Skip to main content
—
Framework library
Framework module · sox-itgc-cobit-2019

COBIT 2019 (SOX ITGC reference)

SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification.

COBIT 2019 · ISACA — COBIT

Standing today
Directory entry

00Answer

from the registry record
What is COBIT 2019 (SOX ITGC reference)?
SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification.
Who does COBIT 2019 (SOX ITGC reference) apply to?
COBIT 2019 (SOX ITGC reference) applies to public companies, financial reporting, US, global, per ISACA — COBIT.
What is the current version of COBIT 2019 (SOX ITGC reference)?
The current edition is COBIT 2019, issued by ISACA — COBIT. Source: https://www.isaca.org/resources/cobit.
What does an assessment under COBIT 2019 (SOX ITGC reference) require?
No control catalog has been ingested for COBIT 2019 (SOX ITGC reference) yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

COBIT 2019 (SOX ITGC reference) is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Licensed framework — ISACA requires an annual license when COBIT content is used in commercial software, tools, audit, advisory, or consulting products; publication access alone is insufficient.

02Registry record

checked 2026-08-30
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Change management · Logical access · IT operations · Governance
Applies to
public companies · financial reporting · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30
Pending change
ISACA states that a COBIT update is planned later in 2026. COBIT 2019 remains the current framework until a successor is published; planned timing is not a released edition.Expected: Later in 2026

03Version ledger

2 editions
COBIT 5Supersededdate not published
COBIT 2019Current edition · supersedes COBIT 5date not published

06Related frameworks

scored from registry facts
  1. Sarbanes-Oxley ICFRSOX Sections 302 and 404; PCAOB AS 2201

    Also applies to public companies · The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion.

  2. Also applies to public companies · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

  3. SEC Cybersecurity Disclosure RulesRelease Nos. 33-11216; 34-97989

    Also applies to public companies · What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.

  4. NERC CIPCIP-002 through CIP-015 (per-standard versions)

    Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.

COBIT 2019 (SOX ITGC reference) | ControlFrame