COBIT position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What it does well

  • Governance vs management distinction useful.
  • Board-level framing of IT.
  • Cross-framework references to ISO, NIST, ITIL.
  • Design factors for tailoring.
  • Focus area guides for specific contexts.

What it does poorly

  • Heavy framework — 40 objectives, many practices, large documentation set.
  • Implementation complexity for smaller orgs.
  • Combined with ITIL — overhead amplified.
  • Procurement signal limited compared to ISO 27001 / SOC 2.

Evidence

  • Widely used in US enterprise + financial services.
  • ISACA certifications (CRISC, CISA, CISM, CGEIT) influential.
  • Less DE / EU adoption than ITIL.

Personal calibration

  • For governance-strategy work: vocabulary useful.
  • For implementation: typically secondary to ITIL / ISO 27001.

See also