COBIT recently announced its COBIT 5 Certified Assessor Program. My organization uses COBIT. Under what circumstances...
By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
does it make sense to invest in COBIT 5 certification, and who or which roles should pursue it?
Ask the Expert
Got a vexing problem for Mike Chapple or any of our other experts? Ask your enterprise-specific questions today! (All questions are anonymous.)
Propagated by the Information Systems Audit and Control Association (ISACA), the Control Objectives for Information Technology (COBIT) are a widely accepted set of practices for managing and governing information technology activities. They are primarily used by auditors seeking a standard framework to evaluate an organization's technology control environment and by security and governance professionals seeking an objective basis for their IT control programs. The COBIT 5 Certified Assessor Program provides individuals with a way to demonstrate their competence in applying the COBIT framework to IT processes.
To achieve COBIT 5 certification, individuals must complete an approved COBIT 5 assessor training program, pass two COBIT examinations and demonstrate that they have five or more years of relevant work experience. These are significant, costly hurdles, and, in my opinion, the barriers to entry do not justify members of the general information security and IT audit communities working toward this credential. Most individuals would likely be better served by obtaining the more widely recognized general certifications in their field, such as the Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA) credentials. The CISSP and CISA both require security and compliance professionals to demonstrate a solid foundation of knowledge and work experience without limiting themselves to one particular standard.
The limited case where the COBIT 5 credential might make sense is for IT professionals who work in an enterprise that is firmly committed to COBIT implementation or IT auditors who routinely encounter COBIT in their regular duties. In those cases, COBIT certification may be appropriate, provided the employer is willing to provide funding! For professionals looking to obtain a credential that increases their marketability in the broader employment market, though, I'd suggest looking elsewhere.
Dig Deeper on COBIT
Related Q&A from Mike Chapple
Cloud compliance issues are no reason for enterprises not to move to the cloud. Expert Mike Chapple explains why, as well as what to keep in mind ...continue reading
The GAO reported on SEC cybersecurity weaknesses, even though the SEC regulates cybersecurity. Expert Mike Chapple discusses the effects of this ...continue reading
Enterprise compliance can be a burden to manage, which is where a PCI ISA can be helpful. Expert Mike Chapple explains how a PCI Internal Security ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.