nerdexam
CompTIA

CAS-005 · Question #193

A company needs to increase the maturity level for the cybersecurity department's governance structure. To achieve this goal, the company wants to implement a set of controls that can be used as part

The correct answer is D. COBIT. A company seeking to enhance its cybersecurity department's governance maturity and integrate controls into operational procedures should adopt a framework focused on IT governance and management.

Submitted by daniela_cl· Mar 6, 2026Governance, Risk, and Compliance

Question

A company needs to increase the maturity level for the cybersecurity department's governance structure. To achieve this goal, the company wants to implement a set of controls that can be used as part of the standard operational procedures and policies within the department and the company. Which of the following frameworks best aligns with this goal?

Options

  • AITIL
  • BCIS
  • CCOSO
  • DCOBIT

How the community answered

(23 responses)
  • B
    4% (1)
  • C
    9% (2)
  • D
    87% (20)

Why each option

A company seeking to enhance its cybersecurity department's governance maturity and integrate controls into operational procedures should adopt a framework focused on IT governance and management.

AITIL

ITIL (Information Technology Infrastructure Library) primarily focuses on IT service management, not holistic cybersecurity governance structure and control implementation at an enterprise level.

BCIS

CIS (Center for Internet Security) focuses on specific technical security controls and benchmarks, rather than a broad governance framework for departmental maturity.

CCOSO

COSO (Committee of Sponsoring Organizations of the Treadway Commission) is a framework for enterprise risk management and internal control, which is broader than, and not solely focused on, IT or cybersecurity governance maturity.

DCOBITCorrect

COBIT (Control Objectives for Information and Related Technologies) is a comprehensive framework that provides principles, practices, and tools for enterprise IT governance and management, directly supporting the implementation of controls for standard operational procedures and policies to increase cybersecurity governance maturity.

Concept tested: Cybersecurity governance frameworks and maturity models

Source: https://www.isaca.org/resources/cobit/cobit-2019

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice