COBIT 2019 Cyber Risk Governance Training Course
| Course code | SD-CS-058 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding which risks require executive action, who owns treatment decisions, or how security priorities support enterprise objectives. This course addresses that gap using COBIT 2019: a governance framework for connecting cyber risk decisions to business goals, risk appetite, assurance requirements and accountable roles. Participants learn to move beyond control checklists and present cyber risk in terms that boards, executives, auditors and business owners can act upon.
The course covers the COBIT 2019 governance system, design factors, goals cascade, governance and management objectives, and performance management approach. Participants work in detail with EDM03 Ensure Risk Optimization, APO12 Managed Risk, APO13 Managed Security, DSS05 Managed Security Services and MEA02 Managed Internal Control. They practise selecting relevant objectives, defining decision rights, documenting risk scenarios, setting risk appetite thresholds, assigning ownership, establishing key risk indicators and designing reporting for management and governance bodies. Practical mappings to NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022 show how COBIT can govern existing security programmes rather than replace them.
Instructor-led briefings are combined with facilitated design workshops, cyber risk case studies and team reviews of realistic governance artefacts. Throughout the week, participants build a Cyber Risk Governance Blueprint for a sample organisation or their own environment. The completed blueprint includes a goals cascade, selected COBIT objectives, risk appetite statements, a RACI matrix, KRIs, reporting cadence and a phased implementation roadmap. This makes the course particularly valuable for professionals expected to establish, improve or assure cyber risk governance across business, technology and security functions.
Course objectives
By the end of this course, participants will be able to:
- Apply the COBIT 2019 goals cascade to connect enterprise objectives, alignment goals and cyber risk priorities
- Select and justify COBIT 2019 governance and management objectives for a defined cyber risk context
- Design a cyber risk governance system using COBIT design factors and governance system components
- Define decision rights and accountability through a RACI matrix for risk optimisation and managed security
- Construct cyber risk scenarios with threat, vulnerability, impact, likelihood and treatment information
- Set risk appetite statements, tolerance thresholds and key risk indicators for executive cyber risk reporting
- Assess the performance of selected COBIT objectives using capability levels, practices and supporting activities
- Produce a phased Cyber Risk Governance Blueprint with target-state controls, metrics and implementation actions
Benefits of attending
For you
- Gain a practical method for explaining cyber risk decisions through enterprise goals, risk appetite and accountable ownership
- Build confidence selecting COBIT objectives such as EDM03, APO12 and APO13 for real security governance issues
- Create governance artefacts that demonstrate capability in risk reporting, RACI design and control oversight
- Strengthen credibility with executives and auditors by using COBIT 2019 terminology and structured governance evidence
- Prepare to contribute to COBIT-based GRC, cyber risk, internal audit and security leadership assignments
For your organisation
- Establish clearer accountability for cyber risk acceptance, treatment decisions and security control ownership
- Improve board and executive reporting through defined risk appetite thresholds, KRIs and reporting cadence
- Focus security investment on COBIT objectives that directly support enterprise goals and priority risk scenarios
- Reduce duplicated governance effort by mapping existing NIST CSF and ISO/IEC 27001 activities into a COBIT structure
- Create an actionable roadmap for improving cyber risk governance, assurance and performance monitoring
Target competencies
Who should attend
- Cybersecurity Managers — who must translate security risks and investments into accountable governance decisions
- Information Security Officers — who need to align security management activities with enterprise risk appetite
- IT Risk Managers — who design risk assessment, treatment and reporting processes across technology services
- GRC Managers and Analysts — who map controls, policies and assurance evidence to a recognised governance framework
- IT Governance Managers — who establish decision rights, performance measures and governance reporting for digital risk
- Internal Auditors — who assess whether cyber risk oversight, control ownership and monitoring arrangements are effective
Requirements and prerequisites
Participants should understand basic information-security concepts such as assets, threats, vulnerabilities, controls, incidents and risk treatment. Familiarity with a risk register, security policy, ISO/IEC 27001, NIST CSF, IT service management or internal audit will help participants relate the exercises to their workplace, but is not mandatory. No prior COBIT certification, audit qualification, coding ability or specialist security tool experience is required. Complete beginners can attend, but should expect to spend time learning governance terminology, risk ownership concepts and the distinction between governance objectives and management objectives.
Training methodology
The five-day programme combines instructor-led COBIT 2019 explanations with guided analysis of a realistic organisation facing ransomware, third-party and cloud-service risks. Participants use design-factor worksheets to tailor a governance system, map enterprise goals to alignment goals, and select relevant COBIT objectives. Small-group workshops develop risk scenarios, RACI matrices, appetite thresholds, KRIs and reporting packs. Facilitated peer review tests whether each design can be operated and assured. The final session converts the work into a prioritised Cyber Risk Governance Blueprint and implementation plan.
Course outline
Day 1: COBIT 2019 foundations for cyber risk governance
- Governance and management distinction in the COBIT 2019 framework
- COBIT 2019 principles for governance systems and governance frameworks
- Governance system components: processes, structures, policies, information and culture
- Enterprise goals cascade from stakeholder needs to alignment goals
- COBIT design factors for tailoring a cyber risk governance system
- Governance and management objectives relevant to cybersecurity
- NIST Cybersecurity Framework 2.0 alignment with COBIT governance concepts
Workshop: Participants map a sample organisation's stakeholder drivers and enterprise goals into a first-pass cyber risk governance context statement.
Day 2: Selecting and structuring cyber risk governance objectives
- EDM03 Ensure Risk Optimization governance practices and decision requirements
- APO12 Managed Risk process purpose, practices and work products
- APO13 Managed Security process design for security management oversight
- DSS05 Managed Security Services and operational security accountabilities
- MEA02 Managed Internal Control for monitoring control effectiveness
- Selection criteria for COBIT objectives based on design-factor inputs
- RACI responsibility mapping across board, executive, risk, IT and security roles
Workshop: Teams select and justify a set of COBIT objectives, then produce a RACI matrix for cyber risk acceptance and security governance.
Day 3: Risk appetite, scenarios and governance reporting
- Cyber risk scenario construction using asset, threat, vulnerability and impact statements
- Inherent risk, residual risk and treatment-option analysis
- Risk appetite statements and measurable tolerance thresholds
- Risk acceptance authority and escalation triggers
- Key risk indicators for cyber exposure and control performance
- Management dashboards versus board-level cyber risk reports
- Risk register fields and evidence requirements for governance decisions
Workshop: Participants develop three cyber risk scenarios and create an appetite statement, escalation threshold and KRI set for one priority risk.
Day 4: Performance management, assurance and control integration
- COBIT performance management concepts and capability-level assessment
- Process practices, activities and work products for APO12 and APO13
- Policy architecture linking risk policy, security policy and operating procedures
- Control ownership and evidence collection for internal assurance
- Mapping ISO/IEC 27001:2022 information security controls to COBIT objectives
- Using NIST CSF 2.0 profiles within a COBIT governance system
- Review cycles, exception management and continuous improvement mechanisms
Workshop: Participants assess a selected cyber risk process, identify capability gaps and define the evidence needed for an assurance review.
Day 5: Implementing the cyber risk governance blueprint
- COBIT 2019 implementation lifecycle and improvement programme stages
- Current-state assessment and target-state governance design
- Prioritisation methods for governance improvements and control dependencies
- Cyber risk governance roadmap sequencing and milestone definition
- Stakeholder engagement for executives, risk owners and technical teams
- Change-management actions for new decision rights and reporting routines
- Blueprint presentation structure for management approval and investment decisions
Workshop: Participants complete and present a Cyber Risk Governance Blueprint containing objectives, RACI, risk appetite, KRIs, assurance actions and a phased roadmap.
Tools & standards covered
COBIT 2019 Framework, NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, ISO 31000:2018
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Cyber Security Fundamentals for IT Professionals Training Course
IT professionals are routinely asked to deploy systems, support users, manage cloud services and respond to incidents, yet security controls…
CyberArk Privileged Access Management Administration Training Course
Privileged accounts sit at the centre of infrastructure administration, application support and incident response, yet unmanaged passwords, …
IBM QRadar SIEM Administration and Offence Investigation Training Course
IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires mor…
Cyber Security Risk Oversight for Board Directors Training Course
Board directors are increasingly expected to challenge management on cyber security without becoming operational security specialists. They …