COBIT 2019 is an IT governance and management framework developed by ISACA that provides principles, practices, and analytical models to align technology and business. Its EDM domain—Evaluate, Direct, and Monitor—focuses on the governance processes responsible for ensuring that strategic IT decisions create value, manage risks, and ensure compliance with corporate objectives.
What is the EDM domain in COBIT 2019?
The EDM domain is the core governance framework of COBIT 2019. While the other domains—APO, BAI, DSS, and MEA—deal with operational IT management, EDM operates at the board and executive level: it defines the governance system, continuously evaluates IT performance against business objectives, directs strategic priorities, and monitors compliance with policies, regulations, and standards. It is the link between corporate strategy and technological execution.
The EDM domain connects directly to complementary frameworks such as ITIL 4 (service management), ISO/IEC 38500 (IT corporate governance) and ISO 27001 (information security), creating a unified governance foundation for organizations with complex operations.
Process reference framework: the 5 EDM domains
The COBIT 2019 Process Reference Framework (PRF) defines five processes within the EDM domain, each covering a distinct aspect of IT governance:
| Process | Objective |
|---|---|
| EDM01 | Configuration and maintenance of the assured governance framework. |
| EDM02 | Delivery of guaranteed benefits |
| EDM03 | Guaranteed risk optimization |
| EDM04 | Resource optimization guaranteed. |
| EDM05 | Guaranteed stakeholder engagement |
EDM01: Governance Framework Configuration and Maintenance
EDM01 establishes the IT governance structure in a consistent, integrated manner, aligned with corporate governance. Its core responsibilities are:
- To ensure that IT decisions are aligned with corporate strategies and objectives.
- To conduct supervisory processes effectively and transparently, ensuring compliance with legal, contractual, and regulatory requirements.
- To meet the governance requirements for board members, enabling the realization of the expected value of IT investments.
EDM02: Delivery of Assured Benefits
Focused on maximizing the value of IT investments, EDM02 ensures that technological initiatives, services, and assets generate concrete and measurable returns for the business. Key actions include:
- To ensure that IT-enabled initiatives deliver value in a cost-effective and measurable way.
- Maintaining a reliable view of expected costs and benefits, supporting investment decisions with accurate and up-to-date data.
EDM03: Risk Optimization
EDM03 ensures that the risks associated with the use of IT are identified, assessed, and managed within the appetite limits defined by the organization. To achieve this, it is necessary to:
- Clearly communicate and articulate the company's IT risk appetite and tolerance.
- Continuously monitor to ensure that corporate IT risk does not exceed the limits established by governance.
- Identify and manage the impact of IT risks on business value and regulatory compliance.
EDM04: Resource Optimization
EDM04 aims to ensure that IT resources—people, processes, information, and technology—are available in the quantity and quality needed to support corporate objectives at the lowest total cost. Key actions include:
- To ideally meet the company's resource needs, avoiding excess or shortage.
- Optimize IT costs, increasing the likelihood of realizing the expected benefits.
- To prepare the organization for future changes while maintaining agility and operational efficiency.
EDM05: Stakeholder Engagement
EDM05 ensures that all stakeholders—both internal and external—are identified, integrated into the governance system, and kept informed about IT performance and compliance. The process guarantees:
- Identifying and integrating stakeholders into the R&D governance system.
- Transparency in performance measurement, compliance, and reporting to the board and stakeholders.
- Approval of goals and metrics, with the definition of corrective actions when necessary.
- Effective communication of the IT strategy and roadmap, identifying areas for improvement and ensuring alignment with the corporate strategy.
The strategic importance of the EDM domain.
The EDM domain is the mechanism that connects strategic intent to operational IT outcomes. Organizations that implement mature EDM processes typically achieve:
- Greater alignment between IT and business objectives.
- More efficient use of available technological resources.
- Reducing the risks associated with IT decisions.
- Transparency and accountability in IT activities before the board.
- Structured communication with all stakeholders.
COBIT 2019 EDM and ServiceNow: Automated Governance
The ServiceNow platform offers native modules that operationalize the principles of the EDM domain. CMDB (Configuration Management Database) It provides the reliable database for the governance decisions required by EDM01 and EDM04. ITAM (IT Asset Management) It supports resource optimization and the delivery of measurable benefits (EDM02 and EDM04). The platform's reporting and dashboard capabilities enable the transparency required by EDM05, while the module of GRC (Governance, Risk and Compliance) It automates the risk monitoring foreseen in EDM03.
For organizations already operating on ServiceNow, structuring IT governance based on COBIT 2019 is a natural evolution: the data and processes are already on the platform; the EDM provides the decision-making model for them. See how... 4MATT structures IT Governance with COBIT and ServiceNow..