Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » COBIT » COBIT framework

COBIT framework

COBIT is an ISACA framework abbreviated for Control Objectives for Information and Related Technology. It was developed to assist IT managers, auditors, and users in developing IT governance and control. COBIT offers a list of widely accepted measures, indicators, processes, and best practices for IT resources management, considering a particular industry’s specificity.  

COBIT can be aligned with IT management frameworks such as TOGAF, CMMI, and ITIL. However, it differs from other frameworks because it incorporates risk management, security, and information governance.

Now, the key objective of the COBIT framework is to align IT through investments with business objectives and mitigate IT risks. To achieve this, COBIT focuses on several key concepts:

  • Frameworks. Both IT governance frameworks link IT activities with organizational requirements, and good information is utilized in decision-making.
  • Process Descriptions. COBIT has effectively offered precise and result-oriented process definitions that remain general yet malleable to businesses. These descriptions provide a reference for planning and controlling the construction processes.
  • Control Objectives. COBIT suggests that business organizations must have five control objectives to address IT risks.
  • Management Guidelines. COBIT has control objectives for providing tools that allocate responsibilities, provide self-checking, and approve IT activities and performance measures.
  • Maturity Models. With COBIT’s maturity models, an organization can assess the capability of its business processes, monitor the levels of improvement, and even determine the areas that require improvement.

In the latest update for 2019, forecasting the COBIT model adds new concepts and 40 management and governance objectives to improve the effectiveness of governance programs. 

Additional reading

Understanding Penalties for HIPAA Non-Compliance: A Comprehensive Guide

HIPAA compliance penalties can range from monetary penalties to civil lawsuits to criminal charges. The monetary penalties range from $127 to $250,000 depending on the nature of the HIPAA violation. The HIPAA law enforces penalties on organizations processing PHI when instances of non-compliance are discovered. In this article, we talk about the types of penalties…

Why Continuous Compliance Is Becoming The New Standard

The audit landscape is evolving. Across the industry, audit firms are applying more detailed reviews and placing greater emphasis on how consistently controls operate across the full audit period. It’s a meaningful shift, and one that points toward stronger, more reliable assurance. For organizations, this is a positive development. Stronger audits mean stronger assurance, and…

Types of Access Control: How to Manage Data Access Safely

TL,DR: Access control limits who can view, use, or modify systems and data. Common models include role-based, rule-based, discretionary, mandatory, and attribute-based access control. Strong access control requires least privilege, MFA, reviews, and automated provisioning. In 2023 data breaches cost organizations an average of $4.45 million, highlighting the critical need for implementing robust cybersecurity measures…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.