Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » COBIT » COBIT domains

COBIT domains

COBIT 4.1 breaks down IT governance and management into four key domains, each focusing on specific areas of IT processes. 

Evaluate, Direct, and Monitor (EDM): EDM forms the major component of the COBIT 5 model and concerns itself with the optimal accomplishment of IT business integration and governance. This domain includes identifying directions for IT’s strategic growth, evaluating outcomes and achievements, and creating guarantees of activities’ conformity to standards and regulations.  

Align, Plan, and Organize (APO): APO, on the other hand, is more focused on turning corporate strategies into executable IT projects. This can be defined as taking and documenting IT choices to coordinate IT actions with a company’s goals.

Build, Acquire, and Implement (BAI): In the BAI domain, more emphasis is placed on the practical implementation of IT projects, from development to procurement and integration. It has some features associated with risk management, quality assurance, and good project work.  

Deliver, Service, and Support (DSS): DSS stands for the management of information technology solutions in organizations after implementation. This entails service provision for an organization’s needs, management of events or occurrences, and support for the total IT services to guarantee their efficiency.  

Monitor, Evaluate, and Assess (MEA): MEA is central to proving continuity toward improving IT governance. It is an ongoing process of monitoring IT processes, IT performance, and even the outcomes of IT governance and management practices.

Additional reading

The 5 Key Components of a Risk Management Framework

TL,DR: A risk management framework consists of 5 core components forming a continuous cycle: risk identification, risk assessment, risk mitigation, risk monitoring, and risk reporting across the organization Major frameworks include NIST RMF (risk-based approach for federal systems), COBIT (aligns IT goals with business objectives, developed by ISACA), and COSO ERM (integrates risk management with…

GDPR Violations: Major Fines and Key Lessons

TL,DR: Over 247 GDPR fines were issued in two years, with average values surpassing €4.4 million and recent penalties exceeding €1 billion. Meta’s €1.2 billion fine for illegal cross-border data transfers remains the largest on record Key violations include relying on invalidated transfer mechanisms (Meta), failing to honor the right to be forgotten (Google, fined…

Proof or Penalty: How Enforcement Is Reshaping Business Compliance

The digital landscape has gone through wave after wave of change, and compliance has evolved right alongside it. Over the years, what was once a static checklist has turned into a moving target, shaped by new technologies and rising risks. And while proof has always been part of compliance, it’s now more important than ever….

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.