5.3 End-to-End Coverage
Key Takeaways
- A governance system covers the enterprise end to end: all functions and all I&T used to achieve goals, not only the IT department.
- Scope follows use, not organization-chart ownership; “the CIO does not own it” is not a COBIT exemption.
- Business processes, operational technology, digital products, vendor platforms, and data are in scope even when they sit outside central IT.
- Holistic approach is about component types working together; end-to-end coverage is about how far the system reaches.
- A manufacturer whose plant OT sits outside the CIO’s solid line is still inside the governance system.
Quick Answer: A COBIT 2019 governance system covers the enterprise end to end. It includes all functions and all information and technology (I&T) the enterprise uses to achieve its goals — not only the department called information technology (IT). Business processes, operational technology (OT), digital products, vendor platforms, and data are in scope even when they sit outside the CIO organization chart.
This is the principle that turns the I&T-versus-IT vocabulary from Framework Introduction into a design rule. Chapter 2 taught you that I&T is broader than the IT function. This section is the requirement that follows: a governance system that only watches the systems in the CIO’s configuration-management database has failed end-to-end coverage, even if its EDM committee meets on time and its process narratives are beautifully written.
What “end to end” means
Two axes, both required.
All enterprise functions. Governance is not a conversation that stays inside the CIO organization. Finance, operations, commercial, clinical, plant, stores, and risk functions that use information and technology are inside the system. A “steering committee” that only the IT leadership team attends is not end-to-end coverage. It is an IT meeting with a governance label.
All I&T used to achieve goals. Scope follows use, not ownership. If the enterprise uses a plant controller, a clinician-owned app, a marketing software-as-a-service (SaaS) platform, or a supplier portal to achieve goals, that use belongs in the governance system. Organization-chart ownership is an operating fact. It is not a COBIT exemption.
The IT function still matters. It is often the most capable operator of shared platforms and the most natural supplier of identity, network, and incident-response services. End-to-end coverage does not mean “fire the CIO” or “every department invents its own governance.” It means the system has to see the whole estate, then apply the other principles — stakeholder value, holism, dynamism, the governance/management split, and tailoring — across that estate.
I&T versus the IT function, as a principle
Older IT-governance talk treated “IT” as a department: the people who run the data center, the service desk, and the project office. COBIT 2019 rejects that boundary on purpose. Information and technology includes every use of information and every technology the enterprise puts in place to achieve goals, regardless of where that use sits.
A useful analogy is already familiar from finance. Accounting is a function with a reporting line. Finance is the enterprise concern that lives in every budget, price, and investment. End-to-end coverage is that pattern applied to I&T. The IT function is real. It is not the edge of EGIT.
If you read every Foundation stem as “what should the IT department do,” you will miss items that describe a plant system, a clinician-owned app, a marketing SaaS buy, or a product squad that never opens a ticket. Those uses are I&T. This principle says the governance system includes them.
Five places coverage fails if you stop at “IT”
Business processes
Order-to-cash, claims adjudication, loan origination, pick-pack-ship, and clinical documentation are information processes. Controls in those processes are I&T governance, which is why DSS06 Managed Business Process Controls exists. A governance system that only audits the data center has missed the process that actually creates or destroys value.
Operational technology
Operational technology (OT) is hardware and software that monitors or controls physical processes: factory supervisory control and data acquisition (SCADA) systems, warehouse robots, infusion pumps, vision-inspection cameras, building-management systems. OT used to be isolated. It is increasingly networked. A ransomware event that stops a packing line is an enterprise I&T event even if engineering, not the CIO, “owns” the controllers.
Digital products
Many enterprises now sell technology: a mobile banking app, a patient portal, a telematics device, a marketplace. Those products are designed by product managers and engineers who may sit far from traditional IT operations. They still process information, create risk, and consume scarce talent. COBIT does not wait for a “handover to IT” before governance applies.
Vendors
Payroll platforms, public cloud, payment processors, contract manufacturers, and claims engines host information the enterprise depends on. Third-party use is still enterprise I&T. “The vendor is responsible” does not remove the use from EGIT. It changes how management will run vendor and service-agreement objectives. It does not shrink the map.
Data
Pricing models, quality metrics, fraud scores, and production-image archives are the business. Data created by a line team, stored on an edge server, or shared with a partner is still information the enterprise uses. Governing only the warehouse the CIO runs leaves the real information estate outside the system.
| In-scope use | Typical owner on the org chart | Why COBIT still includes it |
|---|---|---|
| Plant vision line / SCADA | Operations or engineering | OT used to achieve quality and delivery goals |
| Marketing automation SaaS | Commercial | Customer data and a vendor platform used to achieve growth |
| Mobile product shipped weekly | Product squad | Digital product is how the enterprise achieves goals |
| Supplier portal | Procurement / vendor | Third-party information processing the enterprise depends on |
| Shop-floor image archive | Plant team | Data used for quality decisions, continuity, and liability |
The left column is I&T. The middle column is an operating fact. The right column is the principle.
Scenario: Eastfield Components and the plant the CIO does not own
Eastfield Components stamps metal housings for industrial pumps. The CIO runs enterprise resource planning, email, and the corporate network. The vice president of operations owns the plant. Last year operations installed a new vision-inspection line — cameras, programmable logic controllers, and an edge server that stores an image of every part. The line never appeared in an IT architecture review. It also never appeared on the board’s I&T risk pack. A contractor who maintains the cameras keeps a persistent login on the plant wireless network.
A ransomware strain later jumps from the contractor laptop and stops the inspection line for 36 hours. Shipments slip. A key customer invokes a penalty clause. In the incident review, the CIO says, “That environment is not mine.” Operations says, “We do not do IT governance. We run a plant.”
Both sentences violate this principle.
The vision line is OT. It is information and technology Eastfield uses to achieve quality and delivery goals. The image archive is data. The camera vendor and the contractor are third parties. The plant is an enterprise function. End-to-end coverage does not ask who signs the plant manager’s appraisal. It asks whether the governance system evaluated the risk of an isolated-but-networked line, directed a minimum control baseline (identity, remote access, backup, incident notification), and monitored whether that baseline existed.
Practical EGIT at Eastfield does not require the CIO to confiscate the line or start programming the PLC. That would violate governance distinct from management in the other direction — the CIO organization grabbing work it does not understand. Coverage means the system includes operations as a function, includes OT as I&T, includes the vision-system vendor, and includes the image data. The board still evaluates, directs, and monitors. Operations still runs the line. The CIO may supply identity, network segmentation, and incident-response services. Execution stays with the people who know the process. The map does not have a hole labeled “not IT.”
A Foundation stem will often look exactly like Eastfield: a plant, a clinic, a store, or a product team outside the CIO’s solid line. The scoring answer is that COBIT still applies.
What this principle is not
Do not collapse nearby principles. The exam writes distractors by swapping their jobs.
- Holistic approach is about using all component types together — processes, structures, information, culture, people, and services. It answers “what pieces make a system.”
- End-to-end coverage is about where the system applies — every function, every I&T use. It answers “how far the system reaches.”
- Governance distinct from management is about who evaluates-directs-monitors versus who plans-builds-runs. Eastfield’s board does not start programming the PLC. Operations does not become the board by owning the line.
- Tailored to enterprise needs decides how much capability the vision line requires. It does not decide whether the line is in scope. Scope is this principle; intensity is tailoring.
Exam traps
Drop these instincts the moment you see them:
- “COBIT stops at the IT department.”
- “OT is engineering, so it is out of scope.”
- “SaaS is the vendor’s problem, so we are not in EGIT.”
- “Shadow IT is out of scope until IT takes it over.”
- “Digital products enter COBIT only at handover to operations.”
- “If it is not in the CIO’s configuration-management database, the board can ignore it.”
If the enterprise uses it to achieve goals, the governance system includes it. Ownership explains who manages the use. It does not erase the use from the map.
Eastfield’s plant operations team owns a vision-inspection line the CIO does not control. A ransomware event stops the line. Under end-to-end coverage, what is in the governance system?
How should a Foundation candidate separate end-to-end coverage from the holistic-approach principle?