COBIT is an IT governance framework developed by ISACA. Figure 1 shows the major
milestones in the development of COBIT. The COBIT framework arose from initiatives by
members of ISACA in the financial and IT audit communities. These audit professionals confronted
increasingly automated environments. To guide their work, the initial development of COBIT was
as a framework for the execution of IT audit assignments. It was constructed around a
comprehensive set of so-called ‘‘Control Objectives for IT Processes’’ (IASCF 1994). Over
successive versions, COBIT transitioned toward a broader IT governance and management
framework with management tools including metrics, critical success factors, maturity models, and
tools for the assignment of roles and responsibilities for IT processes. COBIT 4 saw the
development of tools to align business and IT goals and their relationship with supporting IT
processes. COBIT 4 also strengthened the connection with other relevant governance frameworks
and IT frameworks and standards (ITGI 2005). More recently, COBIT was complemented with the
Val IT and Risk IT frameworks (ISACA 2009c, 2010). These addressed the IT-related business
processes and responsibilities in value creation (Val IT) and risk management (Risk IT). In each
case, Val IT and Risk IT drew key concepts and processes from COBIT and added domain-specific
guidance.