COBIT Framework

COBIT objectives: A guide to the 40 COBIT 2019 governance and management objectives

COBIT 2019 organizes its core model around 40 governance and management objectives. These objectives provide a structured way to address different areas of enterprise information and technology (I&T), from risk and security to strategy, operations, continuity, and assurance.

 

The COBIT objectives fall within five domains: EDM, APO, BAI, DSS, and MEA. EDM contains the governance objectives, while APO, BAI, DSS, and MEA contain the management objectives. Each objective relates to a specific process and the other components needed to achieve it.

 

You do not need to implement all 40 objectives with the same priority. The COBIT framework is designed to help organizations select and prioritize objectives based on their enterprise goals, alignment goals, risks, and other factors.

 

 

How the 40 COBIT objectives are organized

 

The COBIT Core Model groups the 40 objectives into five domains:

 

The split between governance and management is important. EDM contains the five governance objectives, while the other four domains contain the 35 management objectives.

 

Now let’s explore these COBIT objectives in detail. 

 

EDM: Evaluate, direct and monitor

 

The EDM domain covers the responsibilities of the governing body. It focuses on evaluating strategic options, directing management, and monitoring the organization’s progress toward its objectives.

 

Code  Objective  Focus 
EDM01   Ensured governance framework setting and maintenance Establishes and maintains the overall governance system for the enterprise
EDM02   Ensured benefits delivery Confirms that IT investments and services deliver expected value to the business
EDM03   Ensured risk optimization Ensures IT-related risk stays within the enterprise’s risk appetite and tolerance
EDM04   Ensured resource optimization Ensures resource needs are met, and IT costs are optimized
EDM05   Ensured stakeholder engagement Ensures stakeholders are engaged, informed, and supportive of the IT strategy

 

APO: Align, plan and organize

 

APO contains the largest group of COBIT 2019 management objectives. It covers the organization’s I&T strategy, structure, resources, relationships, risk, security, vendors, and data.

 

Code  Objective  Focus 
APO01 Managed I&T management framework Establishing and maintaining the management framework for enterprise I&T
APO02 Managed strategy Developing and maintaining an I&T strategy aligned with enterprise direction
APO03 Managed enterprise architecture Maintaining an architecture that supports the organization’s current and future needs
APO04 Managed innovation Identifying, evaluating, and implementing opportunities for I&T-enabled innovation
APO05 Managed portfolio Managing the portfolio of I&T-enabled investments, services, and programs
APO06 Managed budget and costs Planning, allocating, and monitoring I&T budgets and costs
APO07 Managed human resources Managing I&T personnel, skills, competencies, and workforce needs
APO08 Managed relationships Managing relationships between I&T and business stakeholders
APO09 Managed service agreements Managing agreements that define expected I&T services and performance
APO10 Managed vendors  Managing relationships and performance involving I&T vendors
APO11 Managed quality  Establishing and maintaining quality management across I&T activities
APO12 Managed risk  Identifying, analyzing, and managing I&T-related risk
APO13 Managed security  Establishing and maintaining information and technology security
APO14 Managed data  Managing enterprise data throughout its lifecycle

 

APO14 is particularly notable because Managed data was introduced as a new management objective in COBIT 2019.

 

Quick link: How to survive a surprise audit

 

BAI: Build, acquire and implement

 

BAI covers the work involved in turning business and I&T requirements into solutions and putting those solutions into operation. It includes programs, projects, requirements, changes, assets, configuration, knowledge, and organizational change.

 

Code  Objective  Focus 
BAI01 Managed programs Managing groups of related projects and coordinating their delivery
BAI02 Managed requirements definition Defining and maintaining business and I&T requirements
BAI03 Managed solutions identification and build Identifying, designing, developing, and acquiring I&T solutions
BAI04 Managed availability and capacity Managing the availability, capacity, and performance needed to meet business requirements
BAI05 Managed organizational change Managing the organizational changes required to adopt new I&T solutions and ways of working
BAI06 Managed IT changes Managing changes to I&T environments in a controlled manner
BAI07 Managed IT change acceptance and transitioning Testing, accepting, and transitioning new or changed solutions into operation
BAI08 Managed knowledge Managing knowledge needed to support I&T activities and decision-making
BAI09 Managed assets Managing I&T assets throughout their lifecycle
BAI10 Managed configuration Maintaining reliable information about I&T configuration items and their relationships
BAI11 Managed projects Managing individual I&T projects from initiation through completion

 

COBIT 2019 separates program management and project management into BAI01 and BAI11. It also introduced BAI11 as one of the three new management objectives compared with COBIT 5.

 


 

DSS: Deliver, service and support

 

DSS focuses on the operational side of I&T. It covers day-to-day operations, service requests and incidents, problems, continuity, security services, and business process controls.

 

Code  Objective Focus 
DSS01 Managed operations  Managing day-to-day I&T operations
DSS02 Managed service requests and incidents Handling service requests and resolving incidents
DSS03 Managed problems Identifying and addressing the underlying causes of recurring incidents
DSS04 Managed continuity  Planning and maintaining continuity capabilities for I&T and business operations
DSS05 Managed security services  Managing security services and operational security activities
DSS06 Managed business process controls Managing controls within business processes that rely on I&T

 

For example, an organization concerned about business continuity might prioritize DSS04-managed continuity alongside related objectives such as EDM03-ensured risk optimization and APO12-managed risk. ISACA uses this type of prioritization when demonstrating how enterprise and alignment goals can lead organizations toward specific COBIT objectives.

 

MEA: Monitor, evaluate and assess

 

MEA focuses on monitoring performance and conformance, internal controls, external requirements, and assurance.

 

Code  Objective  Focus 
MEA01 Managed performance and conformance monitoring Monitoring performance and conformance against defined targets and requirements
MEA02 Managed system of internal control Monitoring and assessing the effectiveness of the internal control system
MEA03 Managed compliance with external requirements Monitoring compliance with applicable laws, regulations, contracts, and other external requirements
MEA04 Managed assurance Planning and managing assurance activities over I&T governance and management

 

MEA04 managed assurance was also introduced in COBIT 2019. Along with APO14 and BAI11, it is one of the three new management objectives added compared with COBIT 5.

 

Do you need all 40 COBIT objectives?

 

No. COBIT 2019 is not intended to be applied as a checklist where every organization gives equal priority to every objective.

 

Instead, you can use your enterprise goals and alignment goals to determine which objectives are most relevant. COBIT provides mapping between these goals and the governance and management objectives to support prioritization.

 

For example, suppose your immediate priority is improving information security and continuity. You might prioritize:

 

  • EDM03 to ensure risk optimization.
  • APO12 for managed risk.
  • APO13 for managed security.
  • BAI10 for managed configuration.
  • DSS04 for managed continuity.
  • DSS05 for managed security services.

 

That does not mean you ignore the remaining objectives. It means you start with the objectives that are most closely aligned with your current business priorities and risks.

 

COBIT’s design approach can then help you determine the appropriate governance system components and target capability levels for the objectives you prioritize.

 

Quick link: DORA compliance software for financial institutions: Buyer’s guide

 

How to use these objectives in practice

 

You do not need to work through all 40 COBIT objectives at once. Start by identifying the business priorities, risks, and I&T issues that matter most to your organization, then select the objectives that address them.

 

For example, if your priority is strengthening cyber security, you might focus first on APO12 for managed risk, APO13 for managed security, DSS05 for managed security services, and EDM03 for ensuring risk optimization. If continuity is a major concern, DSS04 for managed continuity may become a higher priority.

 

Once you select the relevant objectives, connect them to the work your organization already performs. Map each objective to responsible teams, existing processes, controls, policies, risks, and performance measures. This helps you identify where your current practices already support a COBIT objective and where gaps remain.

 

You can then assess the capability of the related processes, set target levels, and prioritize improvements based on business needs. This approach turns the COBIT objectives from a reference list into a practical structure for improving I&T governance and management.

 

Turn COBIT objectives into tracked, auditable controls with CyberArrow

 

Knowing the 40 COBIT objectives is one thing. Operationalizing them across a growing organization, with real owners, real evidence, and real audit trails, is a different challenge entirely. Most teams start in spreadsheets and outgrow them quickly, especially once EDM, APO, BAI, DSS, and MEA objectives each require their own owners, controls, and evidence.

 

CyberArrow GRC helps you close that gap. With CyberArrow, you can:

 

  • Map objectives to controls: Turn COBIT governance and management objectives into trackable controls, assigned to owners, with clear status at any point in time.

 

  • Cross-map across frameworks: Reuse control work across COBIT, ISO 27001, SOC 2, and NIST instead of rebuilding your compliance program for every standard you need to meet.

 

  • Automate evidence collection: Connect your tech stack through 80+ integrations and stop chasing screenshots before every audit.

 

  • Monitor continuously: Track control posture on an ongoing basis instead of scrambling in the weeks before an assessment.

 

  • Move faster: Go live in as little as three weeks, with auditor-approved templates built in.

 

Whether you’re just starting to scope your COBIT implementation or already managing objectives across multiple domains, CyberArrow gives you one place to see where you stand.

 

Book your free demo today!

 


 

FAQs

 

Do I need to implement all 40 COBIT objectives?

No. COBIT 2019 allows organizations to prioritize objectives based on factors such as enterprise goals, risks, and business requirements. You can focus first on the objectives most relevant to your organization’s priorities.

 

How do I choose which COBIT objectives to prioritize?

Start with your business goals, I&T-related risks, regulatory requirements, and current governance needs. You can then use COBIT’s mapping and design guidance to identify the objectives that best support those priorities.

 

Can COBIT objectives be mapped to other frameworks?

Yes. COBIT can be used alongside frameworks such as ISO 27001, NIST CSF, and ITIL. Mapping related requirements and controls can help reduce duplicate work and give you a more consistent view of governance and compliance.

 

How are COBIT objectives assessed?

COBIT 2019 uses process capability levels from 0 to 5 to assess the processes associated with governance and management objectives. Organizations can compare their current capability with their target level to identify improvement priorities.

Avatar photo
CyberArrow team