# Control Objectives for Information Technologies

Framework id: `cobit_2019`. Governance. Publisher: ISACA. Version: 2019. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.isaca.org/resources/cobit

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (40, average coverage 49%)
- APO01 Managed I&T Management Framework: PM-01, PM-02, PM-03, PL-01, PL-09 (45%)
- APO02 Managed Strategy: PM-01, PM-07, PM-08, PM-11 (35%)
- APO03 Managed Enterprise Architecture: PM-07, PL-08, SA-08, SA-17 (50%)
- APO04 Managed Innovation: PM-01, SA-08 (15%)
- APO05 Managed Portfolio: PM-07, PM-11 (20%)
- APO06 Managed Budget and Costs: PM-03 (25%)
- APO07 Managed Human Resources: PM-13, PS-01, PS-02, PS-03, PS-06, PS-09, AT-01, AT-02, AT-03, AT-06 (60%)
- APO08 Managed Relationships: PM-15, SA-09 (25%)
- APO09 Managed Service Level Agreements: SA-04, SA-09, CA-03 (35%)
- APO10 Managed Vendors: SA-04, SA-09, SR-01, SR-02, SR-03, SR-05, SR-06 (60%)
- APO11 Managed Quality: SA-11, SA-15, CM-04, CA-02 (35%)
- APO12 Managed Risk: RA-01, RA-02, RA-03, RA-05, RA-07, RA-08, RA-09, PM-09, PM-28, CA-05 (85%)
- APO13 Managed Security: PM-01, PM-02, PM-03, PM-06, PM-09, PL-01, PL-02, PL-09, PL-10, PL-11, RA-01, RA-03, CA-02, CA-07, AT-02 (92%)
- APO14 Managed Data: AC-04, MP-01, MP-02, MP-03, MP-04, MP-05, MP-06, MP-07, SC-28, SI-12, RA-02, PT-01, PT-02, PT-03, PT-04, PT-05, PT-06, PT-07, PT-08, CM-12, CM-13, SI-18 (55%)
- BAI01 Managed Programs and Projects: SA-03, PM-07, PM-11 (30%)
- BAI02 Managed Requirements Definition: SA-04, SA-08, PL-02, PL-07, PL-08 (45%)
- BAI03 Managed Solutions Identification and Build: SA-03, SA-04, SA-08, SA-10, SA-11, SA-15, SA-17, SA-20, SA-21 (60%)
- BAI04 Managed Availability and Capacity: CP-02, CP-07, CP-08, SC-05, AU-04, SI-13 (50%)
- BAI05 Managed Organizational Change: CM-03, CM-04, PM-01 (25%)
- BAI06 Managed IT Changes: CM-03, CM-04, CM-05, CM-09, CM-14, SA-10 (72%)
- BAI07 Managed IT Change Acceptance and Transitioning: CM-03, CM-04, SA-11, CA-02 (50%)
- BAI08 Managed Knowledge: AT-02, AT-03, AT-06, PM-13, SA-05 (35%)
- BAI09 Managed Assets: CM-08, CM-12, PM-05, MP-01, MP-02, MP-03, MP-04, MP-05, MP-06, MP-07, SA-22 (58%)
- BAI10 Managed Configuration: CM-01, CM-02, CM-03, CM-04, CM-05, CM-06, CM-07, CM-08, CM-09, CM-10, CM-11, CM-12, CM-13, CM-14 (85%)
- BAI11 Managed IT Projects: SA-03, PM-07, PM-10, PM-11, CA-05 (30%)
- DSS01 Managed Operations: PE-01, PE-02, PE-03, PE-04, PE-05, PE-06, PE-07, PE-08, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-15, PE-16, PE-17, PE-18, PE-21, PE-22, PE-23, MA-01, MA-02, MA-03, MA-04, MA-05, MA-06, MA-07, SI-04, CA-07 (55%)
- DSS02 Managed Service Requests and Incidents: IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09 (62%)
- DSS03 Managed Problems: IR-04, IR-05, SI-02, CA-05 (40%)
- DSS04 Managed Continuity: CP-01, CP-02, CP-03, CP-04, CP-05, CP-06, CP-07, CP-08, CP-09, CP-10, CP-11, CP-12, CP-13 (80%)
- DSS05 Managed Security Services: SC-07, SC-24, SC-44, SC-41, SI-03, SI-04, SI-16, CM-14, AC-01, AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-08, AC-09, AC-10, AC-11, AC-12, AC-13, AC-14, AC-15, AC-16, AC-17, AC-18, AC-19, AC-20, AC-21, AC-22, AC-23, AC-24, AC-25, IA-01, IA-02, IA-03, IA-04, IA-05, IA-06, IA-07, IA-08, IA-09, IA-10, IA-11, IA-12, PE-01, PE-02, PE-03, PE-04, PE-05, PE-06, PE-07, PE-08, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-15, PE-16, PE-17, PE-18 (88%)
- DSS06 Managed Business Process Controls: AC-03, AC-04, AC-05, AC-06, AU-02, AU-03, AU-06, SI-10, SI-15 (48%)
- EDM01 Ensured Governance Framework Setting and Maintenance: PM-01, PM-02, PM-03, PM-09, PL-09, PL-10 (55%)
- EDM02 Ensured Benefits Delivery: PM-01, PM-03, PM-06 (30%)
- EDM03 Ensured Risk Optimization: PM-09, RA-01, RA-03, PM-28, RA-07, RA-09 (75%)
- EDM04 Ensured Resource Optimization: PM-03, PM-13, SA-03 (35%)
- EDM05 Ensured Stakeholder Engagement: PM-01, PM-02 (25%)
- MEA01 Managed Performance and Conformance Monitoring: CA-07, PM-06, AU-06, SI-04 (55%)
- MEA02 Managed System of Internal Control: CA-02, CA-07, PM-06, AU-06 (50%)
- MEA03 Managed Compliance with External Requirements: CA-02, PM-01, PL-04, SA-04 (45%)
- MEA04 Managed Assurance: CA-01, CA-02, CA-07, CA-08, CA-09 (52%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=cobit_2019
- Control-to-clause mappings as JSON: /api/v1/frameworks/cobit_2019?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/cobit-2019.json
- Page for people: /frameworks/cobit-2019/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
