PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
December 5, 2025Standards4 citationsOpen Access

Cybersecurity Strategy Development: Towards an Integrated Approach Based on COBIT and ISO 27000 Series Standards

View Full Paper
BMBilgin MetinSSSibel Berfun SevimMWMartín Wynn

Key Points

  • Qualitative content analysis identifies key themes in cybersecurity strategy frameworks.
  • Governance practices are essential for aligning information security and IT strategies in organizations.
  • Adapting COBIT and ISO standards can support comprehensive cybersecurity governance.
  • Potential limitations include variances in regulatory compliance across different sectors.

Abstract

This article presents a practical guide for developing a cybersecurity strategy that integrates COBIT 2019 with the ISO/IEC 27000 series of standards. Although COBIT 2019 provides strong frameworks for IT strategy and governance, it does not specifically prescribe a cybersecurity strategy. This article addresses this gap in the strategy literature by building upon the ISO/IEC 27000 series, which is designed to be adaptable for organizations of all types and sizes, as well as being suitable for various regulatory and technological environments. First, a synthesis of COBIT 2019 and the ISO/IEC standards (particularly 27014, 27001, 27036, and 27701) identifies six key themes for a cybersecurity strategy. A more specific qualitative content analysis of ISO/IEC 27014 (which focuses on board-level information security governance) and COBIT 2019 (which outlines execution mechanics) confirms the validity of these themes with traceability at the clause and objective levels. To operationalize these themes, a three-step method is put forward: setting alignment objectives and scope; translating these into IT strategy decisions using COBIT governance and management objectives and practices; and establishing a cybersecurity strategy through ISO/IEC 27001. Additionally, ISO/IEC 27701 for privacy and ISO/IEC 27036 for supplier governance are incorporated where relevant. An illustrative example is provided using anonymized data from public sources, and the applicability and limitations of the research findings are discussed.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Metin et al. (2025) studied this question.

synapsesocial.com/papers/6940224e2d562116f28fc11ehttps://doi.org/10.3390/standards5040033
Ask AI
Helpful
Bookmark
Share
View Full Paper