9.1 How Components Work Together

Key Takeaways

  • Holistic approach is applied per objective: all seven components must be present and interacting, not staged as a menu.
  • APO13 Managed Security is the worked example — the same seven-slot walk applies to DSS02 and every other objective.
  • A process scored Established while culture, skills, or information are broken is not a working objective.
  • Name the empty slot when one component is missing; rewriting the process is not the default fix.
  • Capability is a process rating; it is not proof that the objective has been met in practice.
Last updated: August 2026

Quick Answer: The holistic approach principle is now applied, not previewed. For any one objective — this section uses APO13 Managed Security — all seven components must be present and interacting. A process scored Established while culture hides incidents, skills cannot run the stack, or information is missing is not a working objective. That is the exam trap.

Chapters 6 through 8 gave you the inventory and then unpacked each slot. This chapter puts the slots back on one card. The question is no longer “what are the seven names?” It is “can this enterprise actually achieve APO13 Managed Security if one slot is empty?”

An objective is an outcome. APO13 is not “we published a security process.” It is that information-security risk stays inside the enterprise’s risk appetite because the whole system works. The same reading applies to DSS02 Managed Service Requests and Incidents and to the other 38 objectives. The seven-slot card does not shrink because the topic is security, incidents, vendors, or data.

Apply holistic to one named objective

The second governance-system principle said several components of different types must work together. Here the unit of analysis is a single objective, not the whole framework. You do not “implement processes this year and culture next year” for APO13. You assemble a system that can manage security.

Sterling Payments, a mid-size processor, bought a security-process binder and a GRC module after a card-brand finding. Internal audit can tick “process exists.” The CISO still cannot answer four questions the board actually cares about: who may accept residual risk, which policy states the rule, what evidence shows control status, and whether staff will report a near miss. Those four questions are empty organizational structures, principles, policies and frameworks, information, and culture, ethics and behavior. The binder did not fail as a document. The governance system failed as a system.

Use this test on any objective. Name the outcome. Then walk the seven slots. If you cannot say what “good” looks like in a slot, that slot is empty.

What “good” looks like for APO13

The table is the exam picture. Learn the kind of evidence each slot needs. Do not memorize a vendor product list.

ComponentWhat “good” looks like for APO13 Managed Security
ProcessesOrganized practices and activities for directing, planning, implementing, operating, and monitoring information security, with metrics that show whether residual risk stays inside appetite
Organizational structuresA CISO or equivalent with real decision rights, plus a security or risk forum that can accept, reject, or escalate exceptions
Principles, policies and frameworksA published information-security policy, supporting standards, and an exception path that translate the board’s appetite into day-to-day rules — overlaying ISO/IEC 27001 or similar, not replacing them
InformationA living risk register, exception log, control-status reports, and incident metrics the governing body can actually use
Culture, ethics and behaviorPeople report incidents and near misses; shadow IT and “just this once” bypasses are treated as governance failures, not heroics
People, skills and competenciesSecurity architecture, operations, and awareness skills exist in enough depth that the process does not assume experts the enterprise does not have
Services, infrastructure and applicationsIdentity, logging, monitoring, encryption, and ticketing services that actually host the security work

Read across, not down. Processes without a forum have no place to park an exception. A forum without information decides in the dark. Information without skills is a dashboard nobody trusts. Skills without culture will not escalate. Culture without services cannot see or enforce anything. Services without policy become shadow tooling. That chain is holistic applied.

The same walk works for DSS02. A request-and-incident process is “good” only if an on-call structure exists after hours, a severity policy is findable, the status board is populated, staff are not punished for raising Sev-1s, people can use the paging tool, and monitoring is actually in production. You do not need a second framework. You need the same seven slots filled for a different outcome.

Failure modes when one component is missing

Foundation items often give you six healthy slots and one empty one. Name the empty slot. Do not rewrite the process as a reflex.

Missing componentHow APO13 fails in production
ProcessesHeroic firefighting. Security work cannot be repeated, measured, or improved.
Organizational structuresPolicy exists, but nobody has the right to accept residual risk or stop an unsafe release.
Principles, policies and frameworksEngineers invent local rules. Exceptions hide in chat threads.
InformationThe board hears “we are secure” with no register, no exception log, and no trend.
Culture, ethics and behaviorIncidents are buried. The capability score becomes theater.
People, skills and competenciesA SIEM or IAM platform is licensed; nobody can tune it.
Services, infrastructure and applicationsA paper process describes controls the estate cannot host.

Sterling’s assessor later scores the security process at capability 3 Established because activities are defined and organizational assets are referenced. The same week, a developer routes around multifactor authentication “to hit a launch date,” the exception is never logged, and the only person who could read the SIEM left last quarter. That is not a capability-3 objective. It is a process score sitting on three broken slots: culture, information, and skills.

Exam trap: capable process, broken system

COBIT 2019 assesses capability primarily on the process component. That fact is correct and you will use it in the performance-management chapter. The trap is treating that score as proof the objective is met.

If the stem says the process is Established, then asks whether APO13 is achieved, look at the other six components before you agree. A capable process with broken culture, missing skills, or empty information is an incomplete system. The holistic principle is how you refuse the shortcut.

Do not flip the trap the other way either. Empty culture does not mean “capability is a useless idea.” It means capability answered a narrower question than the objective. Section 9.3 will lock that distinction: objective ≠ process ≠ capability level.

How this shows up on the exam

Expect three shapes. First, “which components must support APO13 / DSS02 / any named objective?” The answer is all seven, not “the security ones.” Second, a scenario where one slot is empty — pick the missing component, not a new process rewrite. Third, an assessor who scores the process and declares the objective done. Prefer the answer that keeps capability on the process and still requires the other components for the objective to be met in practice.

You already know the names. This section is the interaction test. If you can walk APO13 across seven slots and name the failure when one is missing, you can do the same walk for any of the 40.

Loading diagram...
APO13 requires all seven components interacting
Test Your Knowledge

Sterling Payments documented APO13 processes and scored them Established. Culture still hides near misses, the SIEM has no skilled operator, and the risk register is empty. What does COBIT 2019 require for the objective?

A
B
C
D
Test Your Knowledge

An assessor scores the APO13 process at capability 3 Established while staff hide incidents and no one can interpret the monitoring service. What is the COBIT 2019 reading?

A
B
C
D
Test Your Knowledge

For APO13 Managed Security, what does “good” look like in the culture, ethics and behavior component?

A
B
C
D