Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

IT governance framework layers compared: COBIT 2019 for governance, ISO 31000 for risk, CIS Controls for implementation

IT Governance Framework: 3 Essential Layers Explained

Teams adopting COBIT, ISO 31000 and the CIS Controls often assume they are choosing between them. They are not. Each occupies a different layer of the same problem, and an IT governance framework that works usually has all three doing distinct jobs: one decides, one weighs risk, one implements. This guide explains which does what, and how to tell which layer you are actually missing.

If you are looking for a certifiable security standard rather than a governance model, our ISO 27001 vs NIST CSF comparison is the better starting point.

Three layers at a glance

  Layer Question it answers Certifiable
COBIT 2019 Governance Who decides, and how do we know it worked? No (individual certification only)
ISO 31000 Risk Which risks matter and what do we do about them? No, by design
CIS Controls v8.1 Implementation What do we actually do first? No, but measurable

The pattern worth noticing: none of them are certifiable. All three are reference models, which is precisely why they combine well rather than competing.

COBIT 2019: separating governance from management

COBIT’s central distinction is one most organisations blur. Governance sets direction and monitors whether it was followed; management executes within that direction. COBIT 2019 makes this structural, with Evaluate, Direct and Monitor as governance objectives, and Align Plan and Organise, Build Acquire and Implement, Deliver Service and Support, and Monitor Evaluate and Assess as management domains.

Its other useful idea is design factors: the framework is meant to be tailored to enterprise strategy, threat landscape and risk profile rather than adopted wholesale. Our COBIT 2019 IT Governance Toolkit covers this with 31 templates — the governance framework manual, implementation and design guides, cross-mapping appendix, and a document set for each of the five domains.

ISO 31000: the risk layer

ISO 31000 is deliberately not certifiable, which confuses people who expect a certificate at the end. It exists to describe how risk management should be designed and run: principles, a framework, and a process of identification, analysis, evaluation and treatment.

Its value is in the plumbing that most risk registers lack — a stated risk appetite, a defined method for scoring, and a clear line between who owns a risk and who accepts it. Our ISO 31000 Risk Management Toolkit provides 30 templates including the framework overview and risk management policy, charter and mandate, risk appetite statement, the process manual with identification through treatment, enterprise, operational and project risk registers, a bow-tie analysis template, three lines mapping workbook and a maturity self-assessment.

For a prescriptive method to run underneath it, our NIST SP 800-30 guide covers one widely used approach.

CIS Controls v8.1: what to do first

Where the other two describe how to think, the CIS Controls tell you what to do, in order. Eighteen controls, prioritised by Implementation Group: IG1 is the basic hygiene every organisation needs, IG2 and IG3 add depth for larger or more exposed enterprises.

That prioritisation is derived from real attack data, which makes it the most practically useful of the three for a team that needs to show progress this quarter. Our CIS Controls v8.1 Toolkit provides 40 templates covering all eighteen controls, from asset and software inventory through data protection, account and access management, vulnerability management, log management and malware defences.

Which layer are you missing?

The symptoms are distinctive. If security work happens but nobody can say who authorised it or whether it achieved anything, the gap is governance — COBIT. If everything is treated as equally urgent and the register is a list rather than a set of decisions, the gap is risk — ISO 31000. If the strategy is sound but nothing has actually been hardened, the gap is implementation — CIS.

Most organisations have one strong layer and two weak ones, and the weak ones are rarely the ones getting attention.

Frequently asked questions

Can you get certified in COBIT?

Individuals can hold COBIT certifications, but organisations cannot be certified against COBIT the way they can against ISO 27001. It is a governance framework rather than a conformity standard.

Do CIS Controls replace ISO 27001?

No. The CIS Controls are a prioritised set of technical and procedural safeguards; ISO 27001 is a certifiable management system. Many organisations use CIS to decide implementation order and ISO 27001 to demonstrate the system around it.

Why is ISO 31000 not certifiable?

By design. It provides guidelines for risk management rather than auditable requirements, so there is nothing to certify against. Organisations wanting certification usually apply it inside a management system that is certifiable.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.