COBIT 2019 (SOX ITGC reference)
SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification.
COBIT 2019 · ISACA — COBIT
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
COBIT 2019 (SOX ITGC reference) is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Licensed framework — ISACA requires an annual license when COBIT content is used in commercial software, tools, audit, advisory, or consulting products; publication access alone is insufficient.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Change management · Logical access · IT operations · Governance
- Applies to
- public companies · financial reporting · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
- Pending change
- ISACA states that a COBIT update is planned later in 2026. COBIT 2019 remains the current framework until a successor is published; planned timing is not a released edition.Expected: Later in 2026
03Version ledger
| COBIT 5 | Superseded | date not published |
| COBIT 2019 | Current edition · supersedes COBIT 5 | date not published |
06Related frameworks
- Sarbanes-Oxley ICFRSOX Sections 302 and 404; PCAOB AS 2201
Also applies to public companies · The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion.
Also applies to public companies · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
- SEC Cybersecurity Disclosure RulesRelease Nos. 33-11216; 34-97989
Also applies to public companies · What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.
- NERC CIPCIP-002 through CIP-015 (per-standard versions)
Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.