COBIT 2019 is designed to work with other frameworks. Consider integrating your maturity assessment with ISO 38500, ITIL, or NIST Cybersecurity Framework assessments for a more holistic view.

You don't need to assess all 40 governance and management objectives at once. Use the (like enterprise size, role of IT, and compliance requirements) to determine which specific processes are critical to your organization. 2. Create the Questionnaire

Case Study: Implementing COBIT 2019 | by Hilda Machando | Medium

Borrowing from the CMMI (Capability Maturity Model Integration) standard, COBIT 2019 rates processes on a scale from 0 to 5:

Aggregated measures for focus areas that reflect how collections of processes achieve goals through substantial evidence.

COBIT 2019 introduced several significant changes:

Built-in radar charts provide clean visual data for leadership presentations. Step-by-Step Assessment Guide

11 Management Objectives managing programs, projects, definition, and transformation.

) often integrate the core design factors and capability models into a single, user-friendly file. Key Components of the Assessment Tool

Whether using the official ISACA toolkit or a 2021 repack, a structured assessment methodology is essential. The following 6-step guide provides a practical roadmap:

Does not automatically ping process owners for evidence or follow-ups. Best Practices for Using the Tool Securely

The framework defines six capability levels (0–5), ranging from “Incomplete” to “Optimizing,” and five maturity levels that are assessed at the focus‑area level. Because ISACA has not published an official PAM for COBIT 2019, organizations are encouraged to build custom assessment schemas based on CMMI principles and their unique governance contexts.

The process is not implemented or fails to achieve its purpose.

Collect policy documents, audit reports, and interview key IT stakeholders. Step 3: Input the Ratings

Each of these solutions demonstrates the value of a well‑structured spreadsheet for governance assessment. However, none of them is explicitly called a “repack” – which brings us to the central keyword.