14.1 Performance Management Principles
Key Takeaways
- COBIT Performance Management (CPM) describes how well the governance and management system and its components work, and how they can be improved.
- Five commonly taught CPM principles: simple to understand and use; consistent with the conceptual model; reliable, repeatable, relevant results; flexible for different organizations; supporting multiple assessment types.
- CPM aligns with and extends CMMI. It is not COBIT 5’s ISO/IEC 33000 / SPICE Process Assessment Model.
- Activities can be rated N/P/L/F (Not / Partially / Largely / Fully, citing ISO/IEC 33004) or binary pass/fail.
- COBIT 2019 Foundation does not require a formal assessor certification before you can explain or apply CPM.
Quick Answer: COBIT Performance Management (CPM) describes how well the governance and management system and all of its components work, and how they can be improved toward required capability and maturity. Five commonly taught principles: simple to understand and use; consistent with the conceptual model; reliable, repeatable, relevant results; flexible for different organizations; and supporting multiple assessment types. CPM aligns with and extends CMMI. It is not COBIT 5’s ISO/IEC 33000 / SPICE PAM. Ratings may be N/P/L/F or pass/fail. Foundation does not require a formal assessor certification.
Performance Management is 4% of the 75-question COBIT 2019 Foundation exam — roughly three items. Those items are cheap if you know the definition, the five principles, the CMMI-versus-COBIT-5 contrast, and the two rating styles. They are expensive if you treat CPM as “hire an assessor first” or as a leftover COBIT 5 Process Assessment Model.
Chapter 9 already warned you: capability is a process-primary rating, and an Established process with a broken culture is not a working objective. This chapter is the scheme behind that warning. Chapter 13 introduced MEA01 Managed Performance and Conformance Monitoring as an objective. MEA01 is work you do. CPM is the ruler you use. Do not collapse the ruler into one objective. Chapter 15 will set target capability during design. This section teaches the ruler, not the target.
What CPM is — and what it is not
ISACA’s published purpose statement is the sentence to memorize. CPM evaluates how well the governance and management system and all the components of an enterprise work, and how they can be improved to achieve target levels of process and practice capability and maturity.
Three words in that sentence do exam work:
- System — you are judging the designed EGIT system, not a single control or a single project.
- Components — processes are not the only thing CPM can consider. The conceptual model has seven components. CPM is consistent with that model, so information, structures, culture, skills, and services can enter the performance conversation even though the 0–5 capability scale is taught primarily on the process.
- Improved — CPM is not a one-time badge. Current-state ratings exist so the enterprise can set targets and close gaps.
CPM is not:
- A substitute for the goals cascade. Cascade first (stakeholder needs → enterprise goals → alignment goals → objectives). Then measure whether the selected system is actually performing.
- A requirement that every objective sit at capability level 5.
- Proof that an objective is met just because the process scored Established (Chapter 9’s trap, restated).
- A formal appraisal you must buy before you are allowed to sit Foundation.
- An ISO/IEC 27001-style enterprise certificate you hang on the wall.
Five CPM principles (the list the exam expects)
COBIT 2019 Framework: Introduction and Methodology states that the performance-management scheme is built on a short principle set. Accredited courses (including the ISACA / Learning Tree family) teach the same five ideas. Learn them as a list, then as a refusal of the opposite claim.
| CPM principle | What it means on exam day | The claim that fails |
|---|---|---|
| Simple to understand and use | A board member, a process owner, and an auditor should be able to explain a rating without a secret decoder. | CPM is only for certified appraisers. |
| Consistent with the conceptual model | Ratings hang on the same objectives, components, and relationships you already learned. Performance of processes and other component types can be managed. | Invent a second model just for scoring. |
| Reliable, repeatable, relevant results | Two competent raters, given the same evidence, should land near the same result, and the result should matter to enterprise goals. | Score from opinion with no evidence trail. |
| Flexible for different organizations | Priorities, size, risk, and regulation change the target, not the ruler. | One mandatory target profile for every enterprise. |
| Supporting multiple assessment types | The same scheme supports a hallway self-assessment, an internal audit, and a formal appraisal. | Only a certified external assessment “counts.” |
A supporting idea is often folded into “consistent with the conceptual model”: CPM should let you manage performance of all types of governance-system components, not processes alone. If a stem says culture or information can be considered, that is still CPM. If a stem says only processes exist in 2019, that is COBIT-5 hangover thinking.
Use the five-row table as your memory device. If a question asks “which statement is a CPM principle?”, match the left column. If it asks “which statement violates CPM?”, match the right column.
CMMI alignment — and the COBIT 5 contrast
COBIT 2019 aligns with and extends CMMI (ISACA materials cite CMMI V2.0 / Development V2.02). The 0–5 capability idea, the incomplete-through-optimizing ladder, and the split between process capability and focus-area maturity come from that family. “Extends” matters: COBIT applies the idea across a governance system and its components, not only to a software-engineering process set.
COBIT 5 measured process capability against ISO/IEC 33000 (the successor to ISO/IEC 15504) and the SPICE Process Assessment Model (PAM). That is a different scheme. ISACA’s own comparison articles say it in one line: performance management in COBIT 2019 is based on the CMMI performance-management scheme instead of ISO/IEC 33000.
Exam move:
- Stem mentions CMMI, 0–5, capability and maturity as the 2019 model → CPM.
- Stem mentions ISO/IEC 33000, SPICE, or PAM as the scheme → COBIT 5, or a distractor.
- Stem mentions ISO/IEC 33004 only as the source of N/P/L/F achievement ratings → still valid in 2019. The rating labels were reused; the scheme changed.
Do not write “COBIT 2019 banned N/P/L/F.” Do not write “COBIT 2019 is still a SPICE PAM.” Both fail.
How activities get rated
Process activities (Chapter 7) are associated with capability levels. When you assess, you rate those activities, then decide whether a capability level has been achieved. The range of ratings depends on why you are assessing.
Two official rating styles:
Binary pass/fail. Common in formal methods that lead toward independent certification. An activity either meets the criterion or it does not.
N / P / L / F, referenced in ISACA materials citing ISO/IEC 33004:
| Rating | Meaning | Typical achievement band |
|---|---|---|
| Not (N) | The capability level is not achieved in any meaningful way | Less than 15% |
| Partially (P) | Some evidence; large gaps | 15% to 50% |
| Largely (L) | The level is mostly achieved | 50% to 85% |
| Fully (F) | The level is achieved | More than 85% |
ISACA is explicit that Fully remains a judgment call, but one that can be substantiated by examining process activities, process goals, or other component good practices. Less formal, improvement-oriented assessments usually prefer the four-point scale because it shows how close a practice is. Formal certification-style work often prefers pass/fail. CPM’s “multiple assessment types” principle is why both styles exist.
You do not need to run a full assessor engagement to answer Foundation items about these scales. You need to recognize the names, the bands, and the fact that both styles are allowed.
Scenario: Harborline Mutual wants a “COBIT certificate” on the wall
Harborline Mutual is a regional insurer. The CIO heard that “COBIT 2019 has a maturity model” and briefed the board as follows:
- “We cannot discuss capability until we hire a COBIT Certified Assessor.”
- “We will use the COBIT 5 ISO/IEC 33000 SPICE PAM because that is the official assessment standard.”
- “Only processes count. Culture and information are out of scope for performance.”
- “Once we are scored, we will be COBIT-certified, the way we are ISO/IEC 27001-certified.”
Every sentence is a Foundation trap.
Harborline can run a self-assessment tomorrow. CPM supports multiple assessment types. A Certified Assessor is a real ISACA credential for people who lead formal capability assessments. It is not a prerequisite for Foundation, and it is not a gate that locks the five principles until a consultant arrives.
Harborline should use the 2019 CMMI-aligned scheme, not the COBIT 5 PAM, as the model of how well the system works. The firm may still rate activities N/P/L/F; that does not secretly put them back on ISO/IEC 33000 as the scheme.
Harborline should expect CPM to stay consistent with the conceptual model, which means components other than processes can be considered. Scoring only the DSS02 binder while incident culture hides near-misses is the Chapter 9 failure mode wearing a new hat.
And there is no wall plaque called “COBIT-certified enterprise” that Foundation asks you to chase. COBIT is a governance framework you adopt and tailor. ISO/IEC 27001 is a certifiable management system. Mixing those two is the umbrella-framework error from Chapter 3, restated in performance language.
Exam traps in this section
Trap 1 — Foundation requires assessor certification.
False. Assessor is a different credential. CPM is designed to be simple and to support self-assessments through formal appraisals. You can sit Foundation, explain CPM, and help a self-assessment without being a Certified Assessor.
Trap 2 — 2019 still uses the ISO/IEC 33000 SPICE PAM as its performance scheme.
False. That is COBIT 5. 2019 aligns with and extends CMMI. N/P/L/F ratings citing ISO/IEC 33004 can still be used to score activities.
Trap 3 — CPM is only a process score.
Incomplete. Capability is taught primarily on the process, but the CPM definition and the “consistent with the conceptual model” principle cover the system and all components. Maturity, in the next section, sits on focus areas, not on a single process.
Trap 4 — CPM replaces design and the cascade.
False. Design (Chapter 15) sets which objectives matter and what target capability they should reach. The cascade (Chapter 10) says why. CPM says how well the resulting system is actually performing.
When a stem mixes these ideas, separate ruler (CPM), target (design), and purpose (cascade). That split is most of the 4% domain.
What does COBIT Performance Management (CPM) describe in COBIT 2019?
Which list matches the COBIT Performance Management principles commonly taught for Foundation?
Harborline Mutual’s CIO says no one may discuss capability until a Certified Assessor is hired, and that the firm must keep the COBIT 5 ISO/IEC 33000 SPICE PAM as the only allowed method. What does Foundation actually teach?