0% found this document useful (0 votes)
28 views7 pages

COBIT 2019: Principles for IT Governance

The document outlines the COBIT framework, designed to help organizations manage IT operations effectively in response to technological changes and regulations. It discusses the historical evolution of COBIT from its inception in 1996 to the current version, COBIT 2019, which emphasizes a customizable approach to governance and management. Key principles and components of COBIT 2019 are highlighted, showcasing its role in aligning IT with business goals and enhancing risk management in the digital age.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
28 views7 pages

COBIT 2019: Principles for IT Governance

The document outlines the COBIT framework, designed to help organizations manage IT operations effectively in response to technological changes and regulations. It discusses the historical evolution of COBIT from its inception in 1996 to the current version, COBIT 2019, which emphasizes a customizable approach to governance and management. Key principles and components of COBIT 2019 are highlighted, showcasing its role in aligning IT with business goals and enhancing risk management in the digital age.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

​ 1

Outlining the COBIT Framework: A Foundation for Managing IT Operations

Venkata Sai Ram Kowdi

Department of Information Technology, Westcliff University.

Professor Moice Dixon


​ 2

Introduction

In today’s digital age, organizations need to keep up with many changes in technology

such as to meet strict government regulations and handling cyber attacks. To make changes to the

IT systems changes effective and organized, COBIT (Control Objectives for Information and

Related Technology) framework is designed. COBIT is created by ISACA (Information Systems

Audit and Control Association). The framework provides organizations a streamlined approach

to meet business expectations with technical solutions. The current version used today is COBIT

2019, which is being refined continuously to meet the modern demands of digital transformation.

This paper explains the core concepts of the COBIT framework and how they play a crucial role

in running IT operations.

Historical Evolution and Purpose of COBIT

The first iteration of COBIT was in 1996, during that period the primary goal was to

handle IT auditing in finance. It ensured all financial technological systems displayed accurate

data for compliance. Soon as the technology started to play a major role in IT, COBIT has

evolved to satisfy the requirements.

In 2012, COBIT 5 was released which is said to be the biggest change shifting focus from

auditing to bringing in a holistic view of IT governance and management. Governance is the

direction business leaders set to achieve goals and Management is where the IT team takes care

of the software development lifecycle to align with the business goals. COBIT 5 also took a

couple of ideas from other frameworks like ISO 38500 (which focuses on IT governance) and

ITIL (which focuses on IT management).


​ 3

Then came COBIT 2019 which is the latest version that further improved COBIT 5 to

make it more customizable for organizations to incorporate their design factors. It adopted

performance measuring business standards such as CMMI (Capability Maturity Model

Integration) which provides a benchmark measure for leaders to understand how well IT

processes are working towards the determined goals.

Core Principles of COBIT 2019

COBIT 2019 was designed with six core principles in mind that strongly tires governance

and management in IT.

The first principle - “Provide Stakeholder Value”. This principle makes sure the IT team's

primary focus should be to support the needs from the stakeholders which include - customers,

employees, investors and management. To keep track of goals COBIT uses a goals cascade

approach where the business goals are first split into small IT goals which are further broken

down into day-to-day actions. This ensures every day-to-day action would directly support the

larger business goal with actual value than just being a regular technical task.

The second principle - “Holistic Approach”. This principle reminds that governance is

not just about software or hardware but a combined well tied system that includes everything that

affects the IT team. The external factors would include not limited to people, processes, culture,

technologies and data. As an example if a technology is considered by the business leaders as a

future direction or a replacement for an existing service, it might receive resistance from the

developers to adopt or to learn. In another situation, the employees might not know how to use it

entirely which may or may not impact the end product but the timeline would definitely have an
​ 4

impact if the learning curve is involved. So, the holistic approach considers everything to make

sure all parts involved are well tied and work effectively.

The third principle - “Dynamic Governance System”. This principle embraces change

within organizations. As time passes, new technologies emerge, which might have an impact not

only on rules and regulations but also new risks. The principal stresses that governance systems

that put in place should be dynamic and be adaptable during changes within organizations. For

example, if new privacy laws are introduced, data handling would be swiftly improved to align

with the privacy laws.

The fourth principle - “Governance Distinct from Management”. This principle is highly

emphasized in frameworks like ISO 38500 which essentially means that governance (what to do

and why) is very different from management (how to do it). This principle is put in place to

segregate roles and responsibilities. Governance would be taken care of the upper management

while management is handled by the operational team or the IT team based on the organization.

The fifth principle - “Tailored to Enterprise Needs”. Every organization is different with

different set of goals, risks and rules within their industry. For example, hospitals and banks

operate differently which is why it is important to have tailored needs based on the organization.

COBIT says to not copy-paste a governance model and instead to analyze the business needs and

customize the governance system.

The sixth principle - “End-to-End Governance System”. Governance is believed to only

handle IT. However COBIT suggests that governance should be implemented in every

department. For example, data handling might be done at a different level from IT operations

which are also to be governed.


​ 5

COBIT Key Components

COBIT 2019 defines several important components that are tied together that create a

strong and effective system for Enterprise Governance of Information and Technology (EGIT).

COBIT focuses on the entire ecosystem rather than focusing on a singular component. There are

several components that COBIT covers which interact to support governance and management.

These are looked at together and are end to end governed.

Processes which include step by step everyday activities or workflow, Organizational

Structures which define the roles and responsibilities of each department, Information Flows and

Items which covers from actual data movement through the organizational system to how it is

stored and shared, People and Skills which includes the knowledge and abilities of staff members

in the IT and decision-making, Culture and Behavior of the employees that includes the mindset

and values, Policies and Procedures that are written rules and instructions that ensure consistent

compliance, and Services and Infrastructure which is essentially the IT systems, tool sand

platforms that support the organization's architecture.

COBIT Structure

COBIT 2019 has a structured 40 governance and management objectives that are grouped

into five key domains.

The first domain is EDM (Evaluate, Direct and Monitor) - This domain specifically

focuses on governance which boils down to setting strategies, tracking performance and making

sure everything is aligned to the business goals.


​ 6

The second domain is APO (Align, Plan and Organize) - This domain deals with aligning

the IT with the business goals along with the plan for the strategies and organizing everything to

reduce risks and efficiently tie everything together within the given budget.

The third domain is BAI (Build, Acquire and Implement) - This is primarily handled by

the IT to build, acquire the requirements and implement the solutions.

The fourth domain is DSS (Deliver, Service and Support) - The domain primarily focuses

on everyday IT operations and support such as service desk operations and issue resolution.

The fifth domain is MEA (Monitor, Evaluate and Assess) - This domain is about tracking

and reviewing the IT governance systems and to bridge any gaps, reduce/handle roadblocks and

implement ideas for improvement.

Conclusion

The COBIT is a framework that helps organizations with a flexible toolkit for governance

and management of Information and Technology. COBIT made a significant difference since it

has transformed from a rigid model to being a dynamic model that provides principles, guidance

and resources that help organizations design their custom governance plan. The plan can be

further adopted by several industries and based on company sizes within the industry which

makes it highly flexible. Implementing COBIT 2019 to their business plan would result in

well-defined business goals and results that align with the business goals that create an actual

value. This framework also helps organizations to equip risk-management guidance to anticipate

and mitigate cybersecurity risks. I found organizations that implement COBIT would have a

stronger control in governance and management which has a huge advantage in the digital age.
​ 7

References

CIO. (2023, June 12). What is COBIT? A framework for alignment and governance.

[Link]

ml

De Haes, S., Van Grembergen, W., Joshi, A., Huygh, T. (2020). COBIT as a Framework for

Enterprise Governance of IT. In: Enterprise Governance of Information Technology.

Management for Professionals. Springer, Cham. [Link]

ISACA. (2019). COBIT 2019 Framework: Introduction and methodology.

[Link]

Common questions

Powered by AI

COBIT 2019 establishes six core principles that enhance IT governance and management: 1) Provide Stakeholder Value: Ensures IT activities align with stakeholders' needs using a goals cascade approach. 2) Holistic Approach: Includes all aspects such as people, processes, culture, and technology. 3) Dynamic Governance System: Adapts to changes like new privacy laws. 4) Governance Distinct from Management: Separates strategic roles from operational roles. 5) Tailored to Enterprise Needs: Customizes governance to organization-specific requirements. 6) End-to-End Governance System: Extends governance beyond IT to all departments .

COBIT 2019’s structured domains encompass EDM, APO, BAI, DSS, and MEA, each contributing to various facets of IT governance and management. EDM focuses on strategy alignment and performance tracking, APO deals with aligning IT with business goals, BAI manages solution implementation, DSS addresses daily IT operations, and MEA involves monitoring and improving governance systems. These domains ensure a comprehensive, structured approach to IT governance that aligns with organizational goals while maintaining operational efficiency .

COBIT 2019 emphasizes separating governance from management to outline distinct roles and responsibilities. Governance involves setting strategies and objectives ("what to do"), while management executes these through operational tasks ("how to do it"). This distinction reduces confusion, enhances accountability, and allows organizations to efficiently align IT operations with strategic goals .

The goal cascade model in COBIT 2019 ensures alignment by transforming high-level business goals into specific IT goals, further breaking them down into actionable daily IT tasks. This cascading ensures that everyday IT operations contribute directly to the strategic business objectives, providing actual value rather than being isolated technical activities, thereby ensuring convergence of IT activities with business priorities .

The "Dynamic Governance System" principle of COBIT 2019 allows organizations to adapt to changes in technology and regulations by ensuring governance systems remain flexible. It enables organizations to swiftly update data handling processes to comply with new laws, like privacy regulations, mitigating potential risks associated with technological shifts and legal requirements .

COBIT 2019 incorporates performance measuring tools like CMMI to provide benchmarks for evaluating IT process effectiveness. CMMI offers a structured assessment framework enabling leaders to understand process maturity and capability, thus helping organizations identify areas of improvement and ensure that IT processes are efficiently meeting predetermined goals aligned with business objectives .

The key components of COBIT 2019 include Processes, Organizational Structures, Information Flows and Items, People and Skills, Culture and Behavior, Policies and Procedures, and Services and Infrastructure. These components interact to form a cohesive governance framework: Processes involve daily workflows, Organizational Structures define departmental roles, and Information Flows manage data movement. The interplay of skilled personnel, cultural alignment, consistent policy implementation, and robust IT infrastructure ensures comprehensive governance and supports the organization's objectives .

COBIT 2019 enhances cybersecurity risk management by providing a flexible governance framework that can be customized to anticipate and mitigate cyber threats. Its principles promote a holistic view of IT governance, encompassing risk management strategies that include aligning IT security measures with business objectives, adhering to updated regulations, and ensuring robust policies and procedures. This comprehensive approach helps organizations strengthen their cybersecurity posture in the digital age .

Initially, COBIT focused on IT auditing in finance to ensure data accuracy for compliance. Over time, the focus shifted with COBIT 5 in 2012 from auditing to IT governance and management, integrating ideas from frameworks like ISO 38500. COBIT 2019 advanced this by allowing more customization to meet enterprise needs and incorporating performance measures like CMMI to better align IT processes with business goals, further enhancing its holistic and dynamic capabilities .

The 'Tailored to Enterprise Needs' principle in COBIT 2019 facilitates adaptability by encouraging organizations to customize their IT governance practices according to their specific goals, risks, and regulatory environments. This flexibility allows diverse industries, such as healthcare and finance, to implement governance models that align with their unique operational needs, ensuring relevance and effectiveness .

You might also like