The other extensions describe cost, quality, security, and service. COBIT sits above them all: the governance layer that decides how IT is directed, prioritized, and held to account against the institution's goals.
COBIT (from ISACA) is a framework for the governance and management of enterprise IT. It separates governance — the board-level job of setting direction and monitoring outcomes — from management — the executive job of planning, building, running, and monitoring — and defines objectives for each, tied back to stakeholder needs.
Its purpose is the question that sits over the whole estate: who decides what IT does, how those decisions ladder up to institutional goals, and how we know they are working. It is the accountability frame around everything else.
COBIT groups its core objectives into one governance domain and four management domains. Adapted from the COBIT 2019 core model.
Governance (EDM) directs; the four management domains plan, build, run, and check. Simplified from the COBIT 2019 core model.
COBIT's distinctive role is that it doesn't replace the other disciplines on this site — it sits above them and decides which parts of each to adopt in service of enterprise goals. Enterprise governance sets direction; COBIT filters and integrates the relevant frameworks; governance of enterprise I&T runs the result. Adapted from ISACA.
Sets enterprise goals and strategy — direction, decisions, and accountability.
Selects and integrates the parts of each framework that fit enterprise goals and strategy.
Governs the information and technology the enterprise runs on.
The other extensions on this site — ITIL, NIST CSF, TBM, DAMA — are exactly the kind of frameworks COBIT filters and integrates. Adapted from ISACA, "The Framework to Manage Frameworks."
COBIT governs decisions; HERM supplies the facts those decisions need. Governance without a clear picture of the estate is opinion; the estate model gives COBIT's objectives something concrete to direct and monitor — and ties every IT decision back to a capability that serves the mission.
Governance decisions rest on the real capabilities, systems, and risks in the model.
Investment and project choices ladder up to the capabilities that serve the mission.
Performance and conformance are measured against a current, shared picture.
Extending the model toward COBIT means adding a governance layer over the estate. A pragmatic starting set:
Who is accountable, responsible, consulted, and informed for each capability or system.
How each system and capability ladders up to an institutional objective.
Which committee or role governs each service category or capability.
The measures each objective is monitored against.
Which governance policies apply to a capability, and the controls that enforce them.
How mature the governance of each area is, and the target.
Start by assigning decision rights to the capabilities the model already names — who governs each, and to which institutional goal it ladders. Governance stops being abstract and becomes a clear map of who decides what, resting on the same estate everyone else works from.
COBIT is a framework of ISACA. This page describes how it complements HERM; decision rights, metrics, and maturity ratings are local extensions.