2019
• Enterprise str ategy
• Enterprise goals
• Enterprise siz e
• Role of IT
• Sourcing model for IT
• Compliance requirements
• Etc.
• SME
• Security
• Risk
• DevOps
• Etc.
Priority governance
and management
objectives
Specific guidance
from focus areas
Target capability
and performance
management
guidance
Design Factors
COBIT 5
Inputs to COBIT 2019COBIT 2019
Community
Contribution
Standards,
Frameworks,
Regulation s
COBIT Core
Publications
Focus Area
Tailored Enterprise
Governance
System for
Information and
Technology
COBIT Core
Reference Model of Governance
and Management Objectives
COBIT
®
2019 Framework:
Introduction and Methodology
COBIT
®
2019 Framework:
Governance and
Management Objectives
COBIT
®
2019 Design Guide:
Designing an Information and Technology
Governance Solution
COBIT
®
2019 Implementation Guide:
Implementing and Optimizing an
Information and Technology
Governance Solution
EDM01—Ensured
Governance
Framew ork Setting
and Maintenance
APO01—Managed
I&T Management
Framew ork
APO08—Managed
Relationships
APO02—Managed
Strategy
APO09—Managed
Service
Agreements
APO03—Managed
Enterprise
Architecture
APO10—Managed
Vendors
APO04—Managed
Innovation
APO11—Managed
Quality
APO05—Managed
Portfolio
APO12 —Managed
Risk
APO06—Managed
Budget and Costs
APO07—Managed
Human Resources
APO014—Managed
Data
MEA0 1—Managed
Performance an d
Conf ormance
Monitoring
MEA02—Managed
System of Internal
Control
MEA03—Managed
Compliance with
External
Requirements MEA04— Managed
Assurance
APO13—Managed
Security
DSS01 —Managed
Operations
DSS02 —Managed
Service Requests
and Incidents
DSS03 —Managed
Problems
DSS04 —Managed
Continuity
DSS05 —Managed
Security
Services
DSS06 —Managed
Business
Process ControlsBAI01—Managed
Programs
BAI08—Managed
Knowledge
BAI0 2—Managed
Requirements
Definition
BAI0 9—Managed
Assets
BAI03—Manage
Solut ions
Identification
and Build
BAI10—Managed
Configuration
BAI04—Managed
Availability
and Capacity
BAI11—Managed
Projects
BAI05—Managed
Organizational
Change
BAI06—Managed
IT Changes
BAI07—Managed
IT Change
Acceptance an d
Transitioning
EDM02—Ensured
Benefits Deli very
EDM03—Ensured
Risk Optimization
EDM04—Ensured
Resource
Optimization
EDM05—Ensured
Stakeholder
Engagement
This excerpt is available as a complimentary PDF at
www.isaca.org/COBIT and for purchase in hard copy
at www.isaca.org/bookstore. We encourage you to
share this document with your enterprise leaders,
team members, clients and/or consultants. Additional
information is available at isaca.org/COBIT.
1. Understand
the enterprise
context and
strategy.
2. Determine
the initial
scope of the
governance
system.
3. Refine the
scope of the
governance
system.
4. Conclude the
governance
system design.
• 1.1 Understand enterprise
strategy.
• 1.2 Understand enterprise
goals .
• 1.3 Understand the risk
profile.
• 1.4 Understand current
I&T-related issues.
• 2.1 Consider enterprise
strategy.
• 2.2 Consider enterprise
goals and apply the
COBIT goals cascade.
• 2.3 Consider the risk profile
of the enterprise.
• 2.4 Consider current
I&T-related issues.
• 3.1 Consider the threat
landscape.
• 3.2 Consider compliance
requirements.
• 3.3 Consider the role of IT.
• 3.4 Consider the sourcing
model.
• 3.5 Consider IT
implementation methods.
• 3.6 Consider the IT adoption
strategy.
• 3.7 Consider enterprise size.
• 4.1 Resolve inherent priority
conflicts.
• 4.2 Conclude the
governance system
design.
the m
om
entum going?
7
How do we keep
6
D
id
w
e
g
e
t th
e
re
?
5
H
o
w
d
o
w
e
g
e
t
t
h
e
r
e
?
4 What needs to be done?
3
W
h e r e d
o
w
e
w
a
n
t to
b
e
?
2
W
h
e
r
e
a
r
e
w
e
n
o
w
?
1 W
hat a
re
t
h
e
d
r
i
v
e
r
s
?
• Program management
(outer ring)
• Change enablement
(middle ring)
• Continual impr
ovement life cycle
(inner ring)
Initia
te
p
r
o
g
r
a
m
D
e
f
i
n
e
p
r
o
b
l
e
m
s
a
n
d
o
p
p
o
r
t
u
n
i
t
i
e
s
D
e f i n
e
ro
a
d
m
a
p
Plan program
E
x
e
c
u
t
e
p
l
a
n
R
e
a
liz
e
b
e
n
e
fits
Review
effectiveness
O
p
e
r
a
t
e
Identify role
C o m
m
u
n
ic
a
te
t
e
a
m
to c
h
a
n
g
e
a
n
d
u
s
e
players
o u
t c
o
m
e
F
o
r
m
i
m
p
l
e
m
e
n
t
a
t
io
n
Estab
lis
h
d
e
s
i
r
e
E
m
b
e
d
n
e
w
Sustain
a
p
p
r
o
a
c
h
e
s
I
m
p
l
e
m
e
n
t
im
provements
s ta
te
A
s
s
e
s
s
Reco
g
n
i
z
eM
onitor
O
p
e
ra
te
i
m
p
r
o
v
e
m
e
n
t
s Build
t a
rg
e
t
c
u
r
r
e
n
t
nee
d