Governance Frameworks and Standards (COBIT, ISO/IEC 38500)
In the CGEIT context, governance frameworks and standards give boards and executives structured, repeatable ways to ensure that IT creates value, optimizes risk and uses resources well. The two most important references are COBIT and ISO/IEC 38500. COBIT (Control Objectives for Information and Rel… In the CGEIT context, governance frameworks and standards give boards and executives structured, repeatable ways to ensure that IT creates value, optimizes risk and uses resources well. The two most important references are COBIT and ISO/IEC 38500. COBIT (Control Objectives for Information and Related Technologies), published by ISACA, is a comprehensive framework for the governance and management of enterprise information and technology. COBIT 2019 rests on six governance system principles: provide stakeholder value, holistic approach, dynamic governance system, governance distinct from management, tailored to enterprise needs, and end-to-end governance system. It defines 40 governance and management objectives grouped into five domains. The governance domain is EDM (Evaluate, Direct and Monitor). The four management domains are APO (Align, Plan and Organize), BAI (Build, Acquire and Implement), DSS (Deliver, Service and Support) and MEA (Monitor, Evaluate and Assess). Each objective is supported by seven components: processes; organizational structures; principles, policies and frameworks; information; culture, ethics and behavior; people, skills and competencies; and services, infrastructure and applications. Design factors, such as strategy, risk profile and compliance requirements, help tailor the governance system. The goals cascade translates stakeholder needs into enterprise goals and then into alignment goals. Process capability is assessed on a 0 to 5 scale based on CMMI. ISO/IEC 38500 is the international standard for corporate governance of IT and is aimed at governing bodies such as boards. It sets out six principles: Responsibility, Strategy, Acquisition, Performance, Conformance and Human Behaviour. It also defines the Evaluate-Direct-Monitor model, in which directors evaluate current and future IT use, direct the preparation and implementation of plans and policies, and monitor performance and conformance. The two are complementary. ISO/IEC 38500 provides high-level principles for directors, while COBIT supplies the detailed objectives, practices and metrics needed to put them into operation. Both clearly separate governance from management. CGEIT candidates should know how these frameworks support benefits realization, risk optimization and resource optimization. They should also understand how COBIT integrates with other standards such as ITIL, ISO/IEC 27001, COSO and TOGAF.
Governance Frameworks and Standards (COBIT, ISO/IEC 38500): A Complete CGEIT Guide
Introduction
Governance frameworks and standards are the foundation of the CGEIT Domain 1: Governance of Enterprise IT. They give boards, executives and IT leaders a shared language, a structure and proven practices for directing and controlling the use of information and technology. The two you must know best are COBIT (published by ISACA) and ISO/IEC 38500 (the international standard for governance of IT for the organization). This guide covers why they matter, what they are, how they work and how to handle exam questions about them.
1. Why Governance Frameworks and Standards Are Important
Alignment of IT with business strategy: Frameworks help make sure IT investments and activities support enterprise goals instead of running as a separate technical function.
Value delivery: They give structured ways to confirm that IT-enabled investments deliver the benefits promised in business cases.
Risk optimization: They support identifying, assessing and managing IT-related risk within the enterprise's risk appetite.
Resource optimization: They help allocate people, infrastructure, applications and information efficiently.
Accountability and transparency: They define clear roles, responsibilities and decision rights, so it is clear who is accountable for what.
Regulatory compliance: Many regulators and auditors expect recognized frameworks to be in place. Examples include SOX, GDPR, Basel requirements and industry-specific rules.
Common language: Boards, business managers, IT, auditors and regulators can talk about IT using the same terms and concepts.
Benchmarking and improvement: Frameworks provide capability and maturity models, so organizations can measure where they are and plan where they want to be.
Without a framework, IT governance tends to be ad hoc, depend on individuals, react to problems and have no clear link to business outcomes.
2. What They Are
2.1 Governance vs. Management (critical distinction)
Both COBIT and ISO/IEC 38500 separate governance from management. This is one of the most heavily tested concepts in the exam.
Governance is about setting direction and holding management to account. It ensures that:
- stakeholder needs, conditions and options are evaluated to set balanced, agreed enterprise objectives;
- direction is set through prioritization and decision making;
- performance and compliance are monitored against agreed direction and objectives.
Governance is usually the responsibility of the board of directors, under the leadership of the chair.
Management plans, builds, runs and monitors activities in line with the direction set by the governance body. It is usually the responsibility of executive management, under the leadership of the CEO.
2.2 COBIT (Control Objectives for Information and Related Technologies)
COBIT is ISACA's comprehensive framework for the governance and management of enterprise information and technology (I&T). It has evolved through several versions:
- COBIT 1 (1996): an audit focus.
- COBIT 2 and 3: added control and management.
- COBIT 4.x: IT governance.
- COBIT 5 (2012): a business framework for governance.
- COBIT 2019: the current version, flexible and tailorable.
COBIT 2019 Governance System Principles (six):
1. Provide stakeholder value.
2. Holistic approach.
3. Dynamic governance system.
4. Governance distinct from management.
5. Tailored to enterprise needs.
6. End-to-end governance system.
COBIT 2019 Governance Framework Principles (three):
1. Based on a conceptual model.
2. Open and flexible.
3. Aligned to major standards.
COBIT 5 Principles (five, still referenced in many study materials):
1. Meeting stakeholder needs.
2. Covering the enterprise end-to-end.
3. Applying a single integrated framework.
4. Enabling a holistic approach.
5. Separating governance from management.
Components of a governance system (COBIT 2019, seven):
1. Processes.
2. Organizational structures.
3. Principles, policies and procedures.
4. Information.
5. Culture, ethics and behavior.
6. People, skills and competencies.
7. Services, infrastructure and applications.
(These were called "enablers" in COBIT 5.)
The COBIT Core Model: 40 governance and management objectives in five domains
Governance domain:
- EDM, Evaluate, Direct and Monitor: 5 objectives (EDM01 to EDM05). They cover the governance framework, benefits delivery, risk optimization, resource optimization and stakeholder engagement.
Management domains:
- APO, Align, Plan and Organize: 14 objectives. Examples include strategy, enterprise architecture, portfolio, budget, HR, vendors, quality, risk, security and data.
- BAI, Build, Acquire and Implement: 11 objectives. Examples include programs, requirements, solutions, change, knowledge and assets.
- DSS, Deliver, Service and Support: 6 objectives. Examples include operations, service requests and incidents, problems, continuity, security services and business process controls.
- MEA, Monitor, Evaluate and Assess: 4 objectives. These cover performance and conformance monitoring, internal control, compliance with external requirements and assurance.
Goals Cascade: This translates stakeholder drivers and needs into enterprise goals, then into alignment goals (formerly IT-related goals), and then into governance and management objectives. It links business needs to specific IT priorities.
Design Factors (COBIT 2019): These are used to tailor the governance system. There are eleven:
- enterprise strategy;
- enterprise goals;
- risk profile;
- I&T-related issues;
- threat landscape;
- compliance requirements;
- role of IT;
- sourcing model;
- IT implementation methods;
- technology adoption strategy;
- enterprise size.
Focus Areas: These are specific governance topics, such as small and medium enterprises, cybersecurity, DevOps, cloud and digital transformation.
Performance Management: COBIT 2019 uses a CMMI-based approach:
- capability levels (0 to 5) for processes;
- maturity levels (0 to 5) for focus areas.
2.3 ISO/IEC 38500
ISO/IEC 38500 is the international standard for the governance of IT for the organization. It was first published in 2008 (adapted from the Australian standard AS 8015) and revised in 2015 and 2024. It is short and principle-based. It is aimed at the governing body (directors, board members and owners), not at IT managers.
The Six Principles of ISO/IEC 38500:
1. Responsibility: Individuals and groups understand and accept their responsibilities for both supplying and demanding IT, and they have the authority to act.
2. Strategy: Business strategy considers current and future IT capabilities, and IT strategic plans meet the current and ongoing needs of the business strategy.
3. Acquisition: IT acquisitions are made for valid reasons, based on appropriate, ongoing analysis and clear, transparent decision making. Benefits, opportunities, costs and risks are balanced.
4. Performance: IT is fit for purpose. It supports the organization and provides services of the quality needed to meet current and future business requirements.
5. Conformance: IT complies with all mandatory legislation and regulations, and policies and practices are clearly defined, implemented and enforced.
6. Human Behaviour: IT policies, practices and decisions respect human behaviour, including the current and evolving needs of all people in the process.
The EDM Model of ISO/IEC 38500: Directors should govern IT through three main tasks:
- Evaluate: examine and judge the current and future use of IT, including strategies, proposals and supply arrangements.
- Direct: assign responsibility for, and direct the preparation and implementation of, plans and policies.
- Monitor: monitor conformance to policies and performance against plans, using suitable measurement systems.
The model sits within a context of business pressures and business needs.
Related ISO/IEC standards:
- ISO/IEC 38500 family (including ISO/IEC 38501 to 38506);
- ISO 37000 (governance of organizations);
- ISO/IEC 27001 (information security management);
- ISO/IEC 20000 (IT service management);
- ISO 31000 (risk management);
- ISO 22301 (business continuity).
2.4 Other Frameworks Often Referenced Alongside
- ITIL: IT service management practices, mostly at the management or operational level.
- COSO Internal Control and COSO ERM: enterprise internal control and risk management.
- ISO/IEC 27001 and 27002: information security.
- NIST CSF: cybersecurity.
- TOGAF: enterprise architecture.
- PMBOK and PRINCE2: project management.
- Val IT and Risk IT: value and risk, now integrated into COBIT.
- Balanced Scorecard: performance measurement.
- CMMI: capability and maturity.
COBIT acts as an umbrella or integrator. It aligns with these frameworks rather than replacing them.
3. How They Work
3.1 COBIT vs. ISO/IEC 38500: how they fit together
ISO/IEC 38500:
- It tells the board what it should do, in the form of principles plus the EDM model.
- It is high-level, short and principle-based.
- It is not prescriptive about processes.
- Its audience is directors and governing bodies.
COBIT:
- It provides what and how in detail: governance and management objectives, processes, practices, activities, RACI charts, metrics and maturity measurement.
- Its EDM domain directly mirrors the 38500 Evaluate-Direct-Monitor model.
- It is often described as a practical way to implement ISO/IEC 38500 principles.
3.2 Implementing a governance framework (COBIT implementation lifecycle)
COBIT uses a seven-phase lifecycle that runs alongside three related views: program management, change enablement and continual improvement.
1. What are the drivers? Recognize the need to act, often triggered by a pain point or trigger event.
2. Where are we now? Assess the current state, including capability and maturity.
3. Where do we want to be? Define the target state and the improvement goals.
4. What needs to be done? Plan feasible solutions and close the gaps.
5. How do we get there? Implement the solutions.
6. Did we get there? Realize the benefits and monitor them.
7. How do we keep the momentum going? Review effectiveness and sustain the change.
3.3 Tailoring with COBIT 2019
COBIT 2019 tailors the governance system in four steps:
1. Understand the enterprise context and strategy.
2. Determine the initial scope of the governance system.
3. Refine the scope using the design factors.
4. Conclude the governance system design.
3.4 Typical success factors
- Board and executive sponsorship (tone at the top).
- A business-driven approach, not an IT-driven one.
- Tailoring to the enterprise; avoid adopting the framework "by the book".
- Quick wins, with priority based on business value and risk.
- Clear roles and decision rights, defined with RACI charts.
- Organizational change management and cultural adoption.
- Performance measurement and continuous improvement.
3.5 Common pitfalls
- Treating the framework as a checklist or a compliance exercise.
- Trying to implement all 40 objectives at once.
- A lack of business involvement.
- Confusing governance with management activities.
- No metrics, or no link to enterprise goals.
4. Exam Tips: Answering Questions on Governance Frameworks and Standards (COBIT, ISO/IEC 38500)
Tip 1: Think like a board member or senior executive, not a technician.
CGEIT is a governance exam. The best answer usually reflects a strategic, enterprise-wide, business-value view. Avoid choices that jump to technical fixes or detailed operational tasks.
Tip 2: Know the governance vs. management split.
- Setting direction, evaluating options, prioritizing and monitoring at a high level is governance, carried out by the board (EDM).
- Planning, building, running and monitoring operations is management (APO, BAI, DSS, MEA).
Questions often ask which body should do something. Choose the board for direction and accountability, and executive management for execution.
Tip 3: The FIRST step is usually to understand business needs or strategy.
When asked what to do first when adopting a framework, choose an option such as:
- understand the enterprise strategy and stakeholder needs;
- obtain executive sponsorship;
- assess the current state.
Do not choose "implement processes" or "buy a tool" as the first step.
Tip 4: Tailor, don't copy.
Answers suggesting a framework should be adopted fully and exactly as written are usually wrong. COBIT 2019 stresses tailoring through design factors and focus areas.
Tip 5: Know the primary purpose of each framework.
- ISO/IEC 38500 gives principles for directors.
- COBIT gives comprehensive governance and management of I&T.
- ITIL covers service management.
- ISO/IEC 27001 covers the information security management system (ISMS).
- COSO covers internal control and ERM.
- TOGAF covers enterprise architecture.
If a question asks which framework best fits a need, match the need to the purpose.
Tip 6: Memorize the lists.
Be ready to recognize:
- the six ISO/IEC 38500 principles: Responsibility, Strategy, Acquisition, Performance, Conformance, Human Behaviour. A mnemonic is "RSAPCH: Really Smart Auditors Prefer Clear Habits".
- the EDM tasks;
- the five COBIT domains;
- the seven components;
- the six COBIT 2019 governance system principles.
Tip 7: Link everything back to value, risk and resources.
The core governance objectives are:
- benefits realization (value);
- risk optimization;
- resource optimization.
An answer that balances all three, or ties a decision to stakeholder value, is usually the strongest.
Tip 8: Watch for keywords.
- "Most important", "primary" and "best" usually point to the strategic or business-aligned choice.
- "Accountable" points to the single role that owns the outcome, often the board or a senior executive. "Responsible" points to whoever does the work.
- "Ensure" often signals a governance or monitoring action.
Tip 9: Monitoring and continuous improvement are expected.
Good answers often include measuring performance (KPIs, KGIs, balanced scorecards) and feeding the results back into direction. Governance is a cycle, not a one-time project.
Tip 10: Eliminate extremes and siloed answers.
Discard choices that:
- favor IT alone without business involvement;
- focus only on cost;
- ignore risk;
- recommend replacing all existing frameworks.
COBIT integrates other standards rather than replacing them.
Tip 11: Scenario questions follow a pattern.
A typical scenario reads: "The board is concerned that IT investments are not delivering value. What should the CIO recommend?" The best answer is usually a governance mechanism, such as:
- portfolio management or a value management framework;
- benefits tracking;
- an IT steering or strategy committee.
It is rarely a single technical project.
Tip 12: Know the governance structures.
- The IT Strategy Committee is board-level. It advises the board on strategic IT direction.
- The IT Steering Committee is executive-level. It prioritizes and oversees programs and projects.
Questions frequently test this distinction.
Sample Question Walkthrough
Question: An enterprise wants to adopt COBIT 2019. Which of the following should be performed FIRST?
A. Implement all 40 governance and management objectives
B. Assess the capability of IT processes
C. Understand the enterprise context, strategy and stakeholder needs
D. Purchase a GRC tool
Answer: C.
- COBIT's design process starts by understanding the enterprise strategy and context, and the goals cascade begins with stakeholder needs.
- B comes after the target is understood.
- A ignores tailoring.
- D is a tool decision, not a governance step.
Question: According to ISO/IEC 38500, which principle addresses ensuring IT decisions consider the needs of people affected?
Answer: Human Behaviour.
5. Quick Revision Summary
- Governance means Evaluate, Direct and Monitor, carried out by the board. Management means plan, build, run and monitor, carried out by executives.
- ISO/IEC 38500 has six principles plus the EDM model. It is high-level and aimed at directors.
- COBIT 2019 has 40 objectives in five domains (EDM, APO, BAI, DSS, MEA), seven components, design factors, focus areas and a goals cascade. It is tailorable and uses CMMI-based capability and maturity levels.
- COBIT is an umbrella that integrates ITIL, ISO 27001, TOGAF, COSO and other frameworks.
- Always prioritize business alignment, stakeholder value, risk optimization, resource optimization, accountability and continuous improvement.
Final advice: On exam day, ask yourself: "Which answer best helps the enterprise create value from I&T while optimizing risk and resources, with clear accountability at the right level?" That answer is almost always correct in this domain.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!