COBIT recently announced its COBIT 5 Certified Assessor Program. My organization uses COBIT. Under what circumstances...
By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
does it make sense to invest in COBIT 5 certification, and who or which roles should pursue it?
Ask the Expert
Got a vexing problem for Mike Chapple or any of our other experts? Ask your enterprise-specific questions today! (All questions are anonymous.)
Propagated by the Information Systems Audit and Control Association (ISACA), the Control Objectives for Information Technology (COBIT) are a widely accepted set of practices for managing and governing information technology activities. They are primarily used by auditors seeking a standard framework to evaluate an organization's technology control environment and by security and governance professionals seeking an objective basis for their IT control programs. The COBIT 5 Certified Assessor Program provides individuals with a way to demonstrate their competence in applying the COBIT framework to IT processes.
To achieve COBIT 5 certification, individuals must complete an approved COBIT 5 assessor training program, pass two COBIT examinations and demonstrate that they have five or more years of relevant work experience. These are significant, costly hurdles, and, in my opinion, the barriers to entry do not justify members of the general information security and IT audit communities working toward this credential. Most individuals would likely be better served by obtaining the more widely recognized general certifications in their field, such as the Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA) credentials. The CISSP and CISA both require security and compliance professionals to demonstrate a solid foundation of knowledge and work experience without limiting themselves to one particular standard.
The limited case where the COBIT 5 credential might make sense is for IT professionals who work in an enterprise that is firmly committed to COBIT implementation or IT auditors who routinely encounter COBIT in their regular duties. In those cases, COBIT certification may be appropriate, provided the employer is willing to provide funding! For professionals looking to obtain a credential that increases their marketability in the broader employment market, though, I'd suggest looking elsewhere.
Dig Deeper on COBIT
Related Q&A from Mike Chapple
Encrypting data going to the cloud is a security best practice, but does it add extra challenges for regulators that might need to access the data? ...continue reading
Merchants that sell at off-site venues need to take extra care to follow PCI compliance standards. Expert Mike Chapple discusses how organizations ...continue reading
The FTC's order for PCI DSS compliance assessments is odd since PCI isn't a government regulation. Expert Mike Chapple explains the motivation ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.