COBIT recently announced its COBIT 5 Certified Assessor Program. My organization uses COBIT. Under what circumstances...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
does it make sense to invest in COBIT 5 certification, and who or which roles should pursue it?
Ask the Expert
Got a vexing problem for Mike Chapple or any of our other experts? Ask your enterprise-specific questions today! (All questions are anonymous.)
Propagated by the Information Systems Audit and Control Association (ISACA), the Control Objectives for Information Technology (COBIT) are a widely accepted set of practices for managing and governing information technology activities. They are primarily used by auditors seeking a standard framework to evaluate an organization's technology control environment and by security and governance professionals seeking an objective basis for their IT control programs. The COBIT 5 Certified Assessor Program provides individuals with a way to demonstrate their competence in applying the COBIT framework to IT processes.
To achieve COBIT 5 certification, individuals must complete an approved COBIT 5 assessor training program, pass two COBIT examinations and demonstrate that they have five or more years of relevant work experience. These are significant, costly hurdles, and, in my opinion, the barriers to entry do not justify members of the general information security and IT audit communities working toward this credential. Most individuals would likely be better served by obtaining the more widely recognized general certifications in their field, such as the Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA) credentials. The CISSP and CISA both require security and compliance professionals to demonstrate a solid foundation of knowledge and work experience without limiting themselves to one particular standard.
The limited case where the COBIT 5 credential might make sense is for IT professionals who work in an enterprise that is firmly committed to COBIT implementation or IT auditors who routinely encounter COBIT in their regular duties. In those cases, COBIT certification may be appropriate, provided the employer is willing to provide funding! For professionals looking to obtain a credential that increases their marketability in the broader employment market, though, I'd suggest looking elsewhere.
Dig Deeper on COBIT
Related Q&A from Mike Chapple
A proposed cyberattack information database in the U.K. aims to improve cyberinsurance. Expert Mike Chapple explains what collecting data breach ...continue reading
The proposed CFTC regulations on cybersecurity testing are set to finalize in 2016. Expert Mike Chapple discusses the effects these regulations have ...continue reading
Whether Apple is a HIPAA covered entity was called into question when it advertised for a health regulations lawyer. Expert Mike Chapple discusses ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.