🏛️ The company's IT management framework desk
The international governance and management framework is aligned in layers - from board level management (COSO, ISO 38500) through integrating COBIT 2019 to operational domains (ITIL, TOGAF, ISO 27001). No framework replaces others - they complement each other.
IT management (governance) determines the direction and monitors, management (management) performs. COBIT 2019 is an integrating framework that harmonises business and IT goals and maps other frameworks as its promoters. This page shows the stack visually and gives references to each frame.
The stack is not a strict hierarchy, but a layer view: governance (why and how far) determines the direction, COBIT translates it into management objectives, and operational domains (how) fulfil. The organisation shall choose those frameworks that are appropriate to its size and sector.
| Framework | Name | Loma steka | Year | Source |
|---|---|---|---|---|
| COSO ERM | Enterprise Risk Management - Integrating with Strategy and Performance | The company risk management framework at board and senior management level - links strategy, performance and risk. The top layer of the steka (corporate management) that determines the risk appetite of the entire organisation. | 2017 | Open |
| ISO 37000 | Governance of organizations - Guidance | The first international standard for the governance of organisations - purpose, values, supervision and accountability. Defines the governance context at the board level, which includes IT management. | 2021 | Open |
| ISO/IEC 38500 | Governance of IT for the organization | Principles of IT corporate governance with the EDM model (Evaluate - Direct - Monitor). A distinction is made between governance (management - direction and supervision) and management (implementation) - the conceptual basis for COBIT and other strata. | 2024 | Open |
| COBIT 2019 | Governance and Management of Enterprise IT (GEIT) | The integrated IT management framework of the company - aligns business goals with IT goals, distinguishes management from management and other frameworks (ITIL, TOGAF, ISO 27001) as its promoters. The central 'umbrella' layer of the steka. | 2019 | Open |
| ITIL 4 | IT Service Management | IT service management practices - service value system and 34 practices. The operational 'as' service delivery and support; COBIT is used as a facilitator for the management layer. | 2019 | Open |
| ISO/IEC 20000-1 | Service management system requirements | Service Management System (SMS) - formalised, audited equivalent of ITIL practices. Operational services domain standard in the bottom layer of the stack. | 2018 | Open |
| TOGAF 10 | Enterprise Architecture Framework | Company architecture framework with ADM development method - business, data, applications and technology architecture layers. It shall be ensured that the IT solutions are in accordance with the direction set by the management. | 2022 | Open |
| ISO 31000 | Risk management - Guidelines | General framework and process for risk management applicable to the whole organisation. Linking the strategic level of COSO ERM to operational risk management (including information security risk, ISO 27005). | 2018 | Open |
| PMBOK 7 / PRINCE2 | Project and programme management | Management frameworks for projects and programmes - implement governance changes and investments in a controlled way. A layer of supply that realises the goals of architecture and services. | 2021 | Open |
| ISO/IEC 27001 | Information Security Management System (ISMS) | The information security management system to be certified - risk management based controls (annex A). A security domain standard that fits into the governance step and supports the requirements of Article 21 of the NIS2. | 2022 | Open |
| NIST CSF 2.0 | Cybersecurity Framework | Cybersecurity management framework in six functions (Govern, Identity, Protect, Detect, Respond, Recover). The government function connects cyber security with company management - a layer of security in the stack. | 2024 | Open |
| ISO 9001 | Quality Management System | Quality management system with process approach and PDCA. Ensures a consistent quality of processes in all strata - the general governance framework underpinning sectoral systems. | 2015 | Open |