Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » COBIT » COBIT framework

COBIT framework

COBIT is an ISACA framework abbreviated for Control Objectives for Information and Related Technology. It was developed to assist IT managers, auditors, and users in developing IT governance and control. COBIT offers a list of widely accepted measures, indicators, processes, and best practices for IT resources management, considering a particular industry’s specificity.  

COBIT can be aligned with IT management frameworks such as TOGAF, CMMI, and ITIL. However, it differs from other frameworks because it incorporates risk management, security, and information governance.

Now, the key objective of the COBIT framework is to align IT through investments with business objectives and mitigate IT risks. To achieve this, COBIT focuses on several key concepts:

  • Frameworks. Both IT governance frameworks link IT activities with organizational requirements, and good information is utilized in decision-making.
  • Process Descriptions. COBIT has effectively offered precise and result-oriented process definitions that remain general yet malleable to businesses. These descriptions provide a reference for planning and controlling the construction processes.
  • Control Objectives. COBIT suggests that business organizations must have five control objectives to address IT risks.
  • Management Guidelines. COBIT has control objectives for providing tools that allocate responsibilities, provide self-checking, and approve IT activities and performance measures.
  • Maturity Models. With COBIT’s maturity models, an organization can assess the capability of its business processes, monitor the levels of improvement, and even determine the areas that require improvement.

In the latest update for 2019, forecasting the COBIT model adds new concepts and 40 management and governance objectives to improve the effectiveness of governance programs. 

Additional reading

Sprinto vs OneTrust vs MetricStream: Which GRC platform should you choose?

Do you need a heavyweight enterprise GRC suite, or a platform that automates most of the work and still grows with you? That’s the choice hiding inside a Sprinto, OneTrust, and MetricStream shortlist, and it comes down to who’s actually doing the work. If you have separate people owning risk, audit, compliance, and vendor reviews, OneTrust and MetricStream are built for you. If a handful of people cover all of it, those tools may take months to set up, and someone has to keep tuning them, which becomes your real cost. Sprinto covers most of the same ground with far less setup, fewer people, and lower spend. I’ll walk through all three across the eight things that decide these evaluations: core design, onboarding, automation, risk and controls, framework coverage, reporting, AI, and pricing. At the end, I’ll tell you which one I’d shortlist for your situation and why.

HIPAA Violation Examples: Common Breaches, Real Case Studies & How to Avoid Them

TL,DR: HIPAA violations occur when PHI is accessed, shared, or handled outside HIPAA rules. Examples include employee snooping, lost devices, unsecured transmission, social posts, and weak vendors. The article connects each violation type to real cases, penalties, and prevention controls. HIPAA violations continue to surge across the healthcare ecosystem, and the data tells a clear,…

A Detailed Overview Of PCI DSS Compensating Controls

If your business handles, stores, transmits, manages, or processes customers’ payment card information, it must comply with PCI DSS (Payment Card Industry Data Security Standard). This is an information security standard that outlines measures and controls for organizations to protect sensitive card details while processing transactions.  Implementing stringent compliance is not a piece of cake…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.