← All Cheat Sheets

Governance Frameworks Comparison

COBIT vs ITIL vs ISO 27001 vs NIST at a glance.

Governance Frameworks Comparison

A side-by-side comparison of the four governance and management frameworks most commonly tested on the CISA exam.

Attribute COBIT ITIL ISO 27001 NIST CSF
PublisherISACAAxelos (PeopleCert)ISO/IECNIST (U.S.)
Primary FocusIT governance and managementIT service managementInformation security managementCybersecurity risk management
Structure6 principles, 40 governance/management objectivesService value system, 34 practicesISMS with 93 controls (Annex A)6 functions, 22 categories
Certifiable?No (individual cert only)No (individual cert only)Yes (organizational)No
Best ForAligning IT with business goalsImproving service deliveryBuilding an ISMSAssessing cybersecurity posture
Audit RelevancePrimary framework for IT audit criteriaAudit service management processesAudit security controls and ISMSBenchmark security programs

COBIT Key Concepts

  • Governance objectives (EDM): Evaluate, Direct, Monitor
  • Management objectives: Align, Plan, Organize (APO); Build, Acquire, Implement (BAI); Deliver, Service, Support (DSS); Monitor, Evaluate, Assess (MEA)
  • Separates governance (board responsibility) from management (executive responsibility)

NIST CSF 2.0 Six Functions

Function Purpose
GovernEstablish and monitor cybersecurity risk management strategy, expectations, and policy
IdentifyUnderstand assets, risks, and governance context
ProtectImplement safeguards for critical services
DetectIdentify security events promptly
RespondTake action on detected incidents
RecoverRestore capabilities after an incident

CISA Exam Tip

COBIT is the most heavily tested framework. Know that it bridges business goals and IT processes. When a question asks about the "best framework for IT governance," the answer is almost always COBIT.

Ready to test your knowledge?

Put this cheat sheet to work with scenario-based CISA practice questions.

Start Free