2.2 I&T Versus the IT Function

Key Takeaways

  • COBIT 2019 expands scope from the IT department to information and technology (I&T) used anywhere the enterprise works toward its goals.
  • Enterprise I&T includes operational technology, digital products, data, shadow IT, and vendor platforms — not only systems the CIO organization owns.
  • Governance covers all technology the enterprise uses to achieve goals; organization-chart ownership does not create an exemption.
  • The classic Foundation trap is answering as if COBIT applies only to the central IT department.
  • End-to-end coverage is the related governance-system principle; this section supplies the vocabulary, and a later Principles section treats it in full.
Last updated: August 2026

Quick Answer: In COBIT 2019, information and technology (I&T) means all technology and information processing the enterprise uses to achieve its goals — not only the systems the information technology (IT) department owns. Operational technology (OT), digital products, data, shadow IT, and vendor platforms are in scope. The exam trap is answering as if COBIT stops at the CIO's organization chart.

From "the IT department" to enterprise I&T

Older IT-governance conversations treated "IT" as a department: the people who run the data center, the service desk, and the project office. That picture is obsolete, and COBIT 2019 says so on purpose.

Information and technology (I&T) is the broader idea. It includes every use of information and every technology the enterprise puts in place to achieve goals, regardless of where that use sits. The chief information officer (CIO) organization is one important home for I&T. It is not the only home.

A useful analogy is finance versus accounting. Accounting is a function with a reporting line. Finance is the enterprise concern that lives in every budget, price, and investment. Marketing versus a sales team is the same pattern. I&T versus the IT function is that pattern applied to technology. The IT function is real and necessary. It is not the boundary of EGIT.

This is not wordplay. If you read every Foundation stem as "what should the IT department do," you will miss items that describe a plant system, a clinician-owned app, a marketing software as a service (SaaS) buy, or a product squad that never opens a ticket. Those uses are I&T. COBIT applies.

Why the distinction matters for governance

The purpose you just learned — value from I&T via benefits, risk, and resources — cannot be achieved if half the estate is invisible. Governance that only watches the IT department is staring at one room while the house is remodeled everywhere else.

  • A plant manager who upgrades a production line is making an I&T decision even if no one from "IT" is in the meeting.
  • A chief marketing officer who signs a multi-year SaaS contract is putting customer data on a vendor platform.
  • A data-science team that trains models in a personal cloud account is creating model, privacy, and continuity risk.
  • A digital-product squad that ships a mobile feature weekly is running technology that is the business, not a back-office utility.

COBIT says the governance system must cover that whole landscape. "We do not own it" is an operating fact. It is not a governance exemption.

Contrast: IT function versus enterprise I&T

LensIT function (too narrow)Enterprise I&T (COBIT 2019)
Who is in scopeStaff who report to the CIOAnyone who uses, builds, buys, or operates information and technology to achieve enterprise goals
What is in scopeCorporate applications, the network, the data center, the service deskThose plus OT, digital products, data estates, shadow IT, and third-party platforms
Who governsAn "IT steering committee" treated as a technical forumBoard and executives as part of corporate governance, with management across the enterprise
Typical blind spot"If it is not in our configuration-management database, it is not our problem"There is no off-books technology from a governance point of view
Success metricTicket times and uptime of CIO-owned systemsValue from all I&T: benefits realization, risk optimization, and resource optimization

Keep the left column as the trap. Keep the right column as the COBIT answer.

Five places I&T lives outside "IT"

1. Operational technology

Operational technology (OT) is hardware and software that monitors or controls physical processes: factory supervisory control and data acquisition (SCADA) systems, hospital infusion pumps and imaging devices, warehouse robots, building-management systems. OT used to be isolated. It is increasingly networked. A ransomware event that stops a packing line or a connected pump is an enterprise I&T event, even if the plant or clinical-engineering team — not the CIO — "owns" the controllers.

Governing only the enterprise resource-planning system while ignoring the line that actually makes the product is the old IT-function mistake with physical consequences.

2. Digital products

Many enterprises now sell technology: a mobile banking app, a patient portal, a telematics device, a marketplace. Those products are designed by product managers and engineers who may sit far from traditional IT operations. They still process information, create risk, and consume scarce talent. COBIT does not wait for the product to be "handed over to IT" before governance applies. If the product is how the enterprise achieves goals, the product is I&T.

3. Data

Data is not a side effect of applications. Pricing models, credit decisions, clinical quality measures, and fraud scores are the business. Data created by a line team, stored in a vendor lake, or shared with a partner is enterprise I&T. Governing "the warehouse the CIO runs" while ignoring the spreadsheets and vendor extracts that actually drive decisions leaves the real information estate outside EGIT.

4. Shadow IT

Shadow IT is technology bought or built outside official IT processes — a marketing automation suite on a corporate card, a department collaboration tool, a "temporary" cloud tenant that became permanent. Shadow IT is often a symptom of slow official services, not of malice. COBIT does not say "shadow IT does not exist." It says the governance system still has to deal with the benefits, risk, and resources those tools represent. "We never approved it" is not a governance answer. Unregistered technology can still leak data, create value, and burn the same scarce people.

5. Vendor platforms

Payroll on a human-capital platform, customer records on a customer-relationship platform, compute on a public cloud, payments through a processor — the enterprise depends on platforms it does not operate. Those platforms are I&T the enterprise uses. Third-party risk, concentration risk, exit plans, and data-residency rules belong in EGIT. If you only govern what you host, you are governing a shrinking fraction of the estate.

Scenario: Northbridge Specialty Manufacturing

Northbridge makes medical-device components. The CIO runs enterprise resource planning, email, and the factory wireless network. Last quarter three things happened that a Foundation stem will treat as one question: what is in COBIT's scope?

  • Operations replaced a vision-inspection camera system (OT) without an architecture review.
  • Commercial signed a quality-analytics SaaS deal that exports production data to a vendor in another country.
  • Two process engineers trained a defect model in a personal cloud account because the official data platform had a six-week backlog.

All three are in scope. The camera system is I&T used to achieve quality goals. The SaaS export is I&T plus third-party and residency risk. The personal cloud account is shadow I&T creating data and continuity risk. Saying "only the ERP and the wireless network, because those report to the CIO" is the trap.

The CIO's practical move is not to confiscate every tool tomorrow. It is to bring those uses into the governance system: who evaluates whether they create value, who directs risk appetite and sourcing rules, who monitors performance and incidents. Management in operations and commercial still runs the work. Governance covers the enterprise.

Notice what the CIO does not say. She does not say OT is "an engineering problem." She does not say the vendor is "responsible, so we are not." She does not say the model is out of scope until it is migrated. Those sentences fail both real EGIT and the exam.

Exam trap: "COBIT is for the IT department"

Expect items that describe a business-owned system and ask whether COBIT applies. The correct instinct is yes, if the enterprise uses that technology to achieve goals. Ownership on an organization chart does not create an exemption.

Drop these instincts:

  • "If it is OT, it belongs to engineering, not COBIT."
  • "If it is SaaS, the vendor is responsible, so we are not."
  • "If it is shadow IT, it is out of scope until IT takes it over."
  • "COBIT starts when a project is logged in the IT portfolio."
  • "Only systems in the CIO's configuration-management database count."

A stem that mentions marketing, a plant, a clinician, or a product owner is not changing the subject. It is testing whether you heard the I&T expansion.

Preview: end-to-end coverage

One of COBIT 2019's governance-system principles is end-to-end coverage: the governance system should cover the enterprise end to end, focusing on I&T, not only the IT function. You will study that principle in the Principles domain. This section is the vocabulary you need first.

Do not collapse nearby ideas. Holistic approach (later) is about using all components of a governance system together — processes, structures, information, culture, people, and services. End-to-end coverage is about where I&T lives across the enterprise. Different principles, related story.

For now, keep the sentence you will reuse on exam day: COBIT governs information and technology wherever the enterprise uses them, not merely the department called IT.

Loading diagram...
Enterprise I&T is wider than the IT function
Test Your Knowledge

In COBIT 2019, information and technology (I&T) refers to:

A
B
C
D
Test Your Knowledge

A marketing team buys a customer-data SaaS platform on a corporate card without involving the IT department. How should a COBIT-minded board treat that platform?

A
B
C
D