COBIT *describes the common requirements* that organisations should have in place *surrounding their information systems*. The COBIT framework is maintained by the **Information Systems Audit and Control Association** ([[Information Systems Audit and Control Association|ISACA]]). As an organisation analyses its risk environment, technical and business leaders determine the level of protection required to preserve the confidentiality, integrity, and availability of their information and systems. They express these requirements by writing the *control objectives that the organisation wishes to achieve*. These control objectives are statements of a desired security state.