Skip to content

COBIT

Definition

Control Objectives for Information and Related Technologies, published by ISACA. A governance and management framework for enterprise IT that defines IT-specific control objectives across domains including Align, Plan and Organise; Build, Acquire and Implement; Deliver, Service and Support; and Monitor, Evaluate and Assess. COBIT 2019 is the current version.

Full name
Control Objectives for Information and Related Technologies
Publisher
ISACA
Current version
COBIT 2019
Domains
Align/Plan/Organise, Build/Acquire/Implement, Deliver/Service/Support, Monitor/Evaluate/Assess

Common questions

How does COBIT differ from a framework like ISO 27001 or NIST CSF?+

COBIT is a governance and management framework covering IT control objectives broadly, including value delivery and risk optimisation for the whole IT function, whereas ISO 27001 and NIST CSF focus specifically on information security controls, so an organisation may run COBIT for governance and layer a security-specific framework underneath it.

Where does COBIT come up in a forensic or fraud engagement?+

Auditors and forensic accountants cite COBIT control objectives when assessing whether an organisation's IT general controls, such as change management or access provisioning, were adequate, which bears on whether a breach or manipulation could have been prevented or detected earlier.

Related terms

Control Environment
The first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational structure, commitment...
COSO Integrated Framework
A framework for internal control published by the Committee of Sponsoring Organizations of the Treadway Commission, defining five interrelated components: control environment,...
Detective Control
A control designed to identify an error or irregularity after it has occurred. Examples include bank reconciliations, exception reports, variance analysis, and...
IT General Controls (ITGCs)
Controls over the IT environment that support the reliable operation of application controls. Key categories include access management, change management, computer operations,...
Preventive Control
A control designed to stop an error or fraudulent act before it occurs. Examples include segregation of duties, mandatory authorisation limits, access...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.