The CISSP exam (especially Domain 1, “Security and Risk Management”) lists NIST, ITIL, the ISO/IEC 27000 series, COSO, and COBIT side by side. But these are not interchangeable “security frameworks.” Their scopes differ substantially, their certification status differs, and they are not even competitors — it is entirely normal for an organization to use COBIT for overall governance design, get ISO/IEC 27001 certified for security, and run risk assessments with NIST CSF, all at the same time.
This article organizes each framework along three axes — (a) what organizational problem it was built to solve, (b) whether its scope is security-specific, general IT service management, or enterprise-wide governance/risk, and (c) whether a formal certification scheme exists — based on official documentation and the standards bodies’ own primary sources. The goal is precision on details (version numbers, publication years, and whether certification applies to individuals or organizations), not a vague summary.
NIST CSF (Cybersecurity Framework)
- Issuing body: National Institute of Standards and Technology (NIST), part of the U.S. Department of Commerce.
- Current version: CSF 2.0, published February 26, 2024. The original CSF 1.0 dates to 2014, so 2.0 is the first major revision in a decade ( NIST’s announcement ).
- Problem it solves: providing a common vocabulary for identifying and managing cybersecurity risk — it is less a technical implementation standard than an organizing framework that lets executives and practitioners discuss risk in the same terms.
- Scope: security-specific. CSF 1.0 had five functions — Identify, Protect, Detect, Respond, Recover. CSF 2.0 adds a sixth function, Govern, explicitly bringing executive oversight, supply-chain risk management, and policy-setting into scope. This means CSF now addresses organizational governance elements alongside technical controls, but its domain remains cybersecurity — it does not cover general IT service efficiency or financial controls.
- Certification: no third-party certification scheme exists. Organizations self-assess maturity using Tiers and Profiles; some audit firms offer independent CSF-alignment assessments, but there is no official certification scheme comparable to ISO/IEC 27001’s.
- Legal status (a common point of confusion): CSF itself is voluntary, for both government and private-sector use. Separately, FISMA (the Federal Information Security Modernization Act) requires U.S. federal agencies to implement controls based on NIST SP 800-53 — this is a distinct requirement from CSF. CSF functions as a higher-level organizing framework that is cross-mapped to detailed control catalogs like SP 800-53; using CSF does not, by itself, satisfy FISMA. FedRAMP, required of cloud providers doing business with U.S. federal agencies, is likewise an extension of the NIST SP 800-53 baseline for cloud environments — not a certification of CSF itself.
ITIL (Information Technology Infrastructure Library)
- Issuing body: originated at the UK’s Central Computer and Telecommunications Agency (CCTA) in the 1980s, later transferred to the Office of Government Commerce (OGC), then to AXELOS (a joint venture between the UK government and Capita) in 2013. PeopleCert acquired AXELOS in 2021, and PeopleCert now owns the ITIL trademark and publications.
- Current version: ITIL 4, published February 2019. The naming convention dropped “v3” style versioning in favor of simply “4.”
- Problem it solves: a collection of best practices for delivering and operating IT services, organized around a Service Value System that maps how IT services generate business value across their full lifecycle.
- Scope: focused on IT service management (ITSM) in general. Information security management is included as one of ITIL’s 34 practices, but it is only one part of a much broader practice set, not a security-specific framework. ITIL touches on governance (aligning services with business strategy) but its primary emphasis is service operation efficiency and quality.
- Certification: there is no organizational certification scheme for ITIL itself. PeopleCert offers individual exams — Foundation, Practitioner, Managing Professional, Strategic Leader — but no company can be “ITIL certified” as an organization. Organizations that want to demonstrate ITSM maturity externally typically pursue ISO/IEC 20000 certification (the international standard for service management systems, which reflects ITIL practices) instead.
The ISO/IEC 27000 series
- Issuing body: a joint technical committee of the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).
- Current version: ISO/IEC 27001:2022, published October 25, 2022. This is the first revision since 2013 — roughly a nine-year gap — and it restructures Annex A’s controls from 114 to 93 (56 controls merged into 24, 11 new controls added, and controls reorganized into 4 categories instead of 14); see ISO’s standard page and certification-body summaries for details. The main clauses (4–10) changed only slightly. Organizations certified under the 2013 version have a transition deadline of October 31, 2025.
- Problem it solves: defines the requirements for an Information Security Management System (ISMS) — a process by which an organization assesses risk specific to its own information assets, threats, and vulnerabilities, then selects and operates appropriate controls. ISO/IEC 27002 provides the implementation guidance (the control catalog) referenced alongside 27001.
- Scope: information security specific. It covers the whole organization (people, process, technology) but only with respect to information security risk — not general IT service operations or financial controls.
- Certification: of the five frameworks, ISO/IEC 27001 is the only one with an established organization-level, third-party certification scheme. Certification is granted after audits by an accredited certification body (a two-stage process — Stage 1 and Stage 2) and maintained through periodic surveillance audits. It is the most widely recognized information security certification internationally and is frequently specified as a vendor requirement.
- A common misconception: “an organization holds ISO/IEC 27001 certification” does not mean “the organization is actually secure.” Certification attests that the organization is running a functioning process (an ISMS) that identifies risk and operates chosen controls per the standard’s requirements — it does not attest to the effectiveness of individual technical controls or resilience against unknown threats. If an organization fails to keep responding to new risks after certification, its actual security posture can erode even while certification is maintained.
COSO (Committee of Sponsoring Organizations of the Treadway Commission)
- Issuing body: COSO, a joint initiative of several accounting and auditing professional associations.
- Current version: two separate flagship frameworks, revised independently.
- Internal Control—Integrated Framework (ICIF): current version dates to May 2013. Five components, 17 principles.
- Enterprise Risk Management (ERM) Framework: current version, “Enterprise Risk Management—Integrating with Strategy and Performance,” was published in 2017. Five components, 20 principles, and a more strategy-oriented view that ties risk to organizational objectives and performance.
- Problem it solves: ICIF evaluates the effectiveness of internal controls against three objectives — reliable financial reporting, effective/efficient operations, and regulatory compliance (it is the most widely used basis for U.S. SOX Section 404 compliance). ERM addresses a broader scope — risk to the achievement of organizational objectives generally — and embeds it into strategy-setting and decision-making.
- Scope: focused on internal control and enterprise-wide risk management. Information security and IT operations are treated as just one category of operational risk among many; COSO touches on IT governance elements (control environment) but is not an IT-specific framework.
- Certification: no organizational certification scheme exists. COSO frameworks function as criteria used for audit and attestation (management’s assertion about the effectiveness of internal controls, verified by external auditors) rather than a pass/fail third-party certification like ISO/IEC 27001’s. Their most common use is as the evaluation criteria U.S. public companies use for SOX Section 404 internal control reporting.
COBIT (Control Objectives for Information and Related Technologies)
- Issuing body: ISACA (Information Systems Audit and Control Association).
- Current version: COBIT 2019, published November 2018 as the successor to COBIT 5. Rather than releasing a full new major version, ISACA has continued to update COBIT 2019 with supplementary guidance covering new areas such as AI and data privacy; COBIT 2019 remains the current version as of 2026.
- Problem it solves: draws a clear distinction between IT governance and IT management, then provides a framework for designing a governance system that aligns enterprise strategy with IT strategy. COBIT 2019 scores 11 design factors (enterprise strategy, risk profile, threat landscape, compliance requirements, and more) to build a governance system tailored to a specific organization, rather than a one-size-fits-all approach.
- Scope: focused on IT governance, but its 40 governance/management objectives span multiple domains — information security, risk management, IT service management, and compliance — cutting across them. It functions less as a standalone security or ITSM standard and more as a higher-level integrating framework that ties those domains together from a governance perspective.
- Certification: like ITIL, there is no organizational certification scheme. ISACA offers individual credentials — COBIT Foundation, COBIT Design and Implementation — but a company cannot obtain “COBIT certification.”
Framework comparison table
| Framework | Issuing body | Current version | Primary scope | Organizational certification |
|---|---|---|---|---|
| NIST CSF | NIST (U.S. Dept. of Commerce) | 2.0 (Feb 2024) | Information security (incl. governance) | None (self-assessed) |
| ITIL | PeopleCert (formerly AXELOS) | 4 (Feb 2019) | IT service management, general | None (individual certs only; orgs use ISO/IEC 20000 instead) |
| ISO/IEC 27001 | ISO/IEC | 2022 edition (Oct 2022) | Information security management | Yes (third-party audit) |
| COSO | COSO | ICIF 2013 / ERM 2017 | Internal control / enterprise risk management | None (audit/attestation criteria) |
| COBIT | ISACA | 2019 (Nov 2018, updated continuously) | IT governance, enterprise-wide | None (individual certs only) |
As a footnote: ISO/IEC 27001 shares Annex SL (the common high-level structure) with standards like ISO 9001 (quality management). Both use the same structural language of running a PDCA-based management system, but 9001 governs quality in general while 27001 governs information security — entirely different subject matter. That shared structure is precisely what makes it easier for an organization to run quality and information security management systems together in an integrated way.
Visualizing the scope overlap
The figure below maps how the five frameworks focus on four domains — information security, IT service management, enterprise risk and internal control, and IT governance — and whether an organization-level certification exists for each.

The structure visible in the figure:
- Each framework has a diagonal “home turf”: NIST CSF and ISO/IEC 27001 in security, ITIL in ITSM, COSO in risk/internal control, and COBIT in governance (the dark-blue cells).
- COBIT is the only framework touching all four domains: this reflects its character as a “meta-framework” that ties together standalone security and ITSM standards rather than being one itself.
- Organizational certification exists only for ISO/IEC 27001: the other four rely on individual credentials (ITIL, COBIT) or self-assessment/audit criteria (NIST CSF, COSO) — “getting certified” is, in practice, a phrase that applies only to ISO/IEC 27001.
How organizations actually combine them
The CISSP exam tends to present these frameworks as if they were mutually exclusive choices, but in practice organizations typically layer them, each addressing a different level of concern:
- COBIT for overall design: use it as the foundation for designing governance structure, responsibility allocation, and metrics between executives and IT (choosing which of the 40 governance/management objectives matter most).
- ISO/IEC 27001 for certifiable security: within the governance structure COBIT designed, build a concrete ISMS for information security specifically, and obtain a certification that can be shown externally.
- NIST CSF for risk assessment: within the “risk assessment” activity that ISO/IEC 27001’s ISMS operation requires, use CSF’s Tiers and Profiles as a common vocabulary to evaluate current maturity and explain improvement priorities to executives (CSF does not conflict with ISO/IEC 27001’s requirements).
- ITIL for efficient IT service operation: run day-to-day operation, change management, and incident response for the systems that implement those security controls according to ITIL practices (incident management, change management, and so on).
- COSO for controls tied to financial reporting: publicly traded companies also need internal control evaluation based on COSO ICIF (for SOX Section 404 compliance) for IT systems that touch financial reporting processes, running in parallel with the above.
None of these five compete with each other. The practical design question is not “which framework should we pick” but “which layer of the problem does each one address.”
FAQ
If an organization holds ISO/IEC 27001 certification, does that mean it’s secure?
No. ISO/IEC 27001 certification attests that the organization is running a functioning process (an ISMS) that identifies risk and operates chosen controls per the standard’s requirements – it does not attest to the effectiveness of individual technical controls or resilience against unknown threats. If the organization stops responding to new risks after certification, its actual security posture can erode even while certification is maintained.
Do COBIT or ITIL have an organization-level certification scheme like ISO/IEC 27001?
No. Both COBIT and ITIL only offer individual credentials (COBIT Foundation and COBIT Design and Implementation; ITIL’s Foundation, Practitioner, Managing Professional, and Strategic Leader), and no company can obtain “COBIT certification” or “ITIL certification.” Organizations that want to demonstrate ITSM maturity externally typically pursue ISO/IEC 20000 instead. Of the five frameworks, ISO/IEC 27001 is the only one with an established organization-level, third-party certification scheme.
For CISSP prep, how are the five frameworks actually combined in practice?
Rather than treating them as competing choices, organizations typically layer them: COBIT designs the overall governance structure, ISO/IEC 27001 provides certifiable security within it, NIST CSF’s Tiers and Profiles are used for risk-assessment maturity, ITIL practices govern day-to-day IT operations, and publicly traded companies also need COSO ICIF-based internal control evaluation running in parallel.
Study Resources for CISSP Prep
The CISSP exam spans eight domains, and its scope is too broad to cover through self-study alone. The security governance material covered in this article in particular tests fine details – framework names, publication years, and certification status – so a systematic approach using an official study guide and practice question sets is effective.
Related Articles
- Security Certification Comparison: CISSP vs Japan’s Registered Information Security Specialist - A detailed comparison of CISSP and Japan’s RISS certification, covering exam requirements, costs, difficulty, and career impact.