Table of Contents
ToggleTwo executives, one boardroom, two diametrically opposed manifestations of the same panic: The CISO cannot justify the security spend without an ISO 27001 certificate, while the CIO cannot rationalize the IT spend without some link between the technology and the business outcomes. “We need to use a framework, but we always seem to pick the wrong one,” say these executives.
The truth is that COBIT and ISO 27001 are not competing frameworks, but rather address different areas. Confusing them can lead to insufficiently governed security or unnecessarily compliant technology functions.
Introduction to ISO 27001
ISO/IEC 27001:2022 is an international standard covering the establishment and maintenance of an Information Security Management System (ISMS), which has a single goal to preserve the confidentiality, integrity, and availability of information.
The 2022 version of the standard significantly revised the Annex A controls, reducing them from 114 (Annex A, 2013) to 93 controls divided into four sections: Organizational (37), People (8), Physical (14), and Technological (34). The 11 New additional controls address several current issues related to cloud security, security intelligence, and data masking.
You do not have to implement all 93 controls by default; instead, you can perform a risk assessment and document the applicable and inapplicable controls in the Statement of Applicability (SoA), the key document examined by auditors.
Summary note: Organizations can be certified to ISO 27001 by accredited certification bodies, whereas individuals obtain qualifications such as Lead Implementer or Lead Auditor.
In Brief, What Is COBIT 2019?
ISACA publishes COBIT (Control Objectives for Information and Related Technology) to address a broader issue. This is about the governance of the entire enterprise IT function, which encompasses issues such as strategy, risk, value delivery, performance management, and security.
The COBIT process splits 40 governance objectives into five domains of activity:
EDM (Evaluate, Direct, Monitor)
EDM (Evaluate, Direct, Monitor) which has 5 objectives that are the responsibility of the board of directors.
APO (Align, Plan, Organize)
BAI (Build, Acquire, Implement)
DSS (Deliver, Service, Support)
MEA (Monitor, Evaluate, Assess)
The specialty of COBIT is the presence of 11 design factors (such as enterprise strategy, risk profile, and threat landscape) that determine which objectives are applicable in a particular case, rather than considering all 40 objectives as a universal list.
The main point is that an organization cannot obtain a COBIT certification, but individuals can obtain the COBIT Foundation certification or the design and implementation certification. COBIT is a governance model to be tailored by the company, not a certification standard.
A Comparison of COBIT and ISO 27001
| Factor | ISO/IEC 27001:2022 | COBIT 2019 |
| Published By | ISO / IEC | ISACA |
| Definition | Specifically relates to information security | Full IT governance: strategy, risk, value, delivery |
| Framework | 93 Annex A controls and 4 themes | 40 objectives and 5 domains |
| Methods | Risk-based approach documented in SoA | Tailoring through 11 design factors |
| Certification | Yes, through accredited enterprises | Not available—no certification available |
| Personal Certification | Lead implementer, Lead auditor | COBIT Foundation and design & implementation |
| Key Trigger | Request from customer, tender and law | IT-business mismatch and lack of responsibility |
| Target Audience | Chief information security officers, compliance teams and security teams | Executives, chief information officers and governance leaders |
Which Option Do You Select?
Choose ISO 27001 if:
- You are requested by a client, a regulatory body, or a tender for the certificate
- Your primary purpose is to safeguard information
- You want to assure and convince your clients of your reliability
Choose COBIT if:
- IT costs are decoupled from business strategies
- There is no one explicitly accountable for which technology decisions
- You want governance over and above security, service delivery, vendor risk management, and IT investment decision-making
Select Both
Select both in order if you are a larger enterprise that has to carry the weight of multiple policies (e.g., GDPR, NIS2, DORA), none of which is covered by only one framework. You can find governance principles in COBIT, while ISO 27001 already provides integrated security controls. ISACA has even published a paper on how ISO 27001 security controls were mapped into the COBIT framework.
COBIT 2019 is designed to work with other standards, frameworks, and regulations, and its design approach allows organizations to tailor governance to their specific needs.
Myth of Retiring
The presence of one does not imply the absence of the other. Having begun contracting with the enterprise, the start-up must implement ISO 27001, as the contracts require it. Once the company ceases to be satisfied with only securing the data, it has to move to COBIT in turn – not instead of the previous standard, but alongside.
So, if the company is interested in both governance and growth in security, the answer to the question “ISO 27001 or COBIT?” would be “Both.”
Ready to Take the Next Step?
If you are looking for a framework or certification that aligns with your company’s governance policy or your career, Spoclearn offers the COBIT 2019 Foundation Certification Training and various courses in IT Governance and Information Security, endorsed by ISACA.
FAQs
1. Is COBIT better than ISO 27001?
Neither replaces the other. ISO 27001 focuses on information security, while COBIT provides a broader framework for IT governance.
2. Can an organization use COBIT and ISO 27001 together?
Yes. Organizations can use COBIT for IT governance and ISO 27001 for information security management and certification.
3. Can you get certified in COBIT?
Organizations cannot obtain COBIT certification, but individuals can earn certifications such as COBIT Foundation. ISO 27001 allows organizations to achieve certification.