Question

Please explain in less than 500 words the most important differences between COBIT and the ISO...

Please explain in less than 500 words the most important differences between COBIT and the ISO 27000 series in relation to information security.

Please also identify and explain at least 3 important differences.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

The ISO 27000 family of information security management standards) is a series of mutually supporting information security standards that can be combined to provide a globally recognised framework for best-practice information security management.

The mainstay of the series is ISO 27001, which sets out the specification for an ISMS (information security management system).

The series is developed and published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

To begin with, what is ISO 27001 and what is COBIT?

ISO 27001 is an international standard for the establishment, implementation, maintenance, and continual improvement of an Information Security Management System. The standard is a joint effort by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

Control Objectives for Information and Related Technologies (COBIT) is an IT management framework developed by the Information Systems Audit and Control Association (ISACA). It is used for business development, organization, and implementation strategies around information management and governance.

Key difference between COBIT and ISO 27001

The key difference between ISO 27001 and COBIT is that the first one is solely for the purpose of information security, and the second one is for management and governance of information technology business processes.

We can consider COBIT to be an umbrella or superset that focuses on management of information technology (IT) and governance. COBIT not only talks about security in an organization, but also includes the way an organization actually organizes, arranges, and oversees the organization of IT operations. It includes all information technology controls, measures, and processes. It helps an organization to map its own business goals to its IT goals. Also, it supplies measurements and provides maturity models to measure an organization’s achievement. Additionally, it helps to identify the organization’s key business responsibilities and the IT process owners.

ISO 27001, on the other hand, is an international standard for Information Security Management Systems. It focuses on performing a risk assessment and then applying specific security controls for protecting the organization’s critical information assets.

Three important differences between COBIT and ISO 27001

COBIT

ISO 27001

Best practice IT management framework

International standard

Defines requirement for governance, management and effective control of information technology processes.

Defines requirements for the establishment , implementation, maintenance, and continual improvement of an information security management system (ISMS)

Implementation is not subject to certification.

Implementation is subject to certification

Add a comment
Know the answer?
Add Answer to:
Please explain in less than 500 words the most important differences between COBIT and the ISO...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT