Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » COBIT » COBIT domains

COBIT domains

COBIT 4.1 breaks down IT governance and management into four key domains, each focusing on specific areas of IT processes. 

Evaluate, Direct, and Monitor (EDM): EDM forms the major component of the COBIT 5 model and concerns itself with the optimal accomplishment of IT business integration and governance. This domain includes identifying directions for IT’s strategic growth, evaluating outcomes and achievements, and creating guarantees of activities’ conformity to standards and regulations.  

Align, Plan, and Organize (APO): APO, on the other hand, is more focused on turning corporate strategies into executable IT projects. This can be defined as taking and documenting IT choices to coordinate IT actions with a company’s goals.

Build, Acquire, and Implement (BAI): In the BAI domain, more emphasis is placed on the practical implementation of IT projects, from development to procurement and integration. It has some features associated with risk management, quality assurance, and good project work.  

Deliver, Service, and Support (DSS): DSS stands for the management of information technology solutions in organizations after implementation. This entails service provision for an organization’s needs, management of events or occurrences, and support for the total IT services to guarantee their efficiency.  

Monitor, Evaluate, and Assess (MEA): MEA is central to proving continuity toward improving IT governance. It is an ongoing process of monitoring IT processes, IT performance, and even the outcomes of IT governance and management practices.

Additional reading

Granular Access Control for Security and Governance

Giving every employee full access to all your IT systems, from databases to dev-ops, is convenient, but also a security nightmare. Unfortunately, that’s exactly what happens with broad access controls; privileges are too generous and not tailored to actual needs.  Granular access control gives employees custom access that opens only the specific systems and processes…

Choosing The Best HIPAA Compliance Software in 2026: Compare & Evaluate

TL;DR The right HIPAA compliance software should continuously monitor safeguards, automate evidence collection, and reduce manual audit prep. A solo practice, SaaS startup, and multi-site healthcare group require different levels of automation, monitoring depth, and workflow structure. If you need full GRC and continuous monitoring, choose Sprinto; for guided HIPAA workflows and small practices, go…

Top 10 Incident Management Software in 2026 (Compared by Use Case)

TL;DR Incident management software helps teams detect, escalate, investigate, and resolve operational or security incidents while maintaining visibility and documentation across the incident lifecycle. DevOps-focused tools like PagerDuty, Better Stack, and BigPanda prioritize alerting and noise reduction; IT service platforms like ServiceNow, Freshservice, and Jira Service Management support structured workflows; SecOps tools like Splunk On-Call,…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.