COBIT objectives: A guide to the 40 COBIT 2019 governance and management objectives
COBIT 2019 organizes its core model around 40 governance and management objectives. These objectives provide a structured way to address different areas of enterprise information and technology (I&T), from risk and security to strategy, operations, continuity, and assurance.
The COBIT objectives fall within five domains: EDM, APO, BAI, DSS, and MEA. EDM contains the governance objectives, while APO, BAI, DSS, and MEA contain the management objectives. Each objective relates to a specific process and the other components needed to achieve it.
You do not need to implement all 40 objectives with the same priority. The COBIT framework is designed to help organizations select and prioritize objectives based on their enterprise goals, alignment goals, risks, and other factors.
- How the 40 COBIT objectives are organized
- EDM: Evaluate, direct and monitor
- APO: Align, plan and organize
- BAI: Build, acquire and implement
- DSS: Deliver, service and support
- MEA: Monitor, evaluate and assess
- Do you need all 40 COBIT objectives?
- How to use these objectives in practice
- Turn COBIT objectives into tracked, auditable controls with CyberArrow
- FAQs
How the 40 COBIT objectives are organized
The COBIT Core Model groups the 40 objectives into five domains:

The split between governance and management is important. EDM contains the five governance objectives, while the other four domains contain the 35 management objectives.
Now let’s explore these COBIT objectives in detail.
EDM: Evaluate, direct and monitor
The EDM domain covers the responsibilities of the governing body. It focuses on evaluating strategic options, directing management, and monitoring the organization’s progress toward its objectives.
| Code | Objective | Focus |
| EDM01 | Ensured governance framework setting and maintenance | Establishes and maintains the overall governance system for the enterprise |
| EDM02 | Ensured benefits delivery | Confirms that IT investments and services deliver expected value to the business |
| EDM03 | Ensured risk optimization | Ensures IT-related risk stays within the enterprise’s risk appetite and tolerance |
| EDM04 | Ensured resource optimization | Ensures resource needs are met, and IT costs are optimized |
| EDM05 | Ensured stakeholder engagement | Ensures stakeholders are engaged, informed, and supportive of the IT strategy |
APO: Align, plan and organize
APO contains the largest group of COBIT 2019 management objectives. It covers the organization’s I&T strategy, structure, resources, relationships, risk, security, vendors, and data.
| Code | Objective | Focus |
| APO01 | Managed I&T management framework | Establishing and maintaining the management framework for enterprise I&T |
| APO02 | Managed strategy | Developing and maintaining an I&T strategy aligned with enterprise direction |
| APO03 | Managed enterprise architecture | Maintaining an architecture that supports the organization’s current and future needs |
| APO04 | Managed innovation | Identifying, evaluating, and implementing opportunities for I&T-enabled innovation |
| APO05 | Managed portfolio | Managing the portfolio of I&T-enabled investments, services, and programs |
| APO06 | Managed budget and costs | Planning, allocating, and monitoring I&T budgets and costs |
| APO07 | Managed human resources | Managing I&T personnel, skills, competencies, and workforce needs |
| APO08 | Managed relationships | Managing relationships between I&T and business stakeholders |
| APO09 | Managed service agreements | Managing agreements that define expected I&T services and performance |
| APO10 | Managed vendors | Managing relationships and performance involving I&T vendors |
| APO11 | Managed quality | Establishing and maintaining quality management across I&T activities |
| APO12 | Managed risk | Identifying, analyzing, and managing I&T-related risk |
| APO13 | Managed security | Establishing and maintaining information and technology security |
| APO14 | Managed data | Managing enterprise data throughout its lifecycle |
APO14 is particularly notable because Managed data was introduced as a new management objective in COBIT 2019.
Quick link: How to survive a surprise audit
BAI: Build, acquire and implement
BAI covers the work involved in turning business and I&T requirements into solutions and putting those solutions into operation. It includes programs, projects, requirements, changes, assets, configuration, knowledge, and organizational change.
| Code | Objective | Focus |
| BAI01 | Managed programs | Managing groups of related projects and coordinating their delivery |
| BAI02 | Managed requirements definition | Defining and maintaining business and I&T requirements |
| BAI03 | Managed solutions identification and build | Identifying, designing, developing, and acquiring I&T solutions |
| BAI04 | Managed availability and capacity | Managing the availability, capacity, and performance needed to meet business requirements |
| BAI05 | Managed organizational change | Managing the organizational changes required to adopt new I&T solutions and ways of working |
| BAI06 | Managed IT changes | Managing changes to I&T environments in a controlled manner |
| BAI07 | Managed IT change acceptance and transitioning | Testing, accepting, and transitioning new or changed solutions into operation |
| BAI08 | Managed knowledge | Managing knowledge needed to support I&T activities and decision-making |
| BAI09 | Managed assets | Managing I&T assets throughout their lifecycle |
| BAI10 | Managed configuration | Maintaining reliable information about I&T configuration items and their relationships |
| BAI11 | Managed projects | Managing individual I&T projects from initiation through completion |
COBIT 2019 separates program management and project management into BAI01 and BAI11. It also introduced BAI11 as one of the three new management objectives compared with COBIT 5.
DSS: Deliver, service and support
DSS focuses on the operational side of I&T. It covers day-to-day operations, service requests and incidents, problems, continuity, security services, and business process controls.
| Code | Objective | Focus |
| DSS01 | Managed operations | Managing day-to-day I&T operations |
| DSS02 | Managed service requests and incidents | Handling service requests and resolving incidents |
| DSS03 | Managed problems | Identifying and addressing the underlying causes of recurring incidents |
| DSS04 | Managed continuity | Planning and maintaining continuity capabilities for I&T and business operations |
| DSS05 | Managed security services | Managing security services and operational security activities |
| DSS06 | Managed business process controls | Managing controls within business processes that rely on I&T |
For example, an organization concerned about business continuity might prioritize DSS04-managed continuity alongside related objectives such as EDM03-ensured risk optimization and APO12-managed risk. ISACA uses this type of prioritization when demonstrating how enterprise and alignment goals can lead organizations toward specific COBIT objectives.
MEA: Monitor, evaluate and assess
MEA focuses on monitoring performance and conformance, internal controls, external requirements, and assurance.
| Code | Objective | Focus |
| MEA01 | Managed performance and conformance monitoring | Monitoring performance and conformance against defined targets and requirements |
| MEA02 | Managed system of internal control | Monitoring and assessing the effectiveness of the internal control system |
| MEA03 | Managed compliance with external requirements | Monitoring compliance with applicable laws, regulations, contracts, and other external requirements |
| MEA04 | Managed assurance | Planning and managing assurance activities over I&T governance and management |
MEA04 managed assurance was also introduced in COBIT 2019. Along with APO14 and BAI11, it is one of the three new management objectives added compared with COBIT 5.
Do you need all 40 COBIT objectives?
No. COBIT 2019 is not intended to be applied as a checklist where every organization gives equal priority to every objective.
Instead, you can use your enterprise goals and alignment goals to determine which objectives are most relevant. COBIT provides mapping between these goals and the governance and management objectives to support prioritization.
For example, suppose your immediate priority is improving information security and continuity. You might prioritize:
- EDM03 to ensure risk optimization.
- APO12 for managed risk.
- APO13 for managed security.
- BAI10 for managed configuration.
- DSS04 for managed continuity.
- DSS05 for managed security services.
That does not mean you ignore the remaining objectives. It means you start with the objectives that are most closely aligned with your current business priorities and risks.
COBIT’s design approach can then help you determine the appropriate governance system components and target capability levels for the objectives you prioritize.
Quick link: DORA compliance software for financial institutions: Buyer’s guide
How to use these objectives in practice
You do not need to work through all 40 COBIT objectives at once. Start by identifying the business priorities, risks, and I&T issues that matter most to your organization, then select the objectives that address them.
For example, if your priority is strengthening cyber security, you might focus first on APO12 for managed risk, APO13 for managed security, DSS05 for managed security services, and EDM03 for ensuring risk optimization. If continuity is a major concern, DSS04 for managed continuity may become a higher priority.
Once you select the relevant objectives, connect them to the work your organization already performs. Map each objective to responsible teams, existing processes, controls, policies, risks, and performance measures. This helps you identify where your current practices already support a COBIT objective and where gaps remain.
You can then assess the capability of the related processes, set target levels, and prioritize improvements based on business needs. This approach turns the COBIT objectives from a reference list into a practical structure for improving I&T governance and management.
Turn COBIT objectives into tracked, auditable controls with CyberArrow
Knowing the 40 COBIT objectives is one thing. Operationalizing them across a growing organization, with real owners, real evidence, and real audit trails, is a different challenge entirely. Most teams start in spreadsheets and outgrow them quickly, especially once EDM, APO, BAI, DSS, and MEA objectives each require their own owners, controls, and evidence.
CyberArrow GRC helps you close that gap. With CyberArrow, you can:
- Map objectives to controls: Turn COBIT governance and management objectives into trackable controls, assigned to owners, with clear status at any point in time.
- Cross-map across frameworks: Reuse control work across COBIT, ISO 27001, SOC 2, and NIST instead of rebuilding your compliance program for every standard you need to meet.
- Automate evidence collection: Connect your tech stack through 80+ integrations and stop chasing screenshots before every audit.
- Monitor continuously: Track control posture on an ongoing basis instead of scrambling in the weeks before an assessment.
- Move faster: Go live in as little as three weeks, with auditor-approved templates built in.
Whether you’re just starting to scope your COBIT implementation or already managing objectives across multiple domains, CyberArrow gives you one place to see where you stand.
FAQs
Do I need to implement all 40 COBIT objectives?
No. COBIT 2019 allows organizations to prioritize objectives based on factors such as enterprise goals, risks, and business requirements. You can focus first on the objectives most relevant to your organization’s priorities.
How do I choose which COBIT objectives to prioritize?
Start with your business goals, I&T-related risks, regulatory requirements, and current governance needs. You can then use COBIT’s mapping and design guidance to identify the objectives that best support those priorities.
Can COBIT objectives be mapped to other frameworks?
Yes. COBIT can be used alongside frameworks such as ISO 27001, NIST CSF, and ITIL. Mapping related requirements and controls can help reduce duplicate work and give you a more consistent view of governance and compliance.
How are COBIT objectives assessed?
COBIT 2019 uses process capability levels from 0 to 5 to assess the processes associated with governance and management objectives. Organizations can compare their current capability with their target level to identify improvement priorities.