicles
1 source controls mapped|1 target controls covered
1%
SANS Incident Handler's Handbook and PICERL Methodology
1 source controls mapped|2 target controls covered
1%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
1 source controls mapped|1 target controls covered
1%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
1%
South Africa Promotion of Access to Information Act (PAIA)
1 source controls mapped|1 target controls covered
1%
UK AI Regulation Framework
1 source controls mapped|1 target controls covered
1%
SASB Standards
1 source controls mapped|1 target controls covered
1%
OECD AI Principles
1 source controls mapped|1 target controls covered
1%
NIST Privacy Framework
1 source controls mapped|2 target controls covered
1%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
1%
Japan AI Guidelines
1 source controls mapped|1 target controls covered
1%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
1%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
1 source controls mapped|1 target controls covered
1%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
1%
IEEE 7000
1 source controls mapped|1 target controls covered
1%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
1%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|1 target controls covered
1%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
1%
ITIL 4
1 source controls mapped|1 target controls covered
1%
ISO 20000-1
1 source controls mapped|1 target controls covered
1%

Frequently Asked Questions

What is COBIT 2019?

COBIT 2019 is a compliance framework from International with 10 domains and 68 controls. Control Objectives for Information and Related Technologies - governance framework for enterprise IT management It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does COBIT 2019 have?

COBIT 2019 has 68 controls organised across 10 domains. The largest domains are APO - Align, Plan and Organize (14 controls), BAI - Build, Acquire and Implement (11 controls), Align, Plan and Organize (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does COBIT 2019 map to?

COBIT 2019 maps to 170 other compliance frameworks. The top mapping partners are Protective Security Policy Framework (PSPF) Release 2024 (3% coverage), PSD2 SCA (3% coverage), OSFI B-13 (3% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with COBIT 2019 compliance?

Start your COBIT 2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about COBIT 2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 68 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required