Global (ISACA)

COBIT 2019

342 controls. 185 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

342 controls 185 frameworks share controls with it Global (ISACA) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

COBIT 2019 Evidence & Implementation Kit

342 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
APO01Managed I&T Management Framework0
APO02Managed Strategy0
APO07Managed Human Resources0
APO08Managed Relationships0
APO09Managed Service Agreements0
APO10Managed Vendors0
APO12Managed Risk0
APO13Managed Security0
APO14Managed Data0
BAI01Managed Programs0
BAI02Managed Requirements Definition0
BAI03Managed Solutions Identification and Build0
BAI06Managed IT Changes0
BAI07Managed IT Change Acceptance and Transitioning0
BAI08Managed Knowledge0
BAI09Managed Assets0
BAI10Managed Configuration0
COBIT-APO01Managed IT management framework0
COBIT-APO02Managed strategy0
COBIT-APO03Managed enterprise architecture0
COBIT-APO04Managed innovation0
COBIT-APO05Managed portfolio0
COBIT-APO06Managed budget and costs0
COBIT-APO07Managed human resources0
COBIT-APO08Managed relationships0
COBIT-APO09Managed service agreements0
COBIT-APO10Managed vendors0
COBIT-APO11Managed quality0
COBIT-APO12Managed risk0
COBIT-APO13Managed security0
COBIT-APO14Managed data0
COBIT-BAI01Managed programs0
COBIT-BAI02Managed requirements definition157
COBIT-BAI03Managed solutions identification and build0
COBIT-BAI04Managed availability and capacity52
COBIT-BAI05Managed organizational change0
COBIT-BAI06Managed IT changes0
COBIT-BAI07Managed IT change acceptance and transitioning0
COBIT-BAI08Managed knowledge0
COBIT-BAI09Managed assets0
COBIT-BAI10Managed configuration0
COBIT-BAI11Managed projects0
COBIT-DSS01Managed operations0
COBIT-DSS02Managed service requests and incidents0
COBIT-DSS03Managed problems0
COBIT-DSS04Managed continuity0
COBIT-DSS05Managed security services0
COBIT-DSS06Managed business process controls0
COBIT-EDM01Ensured governance framework setting and maintenance0
COBIT-EDM02Ensured benefits delivery0
COBIT-EDM03Ensured risk optimization0
COBIT-EDM04Ensured resource optimization0
COBIT-EDM05Ensured stakeholder engagement0
COBIT-MEA01Managed performance and conformance monitoring0
COBIT-MEA02Managed system of internal control0
COBIT-MEA03Managed compliance with external requirements0
COBIT-MEA04Managed assurance0
DSS01Managed Operations0
DSS02Managed Service Requests and Incidents0
DSS05Managed Security Services0
EDM01Ensured Governance Framework Setting and Maintenance0
EDM02Ensured Benefits Delivery0
EDM03Ensured Risk Optimization0
EDM04Ensured Resource Optimization0
EDM05Ensured Stakeholder Engagement0
MEA01Managed Performance and Conformance Monitoring0
MEA02Managed System of Internal Control0
MEA03Managed Compliance with External Requirements0
APO01APO01 Managed I&T Management Framework0
APO01.01APO01.01 Design the management system for enterprise I&T1
APO01.02APO01.02 Communicate management objectives, direction and decisions made3
APO01.03APO01.03 Implement management processes (to support the achievement of governance and management objectives)1
APO01.04APO01.04 Define and implement the organizational structures2
APO01.05APO01.05 Establish roles and responsibilities2
APO01.06APO01.06 Optimize the placement of the IT function1
APO01.07APO01.07 Define information (data) and system ownership1
APO01.08APO01.08 Define target skills and competencies2
APO01.09APO01.09 Define and communicate policies and procedures2
APO01.10APO01.10 Define and implement infrastructure, services and applications to support the governance and management system1
APO01.11APO01.11 Manage continual improvement of the I&T management system1
APO02APO02 Managed Strategy0
APO02.01APO02.01 Understand enterprise context and direction1
APO02.02APO02.02 Assess current capabilities, performance and digital maturity of the enterprise1
APO02.03APO02.03 Define target digital capabilities1
APO02.04APO02.04 Conduct a gap analysis0
APO02.05APO02.05 Define the strategic plan and road map1
APO02.06APO02.06 Communicate the I&T strategy and direction1
APO03APO03 Managed Enterprise Architecture0
APO03.01APO03.01 Develop the enterprise architecture vision0
APO03.02APO03.02 Define reference architecture1
APO03.03APO03.03 Select opportunities and solutions0
APO03.04APO03.04 Define architecture implementation0
APO03.05APO03.05 Provide enterprise architecture services0
APO04APO04 Managed Innovation0
APO04.01APO04.01 Create an environment conducive to innovation0
APO04.02APO04.02 Maintain an understanding of the enterprise environment0
APO04.03APO04.03 Monitor and scan the technology environment0
APO04.04APO04.04 Assess the potential of emerging technologies and innovative ideas0
APO04.05APO04.05 Recommend appropriate further initiatives0
APO04.06APO04.06 Monitor the implementation and use of innovation0
APO05APO05 Managed Portfolio0
APO05.01APO05.01 Determine the availability and sources of funds0
APO05.02APO05.02 Evaluate and select programs to fund0
APO05.03APO05.03 Monitor, optimize and report on investment portfolio performance0
APO05.04APO05.04 Maintain portfolios0
APO05.05APO05.05 Manage benefits achievement0
APO06APO06 Managed Budget and Costs0
APO06.01APO06.01 Manage finance and accounting0
APO06.02APO06.02 Prioritize resource allocation0
APO06.03APO06.03 Create and maintain budgets0
APO06.04APO06.04 Model and allocate costs0
APO06.05APO06.05 Manage costs0
APO07APO07 Managed Human Resources0
APO07.01APO07.01 Acquire and maintain adequate and appropriate staffing1
APO07.02APO07.02 Identify key IT personnel1
APO07.03APO07.03 Maintain the skills and competencies of personnel2
APO07.04APO07.04 Assess and recognize/reward employee job performance1
APO07.05APO07.05 Plan and track the usage of IT and business human resources0
APO07.06APO07.06 Manage contract staff1
APO08APO08 Managed Relationships0
APO08.01APO08.01 Understand business expectations1
APO08.02APO08.02 Align I&T strategy with business expectations and identify opportunities for IT to enhance the business1
APO08.03APO08.03 Manage the business relationship0
APO08.04APO08.04 Coordinate and communicate0
APO08.05APO08.05 Provide input to the continual improvement of services1
APO09APO09 Managed Service Agreements0
APO09.01APO09.01 Identify I&T services1
APO09.02APO09.02 Catalog I&T-enabled services0
APO09.03APO09.03 Define and prepare service agreements1
APO09.04APO09.04 Monitor and report service levels1
APO09.05APO09.05 Review service agreements and contracts1
APO10APO10 Managed Vendors0
APO10.01APO10.01 Identify and evaluate vendor relationships and contracts2
APO10.02APO10.02 Select vendors1
APO10.03APO10.03 Manage vendor relationships and contracts2
APO10.04APO10.04 Manage vendor risk. a1
APO10.05APO10.05 Monitor vendor performance and compliance2
APO11APO11 Managed Quality0
APO11.01APO11.01 Establish a quality management system (QMS)1
APO11.02APO11.02 Focus quality management on customers1
APO11.03APO11.03 Manage quality standards, practices and procedures and integrate quality management into key processes and solutions1
APO11.04APO11.04 Perform quality monitoring, control and reviews1
APO11.05APO11.05 Maintain continuous improvement1
APO12APO12 Managed Risk0
APO12.01APO12.01 Collect data1
APO12.02APO12.02 Analyze risk. a Develop a substantiated view on actual I&T risk, in support of risk decisions2
APO12.03APO12.03 Maintain a risk profile2
APO12.04APO12.04 Articulate risk2
APO12.05APO12.05 Define a risk management action portfolio1
APO12.06APO12.06 Respond to risk1
APO13APO13 Managed Security0
APO13.01APO13.01 Establish and maintain an information security management system (ISMS)1
APO13.02APO13.02 Define and manage an information security and privacy risk treatment plan1
APO13.03APO13.03 Monitor and review the information security management system (ISMS)1
APO14APO14 Managed Data0
APO14.01APO14.01 Define and communicate the organization’s data management strategy and roles and responsibilities1
APO14.02APO14.02 Define and maintain a consistent business glossary0
APO14.03APO14.03 Establish the processes and infrastructure for metadata management0
APO14.04APO14.04 Define a data quality strategy1
APO14.05APO14.05 Establish data profiling methodologies, processes and tools0
APO14.06APO14.06 Ensure a data quality assessment approach0
APO14.07APO14.07 Define the data cleansing approach0
APO14.08APO14.08 Manage the life cycle of data assets1
APO14.09APO14.09 Support data archiving and retention1
APO14.10APO14.10 Manage data backup and restore arrangements1
BAI01BAI01 Managed Programs0
BAI01.01BAI01.01 Maintain a standard approach for program management1
BAI01.02BAI01.02 Initiate a program0
BAI01.03BAI01.03 Manage stakeholder engagement0
BAI01.04BAI01.04 Develop and maintain the program plan0
BAI01.05BAI01.05 Launch and execute the program0
BAI01.06BAI01.06 Monitor, control and report on the program outcomes0
BAI01.07BAI01.07 Manage program quality0
BAI01.08BAI01.08 Manage program risk0
BAI01.09BAI01.09 Close a program0
BAI02BAI02 Managed Requirements Definition0
BAI02.01BAI02.01 Define and maintain business functional and technical requirements2
BAI02.02BAI02.02 Perform a feasibility study and formulate alternative solutions0
BAI02.03BAI02.03 Manage requirements risk1
BAI02.04BAI02.04 Obtain approval of requirements and solutions1
BAI03BAI03 Managed Solutions Identification and Build0
BAI03.01BAI03.01 Design high-level solutions2
BAI03.02BAI03.02 Design detailed solution components2
BAI03.03BAI03.03 Develop solution components1
BAI03.04BAI03.04 Procure solution components1
BAI03.05BAI03.05 Build solutions1
BAI03.06BAI03.06 Perform quality assurance (QA)1
BAI03.07BAI03.07 Prepare for solution testing1
BAI03.08BAI03.08 Execute solution testing2
BAI03.09BAI03.09 Manage changes to requirements1
BAI03.10BAI03.10 Maintain solutions1
BAI03.11BAI03.11 Define IT products and services and maintain the service portfolio0
BAI03.12BAI03.12 Design solutions based on the defined development methodology1
BAI04BAI04 Managed Availability and Capacity0
BAI04.01BAI04.01 Assess current availability, performance and capacity and a1
BAI04.02BAI04.02 Assess business impact1
BAI04.03BAI04.03 Plan for new or changed service requirements1
BAI04.04BAI04.04 Monitor and review availability and capacity1
BAI04.05BAI04.05 Investigate and address availability, performance and capacity issues1
BAI05BAI05 Managed Organizational Change0
BAI05.01BAI05.01 Establish the desire to change0
BAI05.02BAI05.02 Form an effective implementation team0
BAI05.03BAI05.03 Communicate desired vision0
BAI05.04BAI05.04 Empower role players and identify short-term wins0
BAI05.05BAI05.05 Enable operation and use0
BAI05.06BAI05.06 Embed new approaches0
BAI05.07BAI05.07 Sustain changes0
BAI06BAI06 Managed IT Changes0
BAI06.01BAI06.01 Evaluate, prioritize and authorize change requests3
BAI06.02BAI06.02 Manage emergency changes1
BAI06.03BAI06.03 Track and report change status1
BAI06.04BAI06.04 Close and document the changes2
BAI07BAI07 Managed IT Change Acceptance and Transitioning0
BAI07.01BAI07.01 Establish an implementation plan1
BAI07.02BAI07.02 Plan business process, system and data conversion0
BAI07.03BAI07.03 Plan acceptance tests1
BAI07.04BAI07.04 Establish a test environment1
BAI07.05BAI07.05 Perform acceptance tests1
BAI07.06BAI07.06 Promote to production and manage releases2
BAI07.07BAI07.07 Provide early production support0
BAI07.08BAI07.08 Perform a post-implementation review0
BAI08BAI08 Managed Knowledge0
BAI08.01BAI08.01 Identify and classify sources of information for governance and management of I&T0
BAI08.02BAI08.02 Organize and contextualize information into knowledge0
BAI08.03BAI08.03 Use and share knowledge0
BAI08.04BAI08.04 Evaluate and update or retire information0
BAI09BAI09 Managed Assets0
BAI09.01BAI09.01 Identify and record current assets1
BAI09.02BAI09.02 Manage critical assets2
BAI09.03BAI09.03 Manage the asset life cycle1
BAI09.04BAI09.04 Optimize asset value0
BAI09.05BAI09.05 Manage licenses1
BAI10BAI10 Managed Configuration0
BAI10.01BAI10.01 Establish and maintain a configuration model1
BAI10.02BAI10.02 Establish and maintain a configuration repository and baseline1
BAI10.03BAI10.03 Maintain and control configuration items1
BAI10.04BAI10.04 Produce status and configuration reports0
BAI10.05BAI10.05 Verify and review integrity of the configuration repository1
BAI11BAI11 Managed Projects0
BAI11.01BAI11.01 Maintain a standard approach for project management1
BAI11.02BAI11.02 Start up and initiate a project0
BAI11.03BAI11.03 Manage stakeholder engagement0
BAI11.04BAI11.04 Develop and maintain the project plan0
BAI11.05BAI11.05 Manage project quality1
BAI11.06BAI11.06 Manage project risk1
BAI11.07BAI11.07 Monitor and control projects0
BAI11.08BAI11.08 Manage project resources and work packages0
BAI11.09BAI11.09 Close a project or iteration0
DESIGN-FACTORSDesign factors, focus areas and capability levels0
DSS01DSS01 Managed Operations0
DSS01.01DSS01.01 Perform operational procedures1
DSS01.02DSS01.02 Manage outsourced I&T services1
DSS01.03DSS01.03 Monitor I&T infrastructure1
DSS01.04DSS01.04 Manage the environment1
DSS01.05DSS01.05 Manage facilities1
DSS02DSS02 Managed Service Requests and Incidents0
DSS02.01DSS02.01 Define classification schemes for incidents and service requests1
DSS02.02DSS02.02 Record, classify and prioritize requests and incidents1
DSS02.03DSS02.03 Verify, approve and fulfill service requests0
DSS02.04DSS02.04 Investigate, diagnose and allocate incidents1
DSS02.05DSS02.05 Resolve and recover from incidents1
DSS02.06DSS02.06 Close service requests and incidents1
DSS02.07DSS02.07 Track status and produce reports1
DSS03DSS03 Managed Problems0
DSS03.01DSS03.01 Identify and classify problems1
DSS03.02DSS03.02 Investigate and diagnose problems2
DSS03.03DSS03.03 Raise known errors0
DSS03.04DSS03.04 Resolve and close problems2
DSS03.05DSS03.05 Perform proactive problem management1
DSS04DSS04 Managed Continuity0
DSS04.01DSS04.01 Define the business continuity policy, objectives and scope1
DSS04.02DSS04.02 Maintain business resilience1
DSS04.03DSS04.03 Develop and implement a business continuity response2
DSS04.04DSS04.04 Exercise, test and review the business continuity plan (BCP) and disaster response plan (DRP)2
DSS04.05DSS04.05 Review, maintain and improve the continuity plans1
DSS04.06DSS04.06 Conduct continuity plan training1
DSS04.07DSS04.07 Manage backup arrangements2
DSS04.08DSS04.08 Conduct post-resumption review1
DSS05DSS05 Managed Security Services0
DSS05.01DSS05.01 Protect against malicious software1
DSS05.02DSS05.02 Manage network and connectivity security1
DSS05.03DSS05.03 Manage endpoint security1
DSS05.04DSS05.04 Manage user identity and logical access2
DSS05.05DSS05.05 Manage physical access to I&T assets1
DSS05.06DSS05.06 Manage sensitive documents and output devices1
DSS05.07DSS05.07 Manage vulnerabilities and monitor the infrastructure for security-related events1
DSS06DSS06 Managed Business Process Controls0
DSS06.01DSS06.01 Align control activities embedded in business processes with a. Percen enterprise objectives1
DSS06.02DSS06.02 Control the processing of information1
DSS06.03DSS06.03 Manage roles, responsibilities, access privileges and levels of authority2
DSS06.04DSS06.04 Manage errors and exceptions1
DSS06.05DSS06.05 Ensure traceability and accountability for information events. a. Num Ensure that business information can be traced to an originating b1
DSS06.06DSS06.06 Secure information assets1
EDM01EDM01 Ensured Governance Framework Setting and Maintenance0
EDM01.01EDM01.01 Evaluate the governance system1
EDM01.02EDM01.02 Direct the governance system1
EDM01.03EDM01.03 Monitor the governance system2
EDM02EDM02 Ensured Benefits Delivery0
EDM02.01EDM02.01 Establish the target investment mix1
EDM02.02EDM02.02 Evaluate value optimization1
EDM02.03EDM02.03 Direct value optimization1
EDM02.04EDM02.04 Monitor value optimization1
EDM03EDM03 Ensured Risk Optimization0
EDM03.01EDM03.01 Evaluate risk management2
EDM03.02EDM03.02 Direct risk management2
EDM03.03EDM03.03 Monitor risk management1
EDM04EDM04 Ensured Resource Optimization0
EDM04.01EDM04.01 Evaluate resource management1
EDM04.02EDM04.02 Direct resource management1
EDM04.03EDM04.03 Monitor resource management1
EDM05EDM05 Ensured Stakeholder Engagement0
EDM05.01EDM05.01 Evaluate stakeholder engagement and reporting requirements1
EDM05.02EDM05.02 Direct stakeholder engagement, communication and reporting2
EDM05.03EDM05.03 Monitor stakeholder engagement1
FRAMEWORKCOBIT 2019: the framework, its publications and what is held0
MEA01MEA01 Managed Performance and Conformance Monitoring0
MEA01.01MEA01.01 Establish a monitoring approach2
MEA01.02MEA01.02 Set performance and conformance targets2
MEA01.03MEA01.03 Collect and process performance and conformance data1
MEA01.04MEA01.04 Analyze and report performance2
MEA01.05MEA01.05 Ensure the implementation of corrective actions2
MEA02MEA02 Managed System of Internal Control0
MEA02.01MEA02.01 Monitor internal controls2
MEA02.02MEA02.02 Review effectiveness of business process controls1
MEA02.03MEA02.03 Perform control self-assessments1
MEA02.04MEA02.04 Identify and report control deficiencies2
MEA03MEA03 Managed Compliance With External Requirements0
MEA03.01MEA03.01 Identify external compliance requirements2
MEA03.02MEA03.02 Optimize response to external requirements1
MEA03.03MEA03.03 Confirm external compliance1
MEA03.04MEA03.04 Obtain assurance of external compliance1
MEA04MEA04 Managed Assurance0
MEA04.01MEA04.01 Ensure that assurance providers are independent and qualified2
MEA04.02MEA04.02 Develop risk-based planning of assurance initiatives2
MEA04.03MEA04.03 Determine the objectives of the assurance initiative1
MEA04.04MEA04.04 Define the scope of the assurance initiative2
MEA04.05MEA04.05 Define the work program for the assurance initiative1
MEA04.06MEA04.06 Execute the assurance initiative, focusing on design effectiveness2
MEA04.07MEA04.07 Execute the assurance initiative, focusing on operating effectiveness2
MEA04.08MEA04.08 Report and follow up on the assurance initiative2
MEA04.09MEA04.09 Follow up on recommendations and actions1
PRINCIPLESThe six principles of a governance system and the three principles of a governance framework0

Tell me when COBIT 2019 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • ISMS scope statement
  • Statement of applicability
  • ISMS policy
  • Management review minutes
  • Design documents
  • Build standards
  • Annual review records
  • Approval record
  • KB articles
  • Documentation standards

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for COBIT 2019, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition