9.1 How Components Work Together
Key Takeaways
- Holistic approach is applied per objective: all seven components must be present and interacting, not staged as a menu.
- APO13 Managed Security is the worked example — the same seven-slot walk applies to DSS02 and every other objective.
- A process scored Established while culture, skills, or information are broken is not a working objective.
- Name the empty slot when one component is missing; rewriting the process is not the default fix.
- Capability is a process rating; it is not proof that the objective has been met in practice.
Quick Answer: The holistic approach principle is now applied, not previewed. For any one objective — this section uses APO13 Managed Security — all seven components must be present and interacting. A process scored Established while culture hides incidents, skills cannot run the stack, or information is missing is not a working objective. That is the exam trap.
Chapters 6 through 8 gave you the inventory and then unpacked each slot. This chapter puts the slots back on one card. The question is no longer “what are the seven names?” It is “can this enterprise actually achieve APO13 Managed Security if one slot is empty?”
An objective is an outcome. APO13 is not “we published a security process.” It is that information-security risk stays inside the enterprise’s risk appetite because the whole system works. The same reading applies to DSS02 Managed Service Requests and Incidents and to the other 38 objectives. The seven-slot card does not shrink because the topic is security, incidents, vendors, or data.
Apply holistic to one named objective
The second governance-system principle said several components of different types must work together. Here the unit of analysis is a single objective, not the whole framework. You do not “implement processes this year and culture next year” for APO13. You assemble a system that can manage security.
Sterling Payments, a mid-size processor, bought a security-process binder and a GRC module after a card-brand finding. Internal audit can tick “process exists.” The CISO still cannot answer four questions the board actually cares about: who may accept residual risk, which policy states the rule, what evidence shows control status, and whether staff will report a near miss. Those four questions are empty organizational structures, principles, policies and frameworks, information, and culture, ethics and behavior. The binder did not fail as a document. The governance system failed as a system.
Use this test on any objective. Name the outcome. Then walk the seven slots. If you cannot say what “good” looks like in a slot, that slot is empty.
What “good” looks like for APO13
The table is the exam picture. Learn the kind of evidence each slot needs. Do not memorize a vendor product list.
| Component | What “good” looks like for APO13 Managed Security |
|---|---|
| Processes | Organized practices and activities for directing, planning, implementing, operating, and monitoring information security, with metrics that show whether residual risk stays inside appetite |
| Organizational structures | A CISO or equivalent with real decision rights, plus a security or risk forum that can accept, reject, or escalate exceptions |
| Principles, policies and frameworks | A published information-security policy, supporting standards, and an exception path that translate the board’s appetite into day-to-day rules — overlaying ISO/IEC 27001 or similar, not replacing them |
| Information | A living risk register, exception log, control-status reports, and incident metrics the governing body can actually use |
| Culture, ethics and behavior | People report incidents and near misses; shadow IT and “just this once” bypasses are treated as governance failures, not heroics |
| People, skills and competencies | Security architecture, operations, and awareness skills exist in enough depth that the process does not assume experts the enterprise does not have |
| Services, infrastructure and applications | Identity, logging, monitoring, encryption, and ticketing services that actually host the security work |
Read across, not down. Processes without a forum have no place to park an exception. A forum without information decides in the dark. Information without skills is a dashboard nobody trusts. Skills without culture will not escalate. Culture without services cannot see or enforce anything. Services without policy become shadow tooling. That chain is holistic applied.
The same walk works for DSS02. A request-and-incident process is “good” only if an on-call structure exists after hours, a severity policy is findable, the status board is populated, staff are not punished for raising Sev-1s, people can use the paging tool, and monitoring is actually in production. You do not need a second framework. You need the same seven slots filled for a different outcome.
Failure modes when one component is missing
Foundation items often give you six healthy slots and one empty one. Name the empty slot. Do not rewrite the process as a reflex.
| Missing component | How APO13 fails in production |
|---|---|
| Processes | Heroic firefighting. Security work cannot be repeated, measured, or improved. |
| Organizational structures | Policy exists, but nobody has the right to accept residual risk or stop an unsafe release. |
| Principles, policies and frameworks | Engineers invent local rules. Exceptions hide in chat threads. |
| Information | The board hears “we are secure” with no register, no exception log, and no trend. |
| Culture, ethics and behavior | Incidents are buried. The capability score becomes theater. |
| People, skills and competencies | A SIEM or IAM platform is licensed; nobody can tune it. |
| Services, infrastructure and applications | A paper process describes controls the estate cannot host. |
Sterling’s assessor later scores the security process at capability 3 Established because activities are defined and organizational assets are referenced. The same week, a developer routes around multifactor authentication “to hit a launch date,” the exception is never logged, and the only person who could read the SIEM left last quarter. That is not a capability-3 objective. It is a process score sitting on three broken slots: culture, information, and skills.
Exam trap: capable process, broken system
COBIT 2019 assesses capability primarily on the process component. That fact is correct and you will use it in the performance-management chapter. The trap is treating that score as proof the objective is met.
If the stem says the process is Established, then asks whether APO13 is achieved, look at the other six components before you agree. A capable process with broken culture, missing skills, or empty information is an incomplete system. The holistic principle is how you refuse the shortcut.
Do not flip the trap the other way either. Empty culture does not mean “capability is a useless idea.” It means capability answered a narrower question than the objective. Section 9.3 will lock that distinction: objective ≠ process ≠ capability level.
How this shows up on the exam
Expect three shapes. First, “which components must support APO13 / DSS02 / any named objective?” The answer is all seven, not “the security ones.” Second, a scenario where one slot is empty — pick the missing component, not a new process rewrite. Third, an assessor who scores the process and declares the objective done. Prefer the answer that keeps capability on the process and still requires the other components for the objective to be met in practice.
You already know the names. This section is the interaction test. If you can walk APO13 across seven slots and name the failure when one is missing, you can do the same walk for any of the 40.
Sterling Payments documented APO13 processes and scored them Established. Culture still hides near misses, the SIEM has no skilled operator, and the risk register is empty. What does COBIT 2019 require for the objective?
An assessor scores the APO13 process at capability 3 Established while staff hide incidents and no one can interpret the monitoring service. What is the COBIT 2019 reading?
For APO13 Managed Security, what does “good” look like in the culture, ethics and behavior component?