5.5 COBIT 2019 Governance System, CIS Controls v8.1 & PCI DSS Requirements

Key Takeaways

  • COBIT 2019 defines six governance system principles, three governance framework principles, and seven components of a governance system; the seven components were called enablers in COBIT 5.
  • The seven COBIT 2019 components are processes; organizational structures; principles, policies and procedures; information; culture, ethics and behavior; people, skills and competencies; and services, infrastructure and applications.
  • CIS Controls v8.1 contains 18 Controls and 153 Safeguards prioritized into three Implementation Groups - IG1 with 56 Safeguards of essential cyber hygiene, IG2 adding 74 more for 130, and IG3 comprising all 153.
  • PCI DSS organizes 12 requirements under 6 goals and is a contractual card-brand standard rather than a statute, scoped to the cardholder data environment.
  • Sensitive authentication data - full track data, the card verification code, and the PIN block - must never be stored after authorization even in encrypted form, while a stored primary account number must be rendered unreadable and masked to at most the first six and last four digits on display.
Last updated: September 2026

COBIT 2019 Governance System, CIS Controls v8.1 & PCI DSS

Quick Answer: Three closed-list recall tasks from Area II, Group A. The blueprint asks candidates to "recall the governance system principles, governance framework principles and the components of a governance system according to COBIT 2019," to "recall the overview of each CIS Control," and to "recall the requirements of the PCI DSS." All three are memorization tasks with a defined, finite answer — six, three and seven for COBIT; eighteen for CIS; six goals and twelve requirements for PCI DSS.


1. COBIT 2019: Principles and Components

COBIT 2019 restructured what COBIT 5 called "principles" and "enablers" into three distinct sets. Candidates must keep them apart, because the exam will mix them.

The Six Governance System Principles

These describe what a governance system for enterprise information and technology must do.

#PrincipleWhat It Means
1Provide stakeholder valueEvery governance system exists to create value for stakeholders by balancing benefits, risk and resource use
2Holistic approachGovernance is built from several interacting components, not from processes alone
3Dynamic governance systemAny change to a design factor must trigger reconsideration of the whole system — governance is not set once
4Governance distinct from managementGovernance and management have different activities, different structures and different purposes
5Tailored to enterprise needsThe system is customized using design factors, not adopted wholesale off the shelf
6End-to-end governance systemGovernance covers all information and technology across the enterprise, not just the IT department

Two of these are new in COBIT 2019 relative to COBIT 5: dynamic governance system and tailored to enterprise needs.

The Three Governance Framework Principles

These describe what a good framework — the published body of guidance itself — must be.

  1. Based on a conceptual model, identifying key components and their relationships to maximize consistency and support automation.
  2. Open and flexible, allowing new content to be added while preserving integrity and consistency.
  3. Aligned to major related standards, frameworks and regulations — ITIL, ISO/IEC 27001, TOGAF, NIST, COSO and others.

The Seven Components of a Governance System

Renamed from COBIT 5's "enablers." Each of the 40 governance and management objectives is achieved by working all seven, not by writing a process document alone.

  1. Processes — the practices and activities that produce outputs supporting the objective.
  2. Organizational structures — the decision-making entities: the board, an IT steering committee, an architecture board.
  3. Principles, policies and procedures — translating desired behavior into day-to-day guidance.
  4. Information — the data produced and used by the enterprise; governance is pervasive because information is.
  5. Culture, ethics and behavior — the human factor, and the component most often ignored in practice.
  6. People, skills and competencies — the capability required for good decisions and correct execution.
  7. Services, infrastructure and applications — the technology that delivers the processing.

Exam trap: Mapping a control failure to only one component. If a change management objective fails, COBIT's holistic-approach principle says to examine all seven: was the process defined (1), was there a change advisory board (2), was there a written policy (3), was change data captured (4), did the culture tolerate shortcuts (5), were the people trained (6), and did the tooling support the workflow (7)?


2. The Eighteen CIS Controls (v8.1)

The Center for Internet Security publishes a prioritized set of defensive actions. Version 8 reduced the count from 20 to 18 and reorganized them around activities and tasks rather than around who owns the device, which is what made them usable in cloud and remote-work environments. Version 8.1 refined wording and mappings without changing the structure. There are 153 Safeguards across the 18 Controls.

#CIS ControlOverview: Why It Is Critical
1Inventory and Control of Enterprise AssetsYou cannot defend what you do not know you own; unmanaged assets are the attacker's entry point
2Inventory and Control of Software AssetsUnauthorized and unpatched software is the software supply of an attack; only known software should execute
3Data ProtectionIdentify, classify, retain and dispose of data securely; the data is the actual target
4Secure Configuration of Enterprise Assets and SoftwareDefault configurations favor usability over security; hardening removes the easy path
5Account ManagementManage the lifecycle of accounts and credentials; dormant and orphaned accounts are unmonitored doors
6Access Control ManagementGrant, revoke and review the right of access — the enforcement half of account management
7Continuous Vulnerability ManagementContinuously assess and remediate; the window between disclosure and exploitation keeps shrinking
8Audit Log ManagementCollect, alert on, review and retain logs; without logs an incident cannot be detected or reconstructed
9Email and Web Browser ProtectionsEmail and the browser are the two channels where users meet attacker-controlled content
10Malware DefensesPrevent or control installation and execution of malicious applications, code and scripts
11Data RecoveryEstablish and test recovery practices sufficient to restore in-scope assets to a pre-incident state
12Network Infrastructure ManagementActively manage network devices to prevent attackers from exploiting vulnerable services and access points
13Network Monitoring and DefenseOperate processes and tooling for comprehensive network monitoring and defense against threats
14Security Awareness and Skills TrainingBuild the workforce's security awareness and skills to reduce risk from human action
15Service Provider ManagementEvaluate service providers who hold sensitive data or run critical platforms, to ensure they protect them
16Application Software SecurityManage the security lifecycle of developed, hosted and acquired software to prevent and remediate weaknesses
17Incident Response ManagementEstablish the program — plans, roles, training, communications — to detect and respond to an attack
18Penetration TestingTest the effectiveness and resiliency of controls by simulating an attacker's objectives and actions

Implementation Groups

Safeguards are prioritized into three Implementation Groups, and every enterprise starts at IG1:

  • IG1 — essential cyber hygiene. 56 Safeguards. A small or medium enterprise with limited security expertise, whose principal concern is staying operational.
  • IG2. Adds 74 Safeguards, for a running total of 130. An enterprise with multiple departments and differing risk profiles, and staff dedicated to infrastructure and security.
  • IG3. All 153 Safeguards. An enterprise with security specialists and sensitive data subject to regulatory oversight, defending against targeted attacks.

3. PCI DSS: Six Goals, Twelve Requirements

The Payment Card Industry Data Security Standard is a contractual standard imposed by the card brands on any entity that stores, processes or transmits cardholder data — not a statute. Scope is the cardholder data environment (CDE): the systems that touch account data plus anything connected to them.

The Structure

GoalRequirements
Build and maintain a secure network and systems1. Install and maintain network security controls<br/>2. Apply secure configurations to all system components
Protect account data3. Protect stored account data<br/>4. Protect cardholder data with strong cryptography during transmission over open, public networks
Maintain a vulnerability management program5. Protect all systems and networks from malicious software<br/>6. Develop and maintain secure systems and software
Implement strong access control measures7. Restrict access to system components and cardholder data by business need to know<br/>8. Identify users and authenticate access to system components<br/>9. Restrict physical access to cardholder data
Regularly monitor and test networks10. Log and monitor all access to system components and cardholder data<br/>11. Test security of systems and networks regularly
Maintain an information security policy12. Support information security with organizational policies and programs

What Changed in v4.x, and Why It Matters

  • "Firewalls" became "network security controls" in Requirement 1, so cloud security groups and virtual appliances count.
  • A customized approach was introduced alongside the traditional defined approach: an entity may meet a requirement's stated objective with a different control, provided it performs and documents a targeted risk analysis and the assessor validates the design. This is the single largest structural change since the standard's creation.
  • Roles and responsibilities must be documented and assigned for every requirement.

The Data Rules a CPA Must Know

  • Sensitive authentication data — the full magnetic-stripe or chip track data, the card verification code (CVV/CVC/CID), and the PIN or PIN block — must not be stored after authorization, even encrypted. This is the brightest line in the standard.
  • The primary account number (PAN) may be stored only when there is a documented business need, and it must be rendered unreadable — one-way hash of the full PAN, truncation, index tokens, or strong cryptography with associated key management.
  • When the PAN is displayed, it must be masked so that at most the first six and last four digits are visible, unless the viewer has a documented business need for more.
  • Tokenization removes systems from scope. If cardholder data is replaced with a token at the perimeter, the downstream reporting databases and ERP never hold account data and fall outside the CDE — which is the most common and most effective scope-reduction strategy.
  • Validation depends on the entity's card-brand merchant or service provider level: smaller merchants complete a Self-Assessment Questionnaire (SAQ); larger ones undergo an on-site assessment by a Qualified Security Assessor producing a Report on Compliance (ROC).

Framing for the exam: PCI DSS is prescriptive, contractual and pass/fail at a point in time. The Trust Services Criteria, by contrast, are outcome-based and examined by a CPA over a period. A service organization can be PCI DSS compliant and still receive a qualified SOC 2 opinion, and vice versa; they answer different questions.

Test Your Knowledge

Under COBIT 2019, which set correctly identifies the seven components of a governance system?

A
B
C
D
Test Your Knowledge

A payment processor stores the card verification code alongside the primary account number so that recurring charges can be re-authorized without contacting the cardholder. The processor encrypts both fields with AES-256 and restricts database access to two administrators. How does PCI DSS treat this practice?

A
B
C
D
Test Your Knowledge

A 60-employee regional distributor with no dedicated security staff asks which CIS Safeguards it should implement first. What does the CIS Controls framework recommend?

A
B
C
D