COBIT 2019 Cyber Risk Governance Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-058
Duration5 days
LevelFoundation to Intermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding which risks require executive action, who owns treatment decisions, or how security priorities support enterprise objectives. This course addresses that gap using COBIT 2019: a governance framework for connecting cyber risk decisions to business goals, risk appetite, assurance requirements and accountable roles. Participants learn to move beyond control checklists and present cyber risk in terms that boards, executives, auditors and business owners can act upon.

The course covers the COBIT 2019 governance system, design factors, goals cascade, governance and management objectives, and performance management approach. Participants work in detail with EDM03 Ensure Risk Optimization, APO12 Managed Risk, APO13 Managed Security, DSS05 Managed Security Services and MEA02 Managed Internal Control. They practise selecting relevant objectives, defining decision rights, documenting risk scenarios, setting risk appetite thresholds, assigning ownership, establishing key risk indicators and designing reporting for management and governance bodies. Practical mappings to NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022 show how COBIT can govern existing security programmes rather than replace them.

Instructor-led briefings are combined with facilitated design workshops, cyber risk case studies and team reviews of realistic governance artefacts. Throughout the week, participants build a Cyber Risk Governance Blueprint for a sample organisation or their own environment. The completed blueprint includes a goals cascade, selected COBIT objectives, risk appetite statements, a RACI matrix, KRIs, reporting cadence and a phased implementation roadmap. This makes the course particularly valuable for professionals expected to establish, improve or assure cyber risk governance across business, technology and security functions.

Course objectives

By the end of this course, participants will be able to:

  • Apply the COBIT 2019 goals cascade to connect enterprise objectives, alignment goals and cyber risk priorities
  • Select and justify COBIT 2019 governance and management objectives for a defined cyber risk context
  • Design a cyber risk governance system using COBIT design factors and governance system components
  • Define decision rights and accountability through a RACI matrix for risk optimisation and managed security
  • Construct cyber risk scenarios with threat, vulnerability, impact, likelihood and treatment information
  • Set risk appetite statements, tolerance thresholds and key risk indicators for executive cyber risk reporting
  • Assess the performance of selected COBIT objectives using capability levels, practices and supporting activities
  • Produce a phased Cyber Risk Governance Blueprint with target-state controls, metrics and implementation actions

Benefits of attending

For you

  • Gain a practical method for explaining cyber risk decisions through enterprise goals, risk appetite and accountable ownership
  • Build confidence selecting COBIT objectives such as EDM03, APO12 and APO13 for real security governance issues
  • Create governance artefacts that demonstrate capability in risk reporting, RACI design and control oversight
  • Strengthen credibility with executives and auditors by using COBIT 2019 terminology and structured governance evidence
  • Prepare to contribute to COBIT-based GRC, cyber risk, internal audit and security leadership assignments

For your organisation

  • Establish clearer accountability for cyber risk acceptance, treatment decisions and security control ownership
  • Improve board and executive reporting through defined risk appetite thresholds, KRIs and reporting cadence
  • Focus security investment on COBIT objectives that directly support enterprise goals and priority risk scenarios
  • Reduce duplicated governance effort by mapping existing NIST CSF and ISO/IEC 27001 activities into a COBIT structure
  • Create an actionable roadmap for improving cyber risk governance, assurance and performance monitoring

Target competencies

COBIT goals cascadeCyber risk governanceRisk appetite designRACI accountability mappingKRI reporting designGovernance roadmap planning

Who should attend

  • Cybersecurity Managers — who must translate security risks and investments into accountable governance decisions
  • Information Security Officers — who need to align security management activities with enterprise risk appetite
  • IT Risk Managers — who design risk assessment, treatment and reporting processes across technology services
  • GRC Managers and Analysts — who map controls, policies and assurance evidence to a recognised governance framework
  • IT Governance Managers — who establish decision rights, performance measures and governance reporting for digital risk
  • Internal Auditors — who assess whether cyber risk oversight, control ownership and monitoring arrangements are effective

Requirements and prerequisites

Participants should understand basic information-security concepts such as assets, threats, vulnerabilities, controls, incidents and risk treatment. Familiarity with a risk register, security policy, ISO/IEC 27001, NIST CSF, IT service management or internal audit will help participants relate the exercises to their workplace, but is not mandatory. No prior COBIT certification, audit qualification, coding ability or specialist security tool experience is required. Complete beginners can attend, but should expect to spend time learning governance terminology, risk ownership concepts and the distinction between governance objectives and management objectives.

Training methodology

The five-day programme combines instructor-led COBIT 2019 explanations with guided analysis of a realistic organisation facing ransomware, third-party and cloud-service risks. Participants use design-factor worksheets to tailor a governance system, map enterprise goals to alignment goals, and select relevant COBIT objectives. Small-group workshops develop risk scenarios, RACI matrices, appetite thresholds, KRIs and reporting packs. Facilitated peer review tests whether each design can be operated and assured. The final session converts the work into a prioritised Cyber Risk Governance Blueprint and implementation plan.

Course outline

Day 1: COBIT 2019 foundations for cyber risk governance

  • Governance and management distinction in the COBIT 2019 framework
  • COBIT 2019 principles for governance systems and governance frameworks
  • Governance system components: processes, structures, policies, information and culture
  • Enterprise goals cascade from stakeholder needs to alignment goals
  • COBIT design factors for tailoring a cyber risk governance system
  • Governance and management objectives relevant to cybersecurity
  • NIST Cybersecurity Framework 2.0 alignment with COBIT governance concepts

Workshop: Participants map a sample organisation's stakeholder drivers and enterprise goals into a first-pass cyber risk governance context statement.

Day 2: Selecting and structuring cyber risk governance objectives

  • EDM03 Ensure Risk Optimization governance practices and decision requirements
  • APO12 Managed Risk process purpose, practices and work products
  • APO13 Managed Security process design for security management oversight
  • DSS05 Managed Security Services and operational security accountabilities
  • MEA02 Managed Internal Control for monitoring control effectiveness
  • Selection criteria for COBIT objectives based on design-factor inputs
  • RACI responsibility mapping across board, executive, risk, IT and security roles

Workshop: Teams select and justify a set of COBIT objectives, then produce a RACI matrix for cyber risk acceptance and security governance.

Day 3: Risk appetite, scenarios and governance reporting

  • Cyber risk scenario construction using asset, threat, vulnerability and impact statements
  • Inherent risk, residual risk and treatment-option analysis
  • Risk appetite statements and measurable tolerance thresholds
  • Risk acceptance authority and escalation triggers
  • Key risk indicators for cyber exposure and control performance
  • Management dashboards versus board-level cyber risk reports
  • Risk register fields and evidence requirements for governance decisions

Workshop: Participants develop three cyber risk scenarios and create an appetite statement, escalation threshold and KRI set for one priority risk.

Day 4: Performance management, assurance and control integration

  • COBIT performance management concepts and capability-level assessment
  • Process practices, activities and work products for APO12 and APO13
  • Policy architecture linking risk policy, security policy and operating procedures
  • Control ownership and evidence collection for internal assurance
  • Mapping ISO/IEC 27001:2022 information security controls to COBIT objectives
  • Using NIST CSF 2.0 profiles within a COBIT governance system
  • Review cycles, exception management and continuous improvement mechanisms

Workshop: Participants assess a selected cyber risk process, identify capability gaps and define the evidence needed for an assurance review.

Day 5: Implementing the cyber risk governance blueprint

  • COBIT 2019 implementation lifecycle and improvement programme stages
  • Current-state assessment and target-state governance design
  • Prioritisation methods for governance improvements and control dependencies
  • Cyber risk governance roadmap sequencing and milestone definition
  • Stakeholder engagement for executives, risk owners and technical teams
  • Change-management actions for new decision rights and reporting routines
  • Blueprint presentation structure for management approval and investment decisions

Workshop: Participants complete and present a Cyber Risk Governance Blueprint containing objectives, RACI, risk appetite, KRIs, assurance actions and a phased roadmap.

Tools & standards covered

COBIT 2019 Framework, NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, ISO 31000:2018

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior COBIT training is required. The course starts with COBIT 2019 principles, governance system components and the goals cascade before applying them to cyber risk scenarios.

A laptop is recommended for working with the supplied COBIT worksheets, RACI templates, risk scenario templates and roadmap materials. No specialist security software, coding environment or paid COBIT platform is required.

It suits both, provided participants need to make, support or assure cyber risk decisions. Technical practitioners learn how operational security evidence feeds governance, while GRC and governance professionals learn how to structure accountable oversight.

ISO 27001 courses focus on establishing and auditing an information security management system, while NIST CSF courses focus on organising cybersecurity outcomes. This course uses COBIT 2019 to define the governance mechanisms, decision rights, performance measures and accountability that direct those activities.

You can use the goals cascade and design factors to select relevant objectives for a security programme, risk committee or audit finding. The risk appetite, RACI and KRI templates can be adapted directly for governance reporting and improvement planning.

Participants leave with a Cyber Risk Governance Blueprint developed during the workshops. It includes a tailored objectives map, role matrix, risk scenarios, appetite thresholds, KRIs, assurance considerations and a phased implementation roadmap.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Cyber Security Fundamentals for IT Professionals Training Course

IT professionals are routinely asked to deploy systems, support users, manage cloud services and respond to incidents, yet security controls…

5 Days Certificate

CyberArk Privileged Access Management Administration Training Course

Privileged accounts sit at the centre of infrastructure administration, application support and incident response, yet unmanaged passwords, …

5 Days Certificate

IBM QRadar SIEM Administration and Offence Investigation Training Course

IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires mor…

5 Days Certificate

Cyber Security Risk Oversight for Board Directors Training Course

Board directors are increasingly expected to challenge management on cyber security without becoming operational security specialists. They …