COBIT
Definition
Control Objectives for Information and Related Technologies, published by ISACA. A governance and management framework for enterprise IT that defines IT-specific control objectives across domains including Align, Plan and Organise; Build, Acquire and Implement; Deliver, Service and Support; and Monitor, Evaluate and Assess. COBIT 2019 is the current version.
- Full name
- Control Objectives for Information and Related Technologies
- Publisher
- ISACA
- Current version
- COBIT 2019
- Domains
- Align/Plan/Organise, Build/Acquire/Implement, Deliver/Service/Support, Monitor/Evaluate/Assess
Common questions
How does COBIT differ from a framework like ISO 27001 or NIST CSF?+
COBIT is a governance and management framework covering IT control objectives broadly, including value delivery and risk optimisation for the whole IT function, whereas ISO 27001 and NIST CSF focus specifically on information security controls, so an organisation may run COBIT for governance and layer a security-specific framework underneath it.
Where does COBIT come up in a forensic or fraud engagement?+
Auditors and forensic accountants cite COBIT control objectives when assessing whether an organisation's IT general controls, such as change management or access provisioning, were adequate, which bears on whether a breach or manipulation could have been prevented or detected earlier.
Related terms
- Control Environment
- The first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational structure, commitment...
- COSO Integrated Framework
- A framework for internal control published by the Committee of Sponsoring Organizations of the Treadway Commission, defining five interrelated components: control environment,...
- Detective Control
- A control designed to identify an error or irregularity after it has occurred. Examples include bank reconciliations, exception reports, variance analysis, and...
- IT General Controls (ITGCs)
- Controls over the IT environment that support the reliable operation of application controls. Key categories include access management, change management, computer operations,...
- Preventive Control
- A control designed to stop an error or fraudulent act before it occurs. Examples include segregation of duties, mandatory authorisation limits, access...