• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » COBIT 2019

COBIT 2019

Definition

COBIT 2019

COBIT 2019 is the current edition of ISACA’s governance framework for enterprise information and technology. It carries 40 governance and management objectives, and ISACA describes it as an evolution of the COBIT 5 edition that came just before it.

The naming convention changed with this edition — moving from a version number to a year signals a framework meant to be updated continuously rather than released in numbered generations.

Its most useful addition for outsourcing is the idea of design factors. Rather than adopting everything, an organisation tailors the framework to its own risk profile, regulatory exposure and sourcing model.

That tailoring matters because a heavily outsourced organisation needs a different governance design from one running everything in house — the objectives are the same, and the emphasis is not.

Key takeaways

  • It is the current edition of ISACA’s technology governance framework.
  • It defines 40 governance and management objectives.
  • Design factors tailor the framework to an organisation’s own context, including sourcing.
  • Focus areas provide targeted guidance for domains such as security and DevOps.

How it works

The framework sets out governance and management objectives, each with practices and metrics. Design factors then determine which objectives matter most for a given organisation, producing a tailored governance system rather than a uniform checklist.

The publisher describes the scope directly. ISACA’s guidance sets out 40 governance and management objectives and positions the edition as an evolution of its predecessor, adding implementation resources and practical guidance.

Targeted extensions sit alongside the core. ISACA publishes focus area guidance covering DevOps, information security, and information and technology risk, each applying the framework to a specific domain.

ComponentWhat it doesWhy it matters when outsourcing
Governance objectivesDirection, oversight, accountabilityCannot be delegated to a provider
Management objectivesPlanning, building, running, monitoringThe layer usually contracted out
Design factorsTailor the framework to contextSourcing model is one of the inputs
Focus areasDomain-specific guidanceUseful for security and delivery scope
MetricsMeasures attached to each objectiveSource material for contractual reporting

The acronym is recorded differently across authorities. The United States National Institute of Standards and Technology glossary expands it as Control Objectives for Information and Related Technologies.

That entry cites several NIST publications, while the publisher phrases the expansion slightly differently — worth checking before you quote it in a policy document.

The candid limitation is that tailoring invites selective adoption. An organisation can design a governance system that quietly omits the objectives it finds inconvenient — and nothing in the framework prevents that.

Examples

The framework reaches outsourcing through how a buyer designs oversight rather than through anything a provider is certified against. What follows are engagements in progress, rather than engagements somebody might one day win.

A bank tailors its governance design around heavy outsourcing, weighting objectives on third-party risk and supplier performance far above internal build activity.

A buyer derives its contractual reporting pack from the framework’s metrics, so provider reporting maps to internal governance rather than to the provider’s own dashboard.

An organisation applies the information security focus area to define what it requires from a cybersecurity outsourcing partner, rather than writing requirements from scratch.

An internal audit team uses design factors to justify why certain objectives are out of scope, which is legitimate when documented and convenient when not.

Related terms

Governance frameworks, audited standards and attestations do different jobs, and the entries below keep them apart. Each entry here defines one idea, with the nearest alternative deliberately ruled out.

  • ISO 27001: an auditable security management standard, unlike this non-certifiable framework.
  • SOC 2: an attestation report produced by an auditor on a provider’s controls.
  • compliance outsourcing: contracting the compliance function that operates these frameworks.
  • risk outsourcing: contracting risk activity while retaining ownership of the risk itself.
  • cybersecurity outsourcing: the domain covered by the security focus area guidance.
  • IT transformation outsourcing: programmes where governance design is usually rebuilt.
  • ESG: the reporting agenda that draws on similar governance vocabulary.

FAQ

How many objectives does COBIT 2019 have?

Forty governance and management objectives, each with associated practices and metrics that can be tailored to an organisation’s context.

What are design factors?

Inputs such as risk profile, regulatory environment and sourcing model that determine which objectives an organisation should emphasise.

Can an organisation be certified against it?

No. It is a governance framework, not a certifiable management system. Individuals can be certified; organisations cannot.

How does it differ from COBIT 5?

ISACA describes it as an evolution of the earlier edition, retaining its substance while adding design factors, focus areas and implementation guidance.

What are focus areas?

Domain-specific guidance applying the framework to particular subjects, including DevOps, information security, and information and technology risk.

How does it apply to outsourced services?

Management activity can be contracted out while governance stays internal. Design factors let you weight objectives toward third-party oversight.

Compare verified partners in the Outsource Accelerator directory and derive your reporting pack from the objectives that matter.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image