2.3 COBIT 2019 Product Family
Key Takeaways
- The four core publications are Introduction and Methodology; Governance and Management Objectives; the Design Guide; and the Implementation Guide.
- Introduction and Methodology covers principles, architecture, performance-management concepts, and design concepts.
- Governance and Management Objectives is the detailed 40-objective core model.
- The Design Guide is design factors, a tailoring workflow, and a toolkit; the Implementation Guide is the seven-phase continual-improvement lifecycle — do not swap those jobs.
- Focus-area publications (SME, DevOps, information security, I&T risk) are optional overlays, not extra Foundation domains.
Quick Answer: The COBIT 2019 product family has four core publications. Introduction and Methodology teaches principles, architecture, performance, and design concepts. Governance and Management Objectives details the 40-objective core model. The Design Guide is for tailoring with design factors, a workflow, and a toolkit. The Implementation Guide is the seven-phase continual-improvement lifecycle. Focus-area books are optional overlays, not extra Foundation domains.
Framework Introduction will ask you to match a job to a book. Mixing the Design Guide with the Implementation Guide is one of the most reliable ways to lose an item in this 12% domain. Learn the four titles as four jobs, not as four synonyms for "the COBIT book."
An open-ended family, four core books
COBIT 2019 is a product family, not a single binder. ISACA designed it to be open-ended: the core model stays stable, and additional focus-area guidance can be published without rewriting the Foundation syllabus. For the exam, master the four core titles and what each is for.
| Publication | Official job | Open it when you need to… | Foundation cue |
|---|---|---|---|
| COBIT 2019 Framework: Introduction and Methodology | Heart of the framework: expanded governance definition, updated principles, overall structure | Understand principles, architecture, performance-management concepts, and design concepts | "What is COBIT and how is it structured?" |
| COBIT 2019 Framework: Governance and Management Objectives | Detailed COBIT Core Model | Read each of the 40 governance and management objectives, purpose, related process, alignment goals, and enterprise goals | "What does a specific objective contain?" |
| COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution | How to tailor a governance system | Apply design factors, follow the design workflow, use the design toolkit | "How should our system differ from the generic model?" |
| COBIT 2019 Implementation Guide: Implementing and Optimizing an Information and Technology Governance Solution | How to implement and improve | Run the seven-phase continual-improvement lifecycle | "How do we start, embed, and keep improving EGIT?" |
ISACA published the two framework volumes with the 2018 launch of COBIT 2019, then released the Design Guide and Implementation Guide shortly afterward so enterprises could actually design and run a tailored system. You do not need that calendar for a math item. You do need to know 2019 is a family, not one book.
1. Introduction and Methodology
This is the conceptual map. It explains why enterprise governance of information and technology (EGIT) matters, how COBIT positions itself, and how the pieces fit.
Expect this volume to cover:
- The expanded idea of governance and the purpose of generating value from information and technology (I&T)
- The governance-system principles and governance-framework principles (full treatment comes in later chapters)
- The architecture: core model, components, focus areas, design factors
- High-level performance management ideas, including capability — later a small exam domain of its own
- Design concepts — enough to understand that a system should be tailored — without the full design workflow and toolkit
If a question asks where you find the principles, the product architecture, or the explanation of performance and design concepts, this is the book. It introduces the 40 objectives as a model. It does not replace the objective-by-objective reference.
A candidate who studies only this volume will understand the map and fail items that ask what lives inside a named objective. A candidate who jumps straight to the 40 objectives without this volume will miss why the model is shaped the way it is.
2. Governance and Management Objectives
This is the thick reference. The core model has 40 objectives: five governance objectives in Evaluate, Direct and Monitor (EDM) and 35 management objectives across Align, Plan and Organize (APO); Build, Acquire and Implement (BAI); Deliver, Service and Support (DSS); and Monitor, Evaluate and Assess (MEA). You will learn the model as its own domain. For this section, know which book holds the detail.
For each objective the publication typically ties together purpose, the related process, practices and activities at a useful level, and the cascade links to alignment goals and enterprise goals. When an item says "detailed description of the 40 objectives," do not pick Introduction and Methodology or either Guide.
Think of this volume as the catalog of what good looks like for each objective. Think of the Design Guide as which of those matter most here. Think of the Implementation Guide as how the organization changes so those chosen objectives actually operate.
3. Design Guide — tailor, do not "roll out"
Enterprises are not identical. A 40-person software firm, a hospital, and a global bank should not photocopy the same governance system. The Design Guide answers "what should ours look like?"
It centers on design factors — inputs such as enterprise strategy, risk profile, IT-adoption style, threat landscape, compliance requirements, the role of IT, sourcing model, and similar facts you will study in the Designing domain (7% of the exam). It provides a workflow for using those factors and a toolkit to record the design: priority objectives, target capability levels, variant components.
Design is deciding the shape of the system. Design is not the seven-phase change program. If a stem says "which design factors should change priority and target capability," you are in the Design Guide even if someone in the scenario also plans a rollout.
A credit union that is highly regulated, risk-averse, and dependent on two payment processors should not copy the governance system of a consumer-app startup that ships daily and holds little regulated data. The Design Guide exists so that difference is deliberate.
4. Implementation Guide — seven phases, continual improvement
The Implementation Guide is the "how we change the organization" book. It updates the older COBIT 5 implementation approach and folds in 2019 terminology, including design factors. Its spine is a seven-phase continual-improvement lifecycle — a cycle, not a one-time project with a ribbon-cutting.
Typical implementation concerns: recognizing the need to change, executive sponsorship, forming a team, defining a roadmap, executing improvements, operating the new way of working, and reviewing whether value is actually appearing. That is organizational change. It is not the same as filling out the design-factor toolkit.
The Implementation domain is 8% of the Foundation exam and will walk the phases. For Framework Introduction, remember the job of the book: implement and optimize EGIT over time.
ISACA is explicit that implementation is more practical when combined with the Design Guide. Combined use does not merge their identities. You design a tailored system; you implement and improve it through the seven-phase lifecycle. Pairing is not sameness.
The exam trap: Design versus Implementation
| If the stem talks about… | Reach for… | Do not reach for… |
|---|---|---|
| Design factors, tailoring, target capability, toolkit, "what should our system include" | Design Guide | Implementation Guide |
| Seven phases, continual improvement, a program to embed EGIT, "how do we implement" | Implementation Guide | Design Guide |
| Principles, architecture, performance concepts | Introduction and Methodology | Either Guide |
| The 40 objectives in detail | Governance and Management Objectives | Introduction and Methodology |
A badly written mental model is "Design Guide = the new implementation book." They were released as companions. They still have different jobs. If you remember only one contrast from this section, remember that one.
Focus areas: overlays, not extra domains
The family is open-ended. Focus-area publications apply the core model to a topic or community. Official examples you should recognize:
- Small and medium enterprises (SMEs) — right-sizing the model for smaller organizations
- DevOps — governing and managing the development-and-operations way of working
- Information security — security-specific practices, activities, and metrics on top of the core
- Information and technology (I&T) risk — risk-specific practices, activities, and metrics
These are optional overlays. They do not add Foundation exam domains. You will not sit a separate "DevOps domain" on this certificate. You should know that focus areas exist, that they sit on the core model rather than replacing it, and that an SME or a high-security enterprise might use one without abandoning the 40-objective model.
Related companions exist — for example, guidance on implementing the National Institute of Standards and Technology (NIST) Cybersecurity Framework using COBIT 2019. Treat them the same way: useful overlays, not extra Foundation domains, and not substitutes for the four core books.
A small hospital that adopts the SME focus area still has EGIT, still has the core model, and still may use the Design Guide to tailor. It does not get a different Foundation exam.
How a Foundation candidate should study the family
You are not expected to recite every page. You are expected to:
- Name the four core publications and match each to its job.
- Put detailed 40-objective content in Governance and Management Objectives.
- Keep design factors, workflow, and toolkit in the Design Guide.
- Keep the seven-phase continual-improvement lifecycle in the Implementation Guide.
- Call focus areas optional overlays.
If you can do those five things, this product-family slice of Framework Introduction is under control. When a later chapter teaches design factors or the seven phases in depth, you will already know which book owns the idea.
Which COBIT 2019 publication contains the detailed 40-objective core model?
How should a Foundation candidate separate the Design Guide from the Implementation Guide?
How should COBIT 2019 focus-area publications (for example SME, DevOps, information security, and I&T risk) be treated for the Foundation exam?