In my opinion, each framework and standard has its place in the I.T. security, risk management, and compliance realm. Each of them have been developed by organizations that have invested time, research, and care in creating exhaustive frameworks.
The COBIT is a good choice for an enterprise that is aiming to create an organization-wide framework for management that is beyond the boundaries of information security.
The ISO 27000 series and the NIST Cybersecurity Framework are specifically for Information Security and can be adopted by all organizations, irrespective of their industry.
An organization would do well to adopt the COBIT as its umbrella framework, and either the NIST or the ISO for its Information Security one.