3.2 Evolution from COBIT 5 to COBIT 2019
Key Takeaways
- COBIT 5’s five governance principles become six governance system principles in 2019, and three new governance framework principles are added
- The core model grows from 37 processes to 40 governance and management objectives: APO14 Managed Data, BAI11 Managed Projects, and MEA04 Managed Assurance
- Terminology shifts from COBIT 5 verbs (Manage / Ensure) to 2019 adjectives (Managed / Ensured); APO10 changes “supplier” to “vendor,” and BAI06/BAI07 specify IT changes
- Performance management moves from the ISO/IEC 33000 SPICE scale to a CMMI-based capability scheme of 0–5; COBIT 5 enablers are renamed components
- Design factors, focus areas, and the design workflow plus toolkit are 2019 introductions — treating five principles or “enablers” as the 2019 answer is an exam trap
Quick Answer: COBIT 2019 keeps the EGIT idea from COBIT 5 and changes the scaffolding. Five principles become six governance system principles plus three new governance framework principles. Thirty-seven processes become 40 governance and management objectives. Enablers are renamed components. Performance management moves from ISO/IEC 33000 SPICE to a CMMI-based 0–5 capability scheme. Design factors, focus areas, and a design workflow/toolkit are new.
ISACA released COBIT 5 in 2012 and COBIT 2019 in 2018. The 2020 ISACA comparison article, read with COBIT 2019 Framework: Introduction and Methodology, is the source the Foundation exam expects you to know. The update exists because enterprises needed the framework to absorb digitization and newer I&T business trends without abandoning the Evaluate-Direct-Monitor / plan-build-run structure candidates already recognize.
Do not study 2019 as “COBIT 5 with three extra processes.” The scoring differences are principles, terminology, performance, and design. A candidate who still recites five principles and seven enablers is answering a 2012 paper.
Principles: five become six, and a second family appears
COBIT 5 taught five governance principles:
- Meeting stakeholder needs
- Covering the enterprise end-to-end
- Applying a single integrated framework
- Enabling a holistic approach
- Separating governance from management
COBIT 2019 splits the idea into two lists.
Six governance system principles describe how a governance system should behave:
- Provide stakeholder value
- Holistic approach
- Dynamic governance system
- Governance distinct from management
- Tailored to enterprise needs
- End-to-end governance system
Three governance framework principles describe how the COBIT framework itself is built:
- Based on a conceptual model
- Open and flexible
- Aligned to major related standards, frameworks, and regulations
Two system principles are the ones candidates most often miss: dynamic governance system and tailored to enterprise needs. They are why 2019 talks about design factors and changing the system when context changes. The old COBIT 5 line “applying a single integrated framework” is not deleted; it is rebuilt as the three framework principles, especially alignment and openness.
Exam trap: if an option says COBIT 2019 has five principles, it is describing COBIT 5. If it says six principles and stops there, it is incomplete but closer — 2019 has six system principles and three framework principles. Learn both counts.
From 37 processes to 40 objectives
The governance and management model is still organized as EDM, APO, BAI, DSS, and MEA. The count changes from 37 processes to 40 governance and management objectives. 2019 also prefers the word objective because each item is an outcome the enterprise should achieve, supported by components, not only a process document.
Three objectives are added:
| New 2019 objective | Domain | Why it was added |
|---|---|---|
| APO14 Managed Data | Align, Plan and Organize | Data is now a first-class enterprise asset, not a side effect of applications and information flows. |
| BAI11 Managed Projects | Build, Acquire and Implement | Project delivery needed its own objective so EGIT can govern project work without borrowing a generic “change” process. |
| MEA04 Managed Assurance | Monitor, Evaluate and Assess | Assurance is called out so independent review is a designed part of the system, not an afterthought. |
If a question asks “what is new in the 2019 core model?”, name those three. Do not invent extras. APO10, BAI06, and BAI07 were already in COBIT 5; 2019 renames or narrows them, it does not add them.
Terminology you must say the 2019 way
ISACA changed the grammar on purpose.
- COBIT 5 used verbs: management processes were “Manage …”; governance processes were “Ensure …”.
- COBIT 2019 uses adjectives: management objectives are “Managed …”; governance objectives are “Ensured …”.
So COBIT 5 “Manage Security” becomes COBIT 2019 Managed Security. COBIT 5 “Ensure …” governance titles become Ensured …. The MEA domain keeps the domain name Monitor, Evaluate and Assess, but the three inherited MEA objectives are restated with Managed (and MEA04 is the new Managed Assurance).
Two narrower wording changes are official comparison facts:
- APO10 changes supplier to vendor. On the exam, the 2019 name is Managed Vendors, not “Manage Suppliers.”
- BAI06 and BAI07 now specify that the changes being managed, accepted, and transitioned are IT changes. The scope note stops candidates from treating those objectives as generic enterprise change management for every non-IT business change.
If a stem still says “Manage Supplier Relationships” or quotes a five-principle list, you are looking at COBIT 5 language. Translate before you answer.
Performance management: SPICE out, CMMI in
COBIT 5 measured process capability on a 0–5 scale based on ISO/IEC 33000 (the SPICE family). COBIT 2019 measures capability with a CMMI-based performance-management scheme, still 0 through 5, but with CMMI level descriptions rather than the ISO/IEC 33000 process-attribute model.
What does not change is the idea of a capability scale. What does change is the reference model. An option that says “COBIT 2019 uses ISO/IEC 33000 / SPICE” is a COBIT 5 answer wearing a 2019 label. An option that says there is no scale, or that 2019 is only pass/fail, is also wrong.
Capability targets remain tailored. Nothing in the CMMI-based scheme requires every objective to sit at level 5. Design factors set relative importance; the enterprise then chooses a target that is good enough for that context.
Enablers become components
COBIT 5’s seven enablers (processes; organizational structures; principles, policies and frameworks; information; culture, ethics and behavior; people, skills and competencies; services, infrastructure and applications) are renamed components in 2019. The ISACA comparison table is explicit: “Enablers are included” in COBIT 5; “Enablers are renamed as components” in COBIT 2019. The same article also says enablers were removed for simplification — meaning the generic enabler model was hidden so COBIT looks less complex — not that the seven building blocks vanished.
Exam trap: if the correct-looking option says enablers in a 2019 question, it is almost certainly a COBIT 5 leftover. The 2019 word is components. Components can be generic (the core model) or variants used in a focus area such as information security or DevOps.
Design factors, focus areas, and the design workflow
These are the structural additions that make 2019 feel like a design method rather than a fixed process catalog.
Design factors are new. They are the contextual forces that change how the governance system should look. The comparison article highlights the published set of 11 design factors, including enterprise strategy, enterprise goals, risk profile, I&T-related issues, threat landscape, compliance requirements, role of IT, sourcing model for IT, IT implementation methods, technology adoption strategy, and enterprise size. COBIT 5 had no equivalent published design-factor set.
Focus areas are also new. A focus area describes a governance topic or issue that can be addressed by a collection of objectives and variant components — security, DevOps, small and medium enterprises, and similar slices. The potential list is open-ended, which is why the framework-principle “open and flexible” matters.
A governance-system design workflow and toolkit are added so practitioners can move from context to a tailored system. Introduction and Methodology and the Design Guide walk a sequence that produces an initial scope, a refined scope, and a concluded scope:
- Initial scope is driven mainly by enterprise strategy, enterprise goals, risk profile, and I&T-related issues.
- Refined scope is driven by threat landscape, compliance requirements, role of IT, sourcing model, implementation methods, and technology adoption strategy.
- Concluded scope resolves conflicts and completes the design.
The toolkit scores the 40 objectives against those factors. For most design factors the weight is importance; for risk profile the weight is risk rating. That workflow is why “implement all 40 at level 5” is the wrong 2019 picture. The product is a best-fit system, not a clone of the core model at maximum capability.
Side-by-side comparison
Figure 7 in the 2020 ISACA comparison, expanded with the official process notes, is the table to memorize.
| Topic | COBIT 5 | COBIT 2019 |
|---|---|---|
| Governance principles | Five governance principles | Six governance system principles |
| Framework principles | Absent | Three governance framework principles added |
| Core model count | 37 processes | 40 governance/management objectives |
| Added items | — | APO14 Managed Data, BAI11 Managed Projects, MEA04 Managed Assurance |
| Process/objective wording | “Manage” (management), “Ensure” (governance) | “Managed” and “Ensured” |
| APO10 wording | Supplier | Vendor |
| BAI06 / BAI07 | Change / accept-and-transition language | Specifies IT changes |
| Performance management | 0–5 scale based on ISO/IEC 33000 / SPICE | CMMI-based capability 0–5 |
| Building blocks | Enablers | Enablers renamed components |
| Design factors | Not available | Included (11 published factors) |
| Focus areas | Not a 2015-era design concept in the same form | Introduced; open-ended list |
| Design workflow / toolkit | Not part of the COBIT 5 product set in this form | Added in the Design Guide and toolkit |
How to avoid COBIT 5 answers on a 2019 paper
Work every evolution item as a translation problem:
- Count the principles. Five = COBIT 5. Six system + three framework = 2019.
- Count the objectives. 37 = COBIT 5. 40, with APO14, BAI11, and MEA04 named = 2019.
- Check the grammar. Verbs (Manage / Ensure) are COBIT 5. Adjectives (Managed / Ensured) are 2019.
- Check the building-block word. Enabler = COBIT 5. Component = 2019.
- Check the capability reference. ISO/IEC 33000 or SPICE = COBIT 5. CMMI 0–5 = 2019.
- Look for design. Design factors, focus areas, and the design toolkit exist only in the 2019 story.
COBIT 2019 is still recognizably COBIT: EGIT, governance distinct from management, a goals cascade, and a core model organized by EDM / APO / BAI / DSS / MEA. The Foundation exam rewards candidates who can state what changed without claiming that 2019 invented governance or discarded the 2012 model. Quote six system principles, not five. Say components, not enablers. Name the three new objectives. That is the whole evolution slice of Framework Introduction.
Compared with COBIT 5, how many governance and management objectives does the COBIT 2019 core model contain, and which three were added?
A candidate describes COBIT 2019 performance management as an ISO/IEC 33000 SPICE scale and calls the seven building blocks “enablers.” What is the accurate 2019 restatement?
Which statement correctly captures a documented terminology or scope change from COBIT 5 to COBIT 2019?