5.5 COBIT 2019 Governance System, CIS Controls v8.1 & PCI DSS Requirements
Key Takeaways
- COBIT 2019 defines six governance system principles, three governance framework principles, and seven components of a governance system; the seven components were called enablers in COBIT 5.
- The seven COBIT 2019 components are processes; organizational structures; principles, policies and procedures; information; culture, ethics and behavior; people, skills and competencies; and services, infrastructure and applications.
- CIS Controls v8.1 contains 18 Controls and 153 Safeguards prioritized into three Implementation Groups - IG1 with 56 Safeguards of essential cyber hygiene, IG2 adding 74 more for 130, and IG3 comprising all 153.
- PCI DSS organizes 12 requirements under 6 goals and is a contractual card-brand standard rather than a statute, scoped to the cardholder data environment.
- Sensitive authentication data - full track data, the card verification code, and the PIN block - must never be stored after authorization even in encrypted form, while a stored primary account number must be rendered unreadable and masked to at most the first six and last four digits on display.
COBIT 2019 Governance System, CIS Controls v8.1 & PCI DSS
Quick Answer: Three closed-list recall tasks from Area II, Group A. The blueprint asks candidates to "recall the governance system principles, governance framework principles and the components of a governance system according to COBIT 2019," to "recall the overview of each CIS Control," and to "recall the requirements of the PCI DSS." All three are memorization tasks with a defined, finite answer — six, three and seven for COBIT; eighteen for CIS; six goals and twelve requirements for PCI DSS.
1. COBIT 2019: Principles and Components
COBIT 2019 restructured what COBIT 5 called "principles" and "enablers" into three distinct sets. Candidates must keep them apart, because the exam will mix them.
The Six Governance System Principles
These describe what a governance system for enterprise information and technology must do.
| # | Principle | What It Means |
|---|---|---|
| 1 | Provide stakeholder value | Every governance system exists to create value for stakeholders by balancing benefits, risk and resource use |
| 2 | Holistic approach | Governance is built from several interacting components, not from processes alone |
| 3 | Dynamic governance system | Any change to a design factor must trigger reconsideration of the whole system — governance is not set once |
| 4 | Governance distinct from management | Governance and management have different activities, different structures and different purposes |
| 5 | Tailored to enterprise needs | The system is customized using design factors, not adopted wholesale off the shelf |
| 6 | End-to-end governance system | Governance covers all information and technology across the enterprise, not just the IT department |
Two of these are new in COBIT 2019 relative to COBIT 5: dynamic governance system and tailored to enterprise needs.
The Three Governance Framework Principles
These describe what a good framework — the published body of guidance itself — must be.
- Based on a conceptual model, identifying key components and their relationships to maximize consistency and support automation.
- Open and flexible, allowing new content to be added while preserving integrity and consistency.
- Aligned to major related standards, frameworks and regulations — ITIL, ISO/IEC 27001, TOGAF, NIST, COSO and others.
The Seven Components of a Governance System
Renamed from COBIT 5's "enablers." Each of the 40 governance and management objectives is achieved by working all seven, not by writing a process document alone.
- Processes — the practices and activities that produce outputs supporting the objective.
- Organizational structures — the decision-making entities: the board, an IT steering committee, an architecture board.
- Principles, policies and procedures — translating desired behavior into day-to-day guidance.
- Information — the data produced and used by the enterprise; governance is pervasive because information is.
- Culture, ethics and behavior — the human factor, and the component most often ignored in practice.
- People, skills and competencies — the capability required for good decisions and correct execution.
- Services, infrastructure and applications — the technology that delivers the processing.
Exam trap: Mapping a control failure to only one component. If a change management objective fails, COBIT's holistic-approach principle says to examine all seven: was the process defined (1), was there a change advisory board (2), was there a written policy (3), was change data captured (4), did the culture tolerate shortcuts (5), were the people trained (6), and did the tooling support the workflow (7)?
2. The Eighteen CIS Controls (v8.1)
The Center for Internet Security publishes a prioritized set of defensive actions. Version 8 reduced the count from 20 to 18 and reorganized them around activities and tasks rather than around who owns the device, which is what made them usable in cloud and remote-work environments. Version 8.1 refined wording and mappings without changing the structure. There are 153 Safeguards across the 18 Controls.
| # | CIS Control | Overview: Why It Is Critical |
|---|---|---|
| 1 | Inventory and Control of Enterprise Assets | You cannot defend what you do not know you own; unmanaged assets are the attacker's entry point |
| 2 | Inventory and Control of Software Assets | Unauthorized and unpatched software is the software supply of an attack; only known software should execute |
| 3 | Data Protection | Identify, classify, retain and dispose of data securely; the data is the actual target |
| 4 | Secure Configuration of Enterprise Assets and Software | Default configurations favor usability over security; hardening removes the easy path |
| 5 | Account Management | Manage the lifecycle of accounts and credentials; dormant and orphaned accounts are unmonitored doors |
| 6 | Access Control Management | Grant, revoke and review the right of access — the enforcement half of account management |
| 7 | Continuous Vulnerability Management | Continuously assess and remediate; the window between disclosure and exploitation keeps shrinking |
| 8 | Audit Log Management | Collect, alert on, review and retain logs; without logs an incident cannot be detected or reconstructed |
| 9 | Email and Web Browser Protections | Email and the browser are the two channels where users meet attacker-controlled content |
| 10 | Malware Defenses | Prevent or control installation and execution of malicious applications, code and scripts |
| 11 | Data Recovery | Establish and test recovery practices sufficient to restore in-scope assets to a pre-incident state |
| 12 | Network Infrastructure Management | Actively manage network devices to prevent attackers from exploiting vulnerable services and access points |
| 13 | Network Monitoring and Defense | Operate processes and tooling for comprehensive network monitoring and defense against threats |
| 14 | Security Awareness and Skills Training | Build the workforce's security awareness and skills to reduce risk from human action |
| 15 | Service Provider Management | Evaluate service providers who hold sensitive data or run critical platforms, to ensure they protect them |
| 16 | Application Software Security | Manage the security lifecycle of developed, hosted and acquired software to prevent and remediate weaknesses |
| 17 | Incident Response Management | Establish the program — plans, roles, training, communications — to detect and respond to an attack |
| 18 | Penetration Testing | Test the effectiveness and resiliency of controls by simulating an attacker's objectives and actions |
Implementation Groups
Safeguards are prioritized into three Implementation Groups, and every enterprise starts at IG1:
- IG1 — essential cyber hygiene. 56 Safeguards. A small or medium enterprise with limited security expertise, whose principal concern is staying operational.
- IG2. Adds 74 Safeguards, for a running total of 130. An enterprise with multiple departments and differing risk profiles, and staff dedicated to infrastructure and security.
- IG3. All 153 Safeguards. An enterprise with security specialists and sensitive data subject to regulatory oversight, defending against targeted attacks.
3. PCI DSS: Six Goals, Twelve Requirements
The Payment Card Industry Data Security Standard is a contractual standard imposed by the card brands on any entity that stores, processes or transmits cardholder data — not a statute. Scope is the cardholder data environment (CDE): the systems that touch account data plus anything connected to them.
The Structure
| Goal | Requirements |
|---|---|
| Build and maintain a secure network and systems | 1. Install and maintain network security controls<br/>2. Apply secure configurations to all system components |
| Protect account data | 3. Protect stored account data<br/>4. Protect cardholder data with strong cryptography during transmission over open, public networks |
| Maintain a vulnerability management program | 5. Protect all systems and networks from malicious software<br/>6. Develop and maintain secure systems and software |
| Implement strong access control measures | 7. Restrict access to system components and cardholder data by business need to know<br/>8. Identify users and authenticate access to system components<br/>9. Restrict physical access to cardholder data |
| Regularly monitor and test networks | 10. Log and monitor all access to system components and cardholder data<br/>11. Test security of systems and networks regularly |
| Maintain an information security policy | 12. Support information security with organizational policies and programs |
What Changed in v4.x, and Why It Matters
- "Firewalls" became "network security controls" in Requirement 1, so cloud security groups and virtual appliances count.
- A customized approach was introduced alongside the traditional defined approach: an entity may meet a requirement's stated objective with a different control, provided it performs and documents a targeted risk analysis and the assessor validates the design. This is the single largest structural change since the standard's creation.
- Roles and responsibilities must be documented and assigned for every requirement.
The Data Rules a CPA Must Know
- Sensitive authentication data — the full magnetic-stripe or chip track data, the card verification code (CVV/CVC/CID), and the PIN or PIN block — must not be stored after authorization, even encrypted. This is the brightest line in the standard.
- The primary account number (PAN) may be stored only when there is a documented business need, and it must be rendered unreadable — one-way hash of the full PAN, truncation, index tokens, or strong cryptography with associated key management.
- When the PAN is displayed, it must be masked so that at most the first six and last four digits are visible, unless the viewer has a documented business need for more.
- Tokenization removes systems from scope. If cardholder data is replaced with a token at the perimeter, the downstream reporting databases and ERP never hold account data and fall outside the CDE — which is the most common and most effective scope-reduction strategy.
- Validation depends on the entity's card-brand merchant or service provider level: smaller merchants complete a Self-Assessment Questionnaire (SAQ); larger ones undergo an on-site assessment by a Qualified Security Assessor producing a Report on Compliance (ROC).
Framing for the exam: PCI DSS is prescriptive, contractual and pass/fail at a point in time. The Trust Services Criteria, by contrast, are outcome-based and examined by a CPA over a period. A service organization can be PCI DSS compliant and still receive a qualified SOC 2 opinion, and vice versa; they answer different questions.
Under COBIT 2019, which set correctly identifies the seven components of a governance system?
A payment processor stores the card verification code alongside the primary account number so that recurring charges can be re-authorized without contacting the cardholder. The processor encrypts both fields with AES-256 and restricts database access to two administrators. How does PCI DSS treat this practice?
A 60-employee regional distributor with no dedicated security staff asks which CIS Safeguards it should implement first. What does the CIS Controls framework recommend?