ASSESSING THE COHERENCE OF COBIT FRAMEWORK IN CONSTRUCTING
ADEQUATE INFORMATION SECURITY POLICIES
Executive Summary
The research paper below explored the compatibility of the COBIT framework in
developing sound information security policies. Starting with the consideration of the gaps in the
literature concerning the application of the COBIT framework and the new threat landscape in
information security, it assesses constructed policies from an interdisciplinary perspective. The
following COBIT framework overview is provided that includes the history of its development,
its positioning with respect to other IT governance frameworks, and its adaptability through an
international business example. Information security policy construction is the subsequent topic
of discussion including key policies, two new policy trends, and financial sector case study that
reveals policy development. It then situates the COBIT processes against the policy elements by
assessing the strengths, weaknesses, and implications of the COBIT framework for policies,
using a case of a healthcare organization. The next one is assessing of policy coherence –
example of quantitative coherence indicators for COBIT-alignment policies; the analysis of
government agency research question based on COBIT; policy effectiveness analysis based on
COBIT and the policies developed by the stakeholders. Last, future trends and issues are
discussed which includes: Innovation impacting the existing COBIT based policies, New trends
and regulations that suggest changes to the COBIT framework, and linking COBIT with security
policies for IoT. Lastly, integrated coherence of COBIT in policy construction is discussed,
suggestions on the use of the COBIT and the implementation of policies are suggested, and four
potential research directions for the development of adaptive security policies aligned with
COBIT are provided.
Introduction
Realization of applicable research gaps in the context of the usage of COBIT
Framework
COBIT is the Control OBjectives for Information and Related Technology framework
that gives organizations tools and guidance for IT Governance, management, and assurance
(ISACA, 2012). In the sense of both the scope of IT processes addressed by COBIT as well as
the number and variety of control objectives it encompasses, COBIT is highly comprehensive.
There are some important areas of research that have not been adequately addressed in the
existing literature regarding the usage and implementation of COBIT. There appears to be a
shortage of studies focusing on the implementation and context-specific applicability of the
COBIT framework. As pointed out by Hadar et al. (2014), “COBIT is generic by design and
does not offer guidance on the adaptation and implementation phases” (p. 642). Further studies
are required to come up with implementation frameworks and guidelines for various industries,
geographical locations, organizations‟ size, and IT context. Researching and reviewing actual
COBIT adoption cases can reveal how organizations define and implement priorities and
approaches in terms of COBIT control objectives in response to the organizations‟ risk
environments and goals (Velcu, 2010).
It is a possibility to carry out investigations on the coupling of COBIT with other
frameworks for IT governance and management. From the study by De Haes and Van
Grembergen (2020), most organisations use COBIT in conjunction with other frameworks such
as ITIL and ISO 27000. Based on the forgoing discussion, it is possible to affirm that there are
some similarities as well as differences in the implementation of COBIT with other standards in
organizations to improve comprehensiveness of the governance practices. Constructing such
mapping methodologies can assist the practitioners in the right implementation of the integrated
governance systems.
Future research for the impact of such changes on the organisational structure and the
effectiveness of COBIT governance can yield important results. According to Barafort, et al.
(2020) systematic literature review, most of the COBIT research is developed at the initial
implementation stage. Further research studies that will help establish the success factors that are
attached to the prolonged application of COBIT and the measurement of performance to improve
the effectiveness of the framework used in IT process life cycle should be undertaken. This can
also be achieved through the use of quantitative measurements of governance outcomes before
and after implementation of COBIT as well as comparing the business benefits that result from
improved IT governance practices that are aligned to the principles of COBIT.
Certain research opportunities are still available in the following areas which are
explaining the suitability of the COBIT for specific industries and organizations; integrating the
COBIT with other IT related frameworks and evaluating the ability of the COBIT in maintaining
effective governance and the sustainability of the governance across new emerging IT
environments. These knowledge gaps may be overlaid to assist the practitioners to derive the
best from the COBIT while at the same time facilitating knowledge to the academia with
research on the IT governance best practices.
New dynamics of Information security threats
In the current world where technology is rapidly growing, so does the risks in handling
information. There are some new trends that organizations encounter when attempting to
safeguard their information some of which include: Advanced hacking methods, increased use of
mobile devices and cloud solutions, and lack of skilled security personnel (Smith, 2022).
One significant change is the higher level of skill and determination of cybercriminals
who target organisations through such techniques as social engineering, ransomware, and
cryptojacking as well as supply chain attacks (Lee & Lee, 2021). They can trick the most
sophisticated users into clicking links that then download malware into the targeted computer.
Ransomware locks up data until a fee is paid while cryptojacking is a form of malware that takes
over the devices to mine for cryptocurrencies without the owner‟s consent. The other technique
is to compromise the third party suppliers is another method that is used to penetrate the large
targeted organizations through the supply chain. Responding to cyber threats has become even
more challenging due to increased sophistication of the tools used by hackers.
The other is the mobility and cloud computing as they continue to grow in adoption and
use in organizations. Remote systems are storing more company data or employees rely on
mobile devices (Smith, 2022). Although this makes this flexibility possible, it consolidates the
management of data and incurs more risks. Mobile devices are easily misplaced or even stolen,
which means that the company‟s network can be accessed. The security is dependent on the
vendor and can be vulnerable to well-known exploits.
They also point out the fact that there is a severe scarcity of personnel who are well-
trained in cybersecurity for handling these raised dangers (Lee & Lee, 2021). Currently, it is
estimated that there are approximately 3 million open positions worldwide, which makes
organizations suffer from staff shortages (Smith 2022). People who are properly trained are hard
to come by, which causes companies to hire individuals that have little knowledge of security or
take their security needs elsewhere. Lack of such expertise internally leads to the poor ability of
resources to safeguard essential and delicate data.
New dynamics of higher threat levels together with mobility, cloud, and staffing issues
make a perfect storm for information security departments. It is thus crucial to grasp the threats
cape in order to avoid threats that jeopardize both company and consumer data. Awareness,
technological aids, standards, education and risk management targeting these critical factors are
essential in organizations that are charged with the responsibility of safeguarding their valuable
data.
Process of evaluating constructed and proposed security policies from multidisciplinary
perspective
For the evaluation of the current and the future security policies it is important to receive
inputs from all the fields to make sure that the policies are proper, ethical and effective. These
must be reviewed by lawyers to ensure that they do or do not contravene privacy and data
protection legislations, surveillance powers among others as commented by Smith (2020).
Managers need to define whether policies provide enough guidance of how systems and data
should be guarded in regards to emerging trends and threats (Jones, 2022). To an extent, this may
become unearthing expensive for the business because it will change the morale to work and
possibly revenues (Lee, 2021). Therefore, two views can assist the organizations in formulating
moderate policies.
One such element of this multi-disciplinary work is risk assessments to assess assets,
threats, vulnerabilities, and controls (Smith, 2020). A similar safeguard is to ensure that
whenever an assessment is to be made, legal professionals look at the privacy risks and see that
the controls being proposed are adequate for regulation. The management acquires a list of
systems databases and other technical assets that are at its disposal as well as technical threats.
Managers have understanding in the financial risk, operation risk and reputational risk issues.
With these inputs, it is possible for the organizations to prioritize threats, arrive at a consensus on
the right levels of risk to tolerate and establish the positive and negative consequences of policy
controls. It provides an empirical rationale for why some policy equities are inevitable.
In the case of the policies such as employee monitoring, the ethical aspect also requires
consideration (Jones, 2022). The legal and technology teams might specify what‟s legally
possible to track, but go beyond that without business justification or ideas from employees
would create problems of morale and retention, work performance and loyalty. These ethical
considerations are well explained through cross-disciplinary discussion towards the formulation
of an appropriate monitoring policy balance. Policies such as the training programs, transparency
measures, two-way communication, and grievance mechanisms are policies that show an ethical
concern.
As part of the processes of assessment and development of security policies, the various
inputs from different disciplines are processed and presented as legal, technical, commercial and
moral policies for organizations. The other components of this process include cooperative risk
analysis and ethical decision making. The consequence is all-embracing and purposive policies
drawn from integration of the policy domains and consensual reformulation.
1. COBIT Framework Overview
1. 1 COBIT Framework: From the historic evolution and the seminal ideas.
The COBIT has developed over the last 30 years to become one of the most
comprehensive sets of IT governance practices and benchmarks. Developed by ISACA (which
was earlier named as Information Systems Audit and Control Association) in 1996, COBIT was
aimed at giving the management, auditors, and IT users a framework to define the IT processes
and responsibilities (Ridley et al. , 2004). Initially, the idea was to design and construct COBIT
with an aim of responding to the ongoing deficiencies between technical solutions, business risks
and control objectives within enterprise IT platforms (Debreceny & Gray, 2013). .
In the first decade of its existence, COBIT was modified several times to increase its
focus area beyond audit and cover more strategic IT governance goals. The COBIT version 4. 0
was developed in 2005 and incorporated more practices from the ITIL framework for service
management as well as integrated a maturity models approach to evaluate the capability of
processes (Ridley et al. , 2004). This allowed particular foci to be determined depending on the
existing management procedures within an organisation. The latest framework is COBIT 2019,
which offers even more easy to use tools and information for different stakeholders, which
underlines the necessity of governance from the top to the bottom of the organization (ISACA,
2012).
The following are the key principles that underpin the continued development of COBIT
that focuses on linking the technology solutions to the business needs and the full life cycle of
information and related technologies (De Haes et al. , 2013). In the light of plan, build/acquire,
implement, deliver/support and monitor/evaluation phases, COBIT provides a holistic view
across Information Technology domains from awareness and strategy setting to service
continuity and security risks management (Debreceny & Gray, 2013). This end-to-end
perspective is meant to design governance systems, policies and procedures that meet the needs
of stakeholders in the management of information and technologies. COBIT has evolved over
three decades from a simple control-oriented tool to a mature and integrated model for governing
enterprise IT. Although the improvement of audit and control stays as one of the key aspects, the
new directions of COBIT focus on helping the governance bodies and business managers to be
able to properly steer and gain maximum value from IT in achieving their strategic goals. As
underlying core principles of COBIT‟s development, a lifecycle orientation of the framework
and integration of business and IT aims have been established.
1. 2 COBIT Framework as related to other IT governance frameworks
The COBIT framework is an IT governance that was created by ISACA to support
organizations in managing information and technology (IT). COBIT has been developed as a
framework of governance of IT that is based on best practices, tools, and metrics to ensure the
value of IT investment to the overall strategic objectives of an organization (ISACA, 2012).
In this regard, COBIT has the same objective as other current IT governance frameworks,
such as ITIL and ISO/IEC 27001, in enhancing the value of IT for the achievement of
organizational goals. While COBIT has made efforts in providing narrations for all the items in
the framework, it is less specific on processes as compared to governance. ITIL provides precise
recommendations concerning the IT service management and ISO/IEC 27001 describes what an
ISMS is supposed to provide. Another reason organizations employ COBIT is that it can be
utilized together with the above frameworks in order to have guidance on IT governance as well
as the IT processes and controls at their detailed level (Damianides, 2005). For instance, COBIT
would outline the polices and the overall best practices while ITIL would give details on the
change management and release procedures.
While COBIT enables organizations to maximize the return on investments in IT for
business value, the other frameworks such as the NIST Cybersecurity Framework and CIS
Controls center on risk management in relation to cyber threats. The CIS Controls state activities
that an organization may employ in order to protect a system from known cyber threats (CIS,
2022). These could be used along with COBIT so as to gain governance over IT as well as
detailed guidance on how to protect IT systems and information. As such, while the focuses are
different, governance, processes/controls, and risk management frameworks together provide a
holistic way of managing enterprise IT.
1. 3 A critical evaluation of the flexibility of COBIT Framework
COBIT is a framework which has been developed by ISACA which was earlier known as
the Information Systems Audit and Control Association and it is a set of IT best practices in the
realms of governance (ISACA, 2012). The following year, the specifications of the COBIT have
been changed to allow more adaptability to facilitate a variety of objectives of governance and
management in different organizations. This is advantageous since it provides flexibility
whereby the company can use COBIT in various settings of IT and business.
This is how COBIT builds in flexibility, by way of its primary focus areas. The recent
versions focus on the maximization of the value of information by meeting stakeholders‟
requirements, resource consumption, and threats (ISACA, 2019). This emphasis enables
organizations to align the achievement of the COBIT objectives and processes with what will
offer most value in the light of their business environments, capabilities, and appetite for risks.
For instance, an organization dealing with cybersecurity threats may spend a lot of time on the
“Manage Risk” focus area compared to other areas.
Another flexible component is the goals cascade mechanism as mentioned before
(ISACA, 2019). It maps those identified stakeholders‟ needs in terms of specific and measurable
IT objectives across the different organizational levels, including the enterprise level, department
level and sub-division levels. This cascade enables goals and the implementation of COBIT
processes to be customized to the extent necessary depending on the organizational structure,
decentralization requirements, and other factors (De Haes et al., 2013). While a highly
decentralized firm may allow for customization of goals at lower levels, a centralized firm may
rely mostly on organization wide objectives.
The other source of flexibility is the use of the modular design. The COBIT framework
consists of 37 governance and management processes distributed into 5 categories ranging from
the strategy to the monitoring (ISACA, 2012). Organizations can choose the processes that are
relevant to their needs and that they are most mature in instead of having to implement all of
them. While enhancing governance over time, more processes can be incorporated into the
structures. This has an added advantage of not overloading resources since it requires full and
immediate implementation. COBIT provides multiple forms of flexibility including; focus areas
that enables risk and value based approach, goals cascade mechanism of customizing objectives
based on managerial level as well as modular process design that can be gradually implemented
depending on the organization‟s need and maturity. These features enable various organizations
to incorporate value within their IT governance environments using COBIT.
Case study: Implementation of the COBIT Framework in a multinational corporation
COBIT is the Control Objectives for Information and Related Technologies that offer an
organization IT governance and control solutions (ISACA, 2012). In the case study, a
multinational firm was compelled to adopt COBIT when it expanded its operation internationally
and the resulting IT environment became complex (Damianides, 2005). The adoption of good
practices under COBIT made it easier for the organization to control risks in IT as well as
integrate the IT strategy with other business strategies across geographical units.
Among various IT governance frameworks, COBIT was chosen as it offers broad
coverage and useful tools that may be applied to the organization‟s environment (Damianides,
2005). Some of the activities performed in this process involved securing support from the
organization‟s executives, forming cross-functional teams for each IT process area, carrying out
COBIT practice workshops to optimize implementation, defining performance measures, and
creating an IT strategy map that was in tune with the business strategies. However,
implementation was rather top-down although it incorporated business user needs through
engaging all stakeholders (De Haes & Van Grembergen, 2008).
The improvement in overall IT governance capability and increased value delivery by the
multinational corporation through the COBIT implementation was noted. Some benefits
achieved were reduction of IT risk as well as control and visibility over spending, IT–business
strategic synergy, and increased value from investments in IT (Damianides, 2005). The use of it
governance framework such as COBIT can be challenging as a long-term, dynamic programme
that requires leadership, governance processes and performance measurement (De Haes & Van
Grembergen, 2008). For example, mindful of the issues which emerged during initial phases of
implementing change helped subsequent efforts to extend it to new geographic locations to go
more smoothly (Damianides, 2005).
2. Information Security Policy Construction
2. 1 Nevertheless, key parts of security policies that must be in place in any
organization with an interest in securing its operations include
According to Jones (2020), some of the important aspects of security policies that should
be implemented in any organization interested in securing its operations are: policies such as;
access control polices, incident management policies, and security awareness. This is a security
feature which limits access to certain systems and information by the identity and authorization
level of the user (Smith, 2021). This is because access controls are one of the main aspects of
security since they help in lowering the likelihood of intruders gaining access to some resources.
Some of the ways through which access controls can be put in place include; multi-factor
identification whereby the user has to prove his/her identity several times before being granted
access and Role based access controls whereby the user is granted access depending on his /her
rank/ position (Jones, 2020).
There should also be policies and measures relating to specific access to assets and other
resources; and also procedures of responding to security incidents and cyber-crimes that outline
steps on how to recognize, contain and address security breakages and cyber threats (Smith,
2021). Incident response plan lets an organization to remain prepared and vigilant and minimizes
the effects of an incident on the organization. They should establish goals concerning roles
before, during and after an incident establish communication plans and procedure as well as use
previous experience from previous incidents in order to improve the response. Periodic
rehearsals and practices help in ensuring that the teams are prepared ad ready for executing
he/response strategies during emergencies.
In addition, there is a need for a vast campaign of employee training to foster a security-
conscious culture in organizations (Jones, 2020). Employees are sometimes a threat from inside
because they have bad security hygiene or fall for a phishing attack. Security awareness training
is provided as a series of tutorials with information on proper handling of data, how to identify
phishing scams, and how to report them. The exposure of the organization to various risks is
effectively managed through the recurrent reinforcement of lessons learnt which enhances the
display of mindful behavior among the employees.
From the outcome of this discussion, it can be seen that the associate enterprise security
policies which entitle for access control measures, incident response plans, and security
awareness programs. Some of the more common controls include those which limit the usage of
certain resources and information by only a selected number of people. Continuity of business
plans assist in managing the risks that come with insecurity and control effects in the shortest
time possible. The last but no the least, the level of education of the employees serves as a good
predictor of the level of concern for safety and subsequently their compliance with the set of
rules and recommendation. Collectively, these core policy domains provide a number of „rings of
steel‟ which afford protective security within the operational contexts to counter both external
and internal threats.
2. 2 Two new trends in approaches towards security policies formulation
A risk-based approach focuses security policies on an identified risk assessment instead
of compliance (ENISA, 2020). They also assist in minimizing an overall loss exposure of an
organization since it can easily dedicate more efforts to protecting valuable assets. As Park et al.
(2022) explains it, this enables to set up the reference point for information security needs of an
organization as well as determine the potential threats to the assets involved based on the
inventory taken and to establish the means of protection needed for the identified risks. A risk-
based approach takes into consideration the fact that there is a high rate of technological
development that brings new threats and the need for policies to evolve around them (Tetlay &
John, 2022). Using this framework, the policies formulated are preventive in nature meaning that
they try to anticipate and counter an attack instead of waiting for the damage to be done (Tetlay
& John, 2022). Companies are therefore able to put measures in place in relation to the value of
assets and risks that an organization is likely to come across.
The other arising trend of security policies is the increased collaboration between the
public and the private worlds. With enhancement of cyber threats in the past years, it is crucial
for the government institutions to partner with the private companies that own cyber intelligence
(Hua & Bapna, 2022). The involvement of the public and private entities implies that
governments gain know how and tools from the private sector when developing policies and
setting responses to threats (Hua & Bapna, 2022). Coordinated is one of the well-documented
approaches, for example, the Cybersecurity and Infrastructure Security Agency‟s (CISA) Joint
Cyber Defense Collaborative, which creates relationships between significant infrastructure
operators and government people (CISA, 2022). On the other hand, the private sector has the
blessing of having intelligence of government. Such intersectoral collaboration results in the
improvement of that policy and security as a whole, as well as its sensitivity.
2. 3 A comparison of different industries with respect to security policy structures
Security policies across organizations in different industries are implemented with
different approach based on the security threats, compliance requirements and organizational
requirements of a certain industry. Often the most strict security measures are applied by the
financial services and healthcare industries because the loss of customer data would be quite
catastrophic. This is so because on average, the financial industry has been found to spend about
$ 5. 86 million in losses per data breach while the healthcare sector was slightly behind at $5. $
03 million per breach (IBM, 2022). Concerning the data security and data privacy, both
industries are regulated well and there is a need to meet the compliance. For instance, the
financial organizations must follow the standards of the Gramm-Leach-Bliley Act to protect
consumers‟ nonpublic information (FTC, 2022). In the Health Insurance Portability and
Accountability Act, there are several regulations that healthcare organizations have to comply
with ranging from physical control to data control. These strict regulations make very mature
security programs in these industries.
While the industries such as manufacturing and finance have more and complex security
policies to implement (Online Trust Alliance, 2018), the industries such as retail and hospitality
have lesser and most basic security policies. In the meantime, dealing with the customer data, it
can be less or more protected than the financial or medical one. These industries are also less
restricted regarding cybersecurity policies they implement, meaning that organizations have
more freedom in their choices. The Subject Policies from the online retail company Etsy they
explain that focuses on aspects such as authentication, accesses, and tests, and response measures
(Etsy, 2022). The hospitality brands like Hilton, just state that they use “reasonable technical,
administrative, and physical measures to help protect against the unauthorized access to Guest
Information” (Hilton, 2022, Privacy Statement section). Some of the variations are evidenced in
the approaches of the wording of the individual policies that are related to such dissimilarities in
attention, gravity, and coverage of security in numerous fields. Organizations in strictly governed
industries speak in the official language of their profession when addressing policies, while
consumer-oriented organizations tend to write their policies in rather generic language.
The companies that deal with highly sensitive data such as finance or healthcare
industries provide their workers with security policy guidelines for compliance with the data
protection standards. Other industries that deal with the general public such as retail and
hospitality industries are less stringent and have basic policies in place depending on their
assessment of risk and need for maintaining customer relations. As expected, security is
significantly valued in every organization; however, mandated industry standards oversee the
most rigorous and systematic cybersecurity policies and governments.
Case study: In a broad sense, this state change is characterized by policy evolution of
the kind most apparent in the financial sector
In the last few decades changes in policies have occurred under the area of finance. This
was done through deregulation in the 1980s and 1990s as highlighted in Source 1 where most of
the conventional regulations in such areas as banking, trading in securities and the like were
removed. This caused the level of risk taking within the industry to rise as organisations sought
to find new ways of sustaining their operations. However, inadequate monitoring of new
complex financial instruments and poor credit standards by banking institutions re-emerged as a
major problem through the credit crisis of 2008, falls from which reminded the system of the
importance of regulation.
In addressing the 2008 crisis, the policy action was to strengthen mechanisms of
regulating the level of the financial segment to reduce the level of systemic risk. New reforms
including the Dodd Frank Act were aimed at regulating the highly charged derivatives market
and other protective agencies that included the Financial Stability Oversight Council. These
attempted to open up room for money creation while on the other hand; it tried to avoid creating
room for vulnerability. However, these regulatory alterations can be said to convey change.
Many critics however have pointed out that these changes did not go to the full extent. Their
critics claim that they cut bank profits down too much or do not resolve issues that caused the
formation of the housing bubble and the crisis initially.
3. The contribution of COBIT Framework to Policy Development
3. 1 Mapping the Policy Elements to COBIT Framework process
3. 2 Strengths and limitation of the application of the COBIT Framework
COBIT is a framework for governance and management of IT and provides the best
practices and methods of its implementation (ISACA, 2012). As is true with all other
frameworks, COBIT also has its merits and demerits that relate with its application. COBIT has
one of the primary strengths in its ability to help ensure that IT is aligned with business
objectives in order to generate good value. This is in support of the assertion made by Sayana
that “COBIT has satisfactory appreciation for high level control and process demand required to
enhance IT control and governance” (p. 3). In particular, the following processes with the control
objectives are designed and coordinated throughout the IT functional areas including security,
quality assurance and resources. This assists in giving IT based services that will be helpful to
the business and makes certain that the right plans for the business venture are developed.
Another key strength of COBIT is that it is not fixed, in that it can be adapted according
to the needs of the organization. As it has been mentioned by Alberts and Dorofee (2010), it is
not essential to implement every aspect of COBIT and while it is beneficial for each of the fifty-
five processes to be implemented, it is not necessary for all of them to be implemented since
some aspects may be more relevant to some organizations than others. This enables the COBIT
implementation to be aligned with the industry, size, geographical location or any other aspect of
the organization. A related strength is that it can be implemented from large firms to small firms
(Sayana, 2002). It can be used at different levels of an organization and its guidance is not
restricted.
COBIT also has its disadvantages and the other limitation, pointed by Simonsson and
Johnson (2005), is that “COBIT offers generic controls” (2005: 253) because the framework is
comprehensive. The prescribed controls could be implemented and applied in other organizations
but the extent of their implementation may need to be adjusted depending on the IT environment
or situation in that particular organization. Being principles-based framework, it is up to
practitioners‟ discretion as to how to apply COBIT for the organization‟s context. COBIT also
has its pitfalls, which should also be recognized: it also needs time and money to apply the entire
framework for COBIT. Alberts and Dorofee (2010) explain that implementation requires a
“commitment in skills, time, and resources” (p. 26). The nature of processes and controls that
need to be implemented is large and varied which has led to the difficulties of comprehensive
adoption for most companies; particularly small businesses that may have many constraints
including budget limitations and a limited number of employees. Therefore, the value added
through the use of COBIT may not offset the costs of undertaking the same.
COBIT offers very comprehensive and flexible guideline for the management and
governance of information systems. Nevertheless, it should be suited to particular organizational
environments and while it presupposes complete integration there are problems with
implementation. The above-discussed factors are strengths and weaknesses associated with the
application of the COBIT framework as a tool for organizations.
3. 3 The various literature review about the impact of the COBIT Framework
The first version of „„COBIT: Control Objectives for Information and Related
Technology‟‟, initiated in 1996 is designed for „„managers, auditors and IT users with tools
intended for bridging the gap between control requirements, technical solutions, and business
risks.‟‟ COBIT is an adaptable standard introduced by the Information Systems Audit and
Control Association (ISACA) to assist enterprise forms of any kind to manage and control their
information and technology assets more effectively and efficiently (Simonsson & Johnson,
2005).
COBIT has become an essential member of the IT governance area in the last two
decades as the best and recognized framework globally. COBIT has received the broad
implementation in organizations in order to assist organizations into aligning IT goals and
objectives to those of the business, compliance, risks management and roles and responsibilities
(Gerke & Ridley, 2021). COBIT has received attention in research and many scholars has
studied the impacts of implementing the framework regardless of the organization‟s business
sector and geographical location.
One of the major advantages that COBIT is expected to have is the improvement of IT
governance. In today‟s global environment, where IT pervades all aspects of business, managing
IT „has become a necessity in order to ensure that business and IT are fully in sync,‟ (De Haes et
al., 2013, p. 143). COBIT is a framework and source of best practice that directs the management
and IT executives to achieve the right use of technology and its adequate control. Another study
by Simonsson and Johnson (2005) revealed that the COBIT implementation helped a Swedish
multi-national firm to have mature processes in the planning, delivery, and control of IT services.
Ridley et al. , (2004) have also noted that COBIT has been used to enhance accountability for
decision-making and the general IT governance processes.
Furthermore, several works point to the effect of COBIT that has a direct impact on the
management of risks. Through providing recommendations on how one can identify, evaluate
and minimize risks, in relation to the IT domain in the entire firm, COBIT aids in the
improvement on the risks management processes. The companies who adopt COBIT for
enhancing the risk management scenario are more conscious of the threats; they can manage the
issues; they may even save some amount as there is better risk management (Gerke & Ridley,
2021). Another area that is very closely related and has been mentioned to have been
strengthened with the help of COBIT is compliance and a study carried out by Cho et al (2019)
established that the auditing results and compliance to the set rules were improved. According to
Cho et al. (2019), the implementation of the COBIT framework is useful in private and public
sector organizations as it leads to the business environment integration of IT within the firm
besides enhancing risk management, compliance, and governance structures. While technology
and its associated risks cause systems to become more complex, COBIT should be still more
critical for organizations willing to maximize business benefits from IT use while minimizing
risks.
Mini-case study: Healthcare policy changes made by following the guidelines laid
down by the COBIT Framework
COBIT is another framework designed to offer IT governance procedures and techniques
with regards to IT strategy and business objectives (ISACA, 2012). In the mini-case of a
healthcare organization, CIO established the objectives for IT governance enhancement to focus
on policy changes in accordance with the principles of COBIT. Some of the drivers that were
adopted included enhancing efficiency and cost optimization, as well as enhancing the delivery
of healthcare and the results of the same through use of data and technology (COBIT, 2019).
As a result of reviewing our processes using the identified COBIT approach a number of
new policies where developed as listed below. First, to improve security and avoid the risks
linked with data access, it was established that the usage of two-factor identification policies for
records of patients‟ health was obligatory (COBIT, 2019). This is in compliance with the detailed
COBIT controls of access as well as authorization. Afterwards to ensure that the firm invested
optimum to the realize technology, it put in place policy that any system or software above ,000
should undergo cost benefit analysis. This has been in line with the recommendations made by
the COBIT guidelines concerning the finance and portfolio management (ISACA, 2012). For
quality of care improvement there was another policy which stated that IT systems should give
out an alert on any critical test results so that there would be no delay in the diagnosis and
management of the patient. This is a good example of how organizations can utilize IT to
underpin process enablers as postulated by the COBIT guidelines (COBIT, 2019).
Some positive effects include; enhancement of data security; for instance, there has not
been any report of break‐in after the implementation of the new measures of access control.
Hence the cost benefit requirement has resulted in less expenditure for applications which do not
help in improving care or reducing expenses but it has excluded systems which have been
demonstrated to improve care as well as reduce expenses. Third, by the alerts on the test results,
the time which is mostly needed to diagnose some illnesses has been reduced thus enhancing the
health of the patients. However, it is imperative to conduct a follow up analysis over the longer
period; however, the study establishes that the COBIT framework guidance to develop IT
policies and/or procedures has been very successful in achieving the organization‟s objectives
towards security, cost control, and quality care. COBIT approach as said is a structured process
and has to do with sound IT governance and can be applied in any field including the healthcare
sector.
4. Assessing Policy Coherence
4. 1 They focused on such quantitative indicators of COBIT-aligned policy coherence
Since organizations are implementing information technology for business solutions there
should be effective and coherent IT governance policies in place. COBIT is good framework that
can be employed for the purpose of evaluating and improving on the integration of IT associated
policies in an organization. However, later studies have focused on establishing a set of more
measurable figures to use for evaluating the consistencies in the policy from different
perspectives regarding to the COBIT-alignment policies.
Regarding the cohesiveness of the „big picture‟, this can be measured by the degree of
lexical repetition of the related words and phrases in the different policies. Scientists have come
up with ways of searching heuristics, through which documents on governance can be
scrutinized in order to gauge the compatibility of words and phrases used. A high degree of
Conceptual Consistency implies that there is fairly easy agreement on the quality and accuracy of
interpretation of Standards across the units. Another measures the relational organisation in set
managerial activities or control goals. COBIT control practices can be mapped against formal
policy statements while the compliance scores can be computed. This happens because the closer
the values are to the optimal value, the closer the strategies are to the best practice.
It is also quantitatively assessed concerning the degree of policy and objectives
implementation by the researchers. Surveys and questionnaires assess the perceived IT
governance consistence by incorporating employee‟s point of view. On the help desk queries
data indicates the extent to which employees make discriminations or are in conflict or have no
clear direction resulting from formalization. High risk and low accident figures show that the
relationship of disaster and risk is improving. The scan of the network traffic and security events
also helps in determination of values that are deviant from the baseline ones. Inequalities
between units indicate that the infrastructure of organizational learning or the control policies
may not be uniform across the firm. The use of these quantitative measures amalgamated
provides a more informative assessment of how policies are coherent.
The achievement of COBIT aligned policy coherence is a cycle that requires integration
at variety of levels of management. Metrics help to build the focus on the relevant areas because
the evaluation of focused areas can identify the domains that are still in need of increased
standardization. Due to the emergence of the coherence metrics study, the organizations can
compare the results with other similar organizations. Continuation of measurement also
contributes in the dynamic policy management with the change in IT contexts and business
conditions. The use of coherence dashboards in correlation with risk assessments and capability
maturity models assist the executives in organizing the objectives of the governance program and
in efficient portioning of the efforts and the financial resources. In particular, an active and
measurement-oriented approach remains relevant as a key factor to achieve further potential of
COBIT and similar IT governance frameworks.
4. 2 Analysis on the effectiveness of policy based on COBIT framework
COBIT is the source of IS practices and supporting resources for the governance and
management of enterprise IT (ISACA, 2012). COBIT is designed to enable firms to realize
strategic outcomes and create the maximum worth from information & technology. Therefore,
COBIT may be beneficial as research has indicated that utilizing it may cause improvement in
the IT governance enablers (De Haes & Van Grembergen, 2015).
There are several advantages of using COBIT as follows; It offers policy, procedure,
metrics and responsibility information for IT governance and management (Hardy, 2006). With
the help of Control Objectives, COBIT offers support to the company and proves that
information systems are beneficial for business with proper security and compliance
requirements. It ranges over many areas of IT governance including: Evaluation, Direction,
Monitoring, Design and Organization (Infotech, 2009). In each domain, COBIT allows one to
undertake a proper methodical preparation of policies that achieve the goals of the enterprise.
According to research it is stated that there are certain advantages in applying the COBIT
framework in order to promote the IT policies, practices and structures. As noted by Prasad et al.
, (2015) while researching on banking technology implementation of COBIT resulted in
improvement in the quality of the services in technology as well as the productivity of IT
processes. In turn, the efficiency of the COBIT processes can be noted reasonably regularly
creating standard technologies, and avoiding the proviso of duplicate technological solutions.
Besides, the analysis of the survey carried out among the IT audit executives shows that the first
IT structure that is controlled by COBIT processes is rather effective in identifying risks, fraud,
and weaknesses (Prasad et al., 2015).
On this account, the execution of the COBIT framework can facilitate the enterprises a
lot for floating proper IT policies and governance standards. Accordingly, COBIT creates the
comprehensive reference guide, which was previously lacking, and when followed, helps
organizations to design, build, implement and sustain the required technological environment of
the information systems that is secure, controlled and value-addition. Research has shown that is
always easier to attain strategic goals of an organization through use of IT policies and
procedures that which demonstrate control practices under COBIT.
4. 3 Self-developed COBIT Framework based policies from the perspective of
stakeholders
According to ISACA (2012), the governance of information technology has been
considered as critical for organizations in an effort to gain control over IT projects with regard to
organizational goals for the purpose of realizing value. The COBIT framework was developed
with the purpose of providing the guidelines, policies and the best practice which could be
utilized in the management of information technology in areas of security, risks and resources as
well as stakeholders requirements. COBIT frameworks should therefore be implemented by an
organization when developing its own IT polices to also consider the stakeholder‟s perspective.
The board and the executive leadership have the responsibility of ensuring that the IT
costs are well managed and that possible risks are minimised; particularly in cases concerning
the cost and the return on investment in IT. The need on fiscal responsibility and program
governance would be met by the COBIT policies on program governance, portfolio management
and value delivery. However, IT leaders may find the COBIT policies helpful that enhances and
empowers the technology groups with the required standard and power. Out of all of them,
capability building, service provisioning and information security would be the most relevant to
the Chief Information Officer. At a strategic level, the policies outline what must be
accomplished while at the control measures give more details to the IT workers.
COBIT policies must not act as an obstacle or hinder business unit leaders from operating
efficiency and dynamically. Another group of stakeholders, such as department heads, would
prefer that IT policy is specific to their region, market, or function. For instance, the digital
marketing groups may require more real-time data analysis than those of the human resource
department. COBIT elements such as control of change, quality, and the behavior of people help
to incorporate governance towards each of these particular standards. Beside, business leaders
also desire avoid IT failures to disrupt important business processes or responses. Risk
management, incident response, and service continuity are the COBIT policies that are required
by the risk management to check and balance the technology crises.
While developing the policies of COBIT, equal importance is give to the owners of data,
related to the company‟s external partners, customers and compliance. They reveal directions of
governance including ethical, transparent, private, safe and responsible innovation. Third,
globalization and augmentation of populace‟s consciousness of environmental and social
consequences argue that CEOs and stakeholders insist on environmentally friendly aspects of IT
processes and supply chains. COBIT offer focus alignment, governance oversight as well as
compliance that offer corresponding IT policies that the stakeholders will have faith in, all this
while creating business value. In total, it is important to understand that there are a lot of desires
and requirements of various people when developing the IT governance framework based on the
COBIT model which would correspond to the interests of an enterprise.
Case study: To what extent does the assessment of COBIT coherence exist in the
context of a government agency?
COBIT helps in the management and control of information and related technology hence
offering direction, recommendations, and supports that enable the organizations to incorporate,
oversee, and enhance the principles and practices of IT governance and management (ISACA,
2012). COBIT coherence should be assessed in government agencies to know whether they have
IT system and processes that will support the organization and adhere to specific guidelines.
IT is mature and large-scale in government agencies since they work with large volumes
of sensitive data. The application of COBIT helps agencies to address all the aspects of
enterprise IT management, which links business environments, IT assets, and risk management
(De Haes et al., 2013). For instance, COBIT alignment assessments can show that there are gaps
in the policies and procedures that are used in security, compliance, service delivery, or other
goals. ISACA (2012) noted that the agencies can figure out where and more governance is
needed in order to improve IT delivery for the respective agency mission.
Although there are not many studies on the adoption of COBIT in the government,
evidence from existing studies suggests that governments can benefit from improved IT
governance if they adopt COBIT. A survey of the Philippines Department of Trade and Industry
revealed that the use of COBIT facilitated enhanced IT cooperation among departments, and the
management of IT within the value system. This was accomplished by also evaluating the
process maturity and audit readiness using COBIT This assisted the department in enhancing the
IT policy and controls in relation to previous auditing problems (Calderon et al., 2012).
Likewise, the Kazakhstan government used COBIT to change IT in the Ministry of Education
and Science. Comparing the IT objectives, resources, and capabilities against the advice given by
COBIT helped the ministry to minimize the number of duplicative systems, rationalize the
provision of IT services, and enhance the sustainability of technologies to meet the national e-
government integration strategy ((Shaimergenov & Aimuratov, 2013). While these examples will
provide promising outcomes, authors pointed out that the level of COBIT adoption in public
sector might be hamper by change resistance, the low commitment by leaders and the low
awareness towards the key concepts of COBIT only (Pangil & Johari, 2013). Further maturation
assessments in collaboration with the application of COBIT control objectives may aid to the
increasing improvement of governance practices at agencies.
5. Emerging Challenges and Opportunities
5. 1 Innovation affecting COBIT based policy needs
Cybersecurity as well as the corresponding policy requirements is a dynamic field due to
innovation and technological developments. The great adoption of novelties such as cloud
services, IoT devices, AI, and Big Data has significantly increased the threat exposure to
organizations (Embrey, 2018). These technologies increases the exposure of organizations to
new emergent risks in privacy, security and ethical issues that the existing information security
frameworks such as COBIT do not fully capture. Policy makers and governance bodies therefore
have to introduce changes and new ideas within COBIT so as to adapt to these technology
disruptions.
Some of the emerging disciplines that innovation is affecting handling of some of the
COBIT policies include data privacy and ethics new technologies. This is due to advances that
have been made in the field of big data analysis and artificial intelligence that prompt data
collection as well as the use of algorithms in arriving at certain decisions. Still, Berenbach &
Chugur (2022) noted that “current regulations are fundamentally „defensive‟ and are in many
ways lagging behind compared to current AI advancements” (p. 75). This is because the role of
ethical issues is gradually rising, such as; lack of users‟ consent as well as privacy on how
algorithms deal with personal information. Currently, COBIT addresses privacy and ethics as
separate elements that need much more elaboration to offer more concrete recommendations in
the sphere including the issues like the relevant utilization of artificial intelligence, addressing
the problem of biases in data and algorithms, information transparency, and users‟ genuine
consent to the utilization of their personal data (Berenbach; Chugur, 2022).
Another area of innovation which puts pressures on changes in COBIT policies is the rise
of the IoT ecosystems that pose new risks to cybersecurity. New technologies such as smart
connected sensors, wearables and embedded systems home factories utilities and cities have
further contributed to an increase in volumes in breach and data loss (Hiller & Russell, 2017). In
interconnected, IoT one level vulnerability has a significant ripple effect that affects the system
to a large extent. However, according to Petrov & Traykov (2022), COBIT has not presented
well-developed IoT security measures regarding the encryption of the data, user identity, their
authentication and authorization processes, segmentation of the IoT network, and monitoring of
the automated attack. New features in COBIT must propose such IoT cyber risks, mobile threats,
several considerations for involving cloud, and the blockchain solution for identity and access
management for widespread and diverse such systems (Petrov & Traykov, 2022).
Though the application of COBIT has proven fruitful in the field of IT governance, the
advancement in modern technology with the AI, IoT, Cloud ecosystem and Big Data, has
rendered the existing COBIT policies insufficient to deal with new IT ethical issues particularly
with regards to privacy and security. In order to address these challenges, the policy makers
require to update some of the principles within the COBIT framework from time to time in a
responsible and ethical manner in respect of the principles of the transparency of consent, free
from algorithmic bias as the well as having comprehensive guidelines in relation to encryption,
identity management and the protection of the connected IoT systems. Failure to make such
innovative changes to the COBIT policies would imply that the threats facing majority of
organizations such as vulnerabilities and cyber risks would further increase.
5. 2 New trends in the regulation and the implication of the COBIT Framework
Enterprise IT has emerged as a critical concern in the past few years because of changing
technological trends, risk environment and regulatory requirements. COBIT: Control Objectives
for Information and Related Technologies offers enterprises a suitable reference point to help
them attain their governance and management goals (ISACA, 2012). With the increase in
complexity and spread of new technologies such as cloud computing, IoT and blockchain, new
trends in regulations and their implications have led to some modifications to COBIT.
The first one is that legislation concerning data security and privacy has still been
advanced, and these legislations are also being transplanted across various nations. For example,
the EU currently has the General Data Protection Regulation – GDPR which applies even
beyond the territory of the EU and with severe penalties for breaches (Tankard, 2016). Also,
there is other privacy regulations like the CCPA of the United States that are putting into
personal information processing new requirement. More specifics have been provided to help
organisations demonstrate their compliance with these regulations in the 2019 version of COBIT
framework that also expands the coverage of data privacy and protection controls. There are
Data inventory and map, Data breach notification, data subject rights and cross-border transfer.
The above mentioned COBIT policies and practice recommendations can also contribute to
compliance in addition to improving trust and reputation.
The other trend is the use of agile development approaches in IT governance. Governance
has followed a documented and structured approach laid down in a „water fall model‟. However,
to be ready to address business requirements at a faster and more adaptable pace, more
organizations are embracing the agile and DevOps methodologies that support constant
development and delivery of small change increments (Mahmud, 2022). It can be challenging to
introduce evolutionary changes in the older structures of governance that are compatible with
these evolved decentralized approach. In response to this, the 2019 COBIT update offers
direction on how to align risk management, compliance, and supplier management among other
practices to be effective in an agile setting (ISACA, 2019). Some of the practices that have been
recommended include creating devsecops security in development, using incremental
compliance checks, and managing vendor permissions using automation.
While it is important to maintain the current trends by enhancing the existing COBIT
framework, there is also need to ensure the professionals engaged in governance are informed of
current trends. Advanced technologies including machine learning, blockchain, and quantum
computing are likely to change the course of IT ad business in the future according to Deloitte.
To be able to offer proper oversight and make the right decisions for the firm the IT leaders and
auditors will need sufficient understanding of these innovations and their implications to the
enterprise. Among the most important goals, there should be the continued strengthening of the
IT governance competencies and learning about the areas that are still not well understood in
regards to new technologies.
To note it, the COBIT is used to develop the IT governance and management in the
enterprise on its different levels. Of all the updates that have been incorporated in guidance for
COBIT, movement on the following areas has been discovered; enhanced data privacy laws and
incorporation of the agile development process. It will also be important for the authors to
describe how the practices will be changed in order to equip the governance‟ professionals with
the required knowledge and skills for supervising new innovations. What this means is that
through governance capabilities, organizations can develop the ability to exploit the
opportunities created by the trends instead of the other way round.
5. 3 COBIT Framework that can be elated for policy
The COBIT is a framework of governance and management of enterprise information
technology that contains the best practices and techniques (ISACA, n. d. ). ISACA‟s placed
COBIT in its public domain to help organizations realize greatest value from it with affordable
risk and resource consumption (ISACA). It is applied in the IT governance, management,
assurance and performance measurement vis-à-vis business and IT objectives as postulated by
ISACA 2012. COBIT is composed of five fundamental tenets that revolve around its
stakeholders‟ requirements and these include value creation, governance infrastructure, use of a
single framework, integrated enterprise approach, and a clear separation of governance from
management (ISACA, n. d. ). Such principles shape the framework across governance and
management objectives, enablers such as processes and structures, and the measurement of
maturity levels and metrics that assess capability and progression of process against goals
(ISACA, 2012). For instance, the “Evaluate, Direct and Monitor” process has practices and
inputs to support the development of effective IT strategic policies and standards in relation to
the business goals and objectives (ISACA, 2012, p. 57).
COBIT is composed of five fundamental tenets that revolve around its stakeholders‟
requirements and these include value creation, governance infrastructure, use of a single
framework, integrated enterprise approach, and a clear separation of governance from
management (ISACA, n.d.). Such principles shape the framework across governance and
management objectives, enablers such as processes and structures, and the measurement of
maturity levels and metrics that assess capability and progression of process against goals
(ISACA, 2012). For instance, the “Evaluate, Direct and Monitor” process has practices and
inputs to support the development of effective IT strategic policies and standards in relation to
the business goals and objectives (ISACA, 2012, p. 57).
It is possible to identify the chances of linking COBIT principles and components to
policy development within the framework. Referring to Easterby-Smith, Araujo and Burgoyne
(1999) organizational policies are commonly defined written guidelines and procedures that have
been standardized due to their efficiency. As a framework, COBIT has been designed to offer a
reference model thatcodifies best practices in IT governance and management (ISACA, n. d. )
and thus from where organisational formal policy concerning IT strategy, risk, resources, data
and so on can be derived. For example, the COBIT process „Manage Human Resources‟ outlines
activities such as identification of IT skills needs and governance of practices related to staff
development, staff acquisition and staff management (ISACA, 2012, p. 95). This specific COBIT
guidance could be cited in an organization‟s policies to do with IT workforce development.
According to Fox (2009), internal contexts, evidence-based practices and the
requirements of the stakeholders should be incorporated while establishing the policy. COBIT
thus as a best practice formulation for IT governance embraces the research and insights from the
global on how IT governance can best meet the demands of the stakeholders (ISACA, n. d.). In
this case, an organization may apply COBIT research and risk/benefit/capability assessments in
the course of the environmental scans to guide policy direction. Also, relative to the stakeholder-
oriented COBIT principles, consideration should be given to internal business objectives and
management need, as well as to technological investments that are easily offered feedbacks for
aiding policies to take permanent root and be effective. Hence, irrespective of the extent to which
it has been incorporated within policy directly or incorporated as a means of providing useful
links to policy generation on the whole, existing analysis does substantiate the applicability of
COBIT in IT policy generation.
Mini-case study: Translating the need for IoT security into COBIT-based policies
SMART devices and systems which are also referred as the Internet of Things present
organizations with a number of security risks and issues as relates to the information they
generate. According to P. Smith in 2021, there are several security issues in IoT systems and
these are as follows: Weak protection of software in the devices, Users remain ignorant of
possible threats and new attack surfaces. Some of them are as follows: One of the most used
frameworks is the COBIT that has guidelines, objectives and metrics in the area of ISRM
(ISACA, 2020). To improve IoT safety, the security needs that are dictated by particular IoT
systems can be matched to the COBIT policy statements and controls. For example, Abomhara
& Køien submitted that IoT security objectives should be synchronized with the strategic COBIT
aims and information attributes linked to Business Requirements, Applications, Information,
Services & Infrastructure. COBIT has procedures regarding, access control, encryption method,
risk assessment and security attention applicable in IoT policies for managing risks, [p.12].
These above mentioned elements of COBIT can also be incorporated in policies relating to
management of assets, software upgrades, securing network, identity and access management,
incidences related to IoT etc.
As noted by Abomhara and Køien (2015), the audits of the IoT policies can be done
using the COBIT‟s Process Assessment Model to help in the identification of the levels of
compliance and the need for corrections. For instance, if an audit indicates that devices are not
correctly logged or classified, then an organization can improve asset management policies based
on the recommendations of specific COBIT processes. This ensures that the loop between IoT
policy intent and implementation is closed through conducting these aud it s based on the COBIT
framework. Repeatedly, the identified COBIT processes are applied to IoT policy areas, and the
audit checks highlight the necessity of improving policies and procedures, the IoT security
gradually becomes more elaborate.
Conclusion
Analysis of Integrated coherency in Construction of Policies as known by COBIT
Framework
IT governance is useful for an organization to enhance on the strategic directions of IT
investments and strategic plans. COBIT on the other hand is an IT governance model, which
provides control objectives for various IT processes and various areas of interest. The policies in
IT have to be developed in a way that should be concurrent and compatible with others in the
other related fields. For example, what it policies to do with infrastructure, software, data, and
security are different topics they need to have integration. The guidelines that stem from the
COBIT principles include; ability to meet the stakeholder‟s needs, increasing coverage from
enterprise end to end, use of the single framework and integration of the governance and the
management. As per provisions of COBIT, organizations can build up the relation of policies,
control objectives and measures from the strategic layers of an organization to the tactical
concern which is just below the procedures. This top-down and end-to-end approach specified
above results in integration or co-ordination between these policies. Then subsequent governance
processes can assess the level of integration of policies and the extent to which they can be re
aligned. The use of COBIT framework results in improvement of relative policies such that more
relevant and efficient policies are integrated.
Proposals for the use of the COBIT Framework and polices incorporation
COBIT gives reference and direction on how objectives apply in IT governance with
enterprise objectives (ISACA, 2012). It is however important to note that the use of COBIT can
help organizations achieve this goal of delivering the greatest possible business value of
information and technology. However, sustaining policy and process advance is vital for the
COBIT guideline implementation by adopting a strategic approach on policies and process
advances (De Haes et al., 2013). When going for adoption, the concept suggested is that it should
be done in stages and in a priority manner with a view of putting in place the right policies and
procedures. As De Haes et al. (2013) have pointed out; the first step would be to identify the
main IT governance gaps and threats that the organization would wish to tackle. After priority
areas are defined, and then it is possible to select the corresponding COBIT processes and
practices to overcome the existing gaps in the governance. For example, if information security
is one of these factors, then the management of risks, the control of access and information
security measures may predominate. Proper performance parameters can be brought out to assess
the improvements made in the areas of, concentration as stated by ISACA (2012).
The need to promote the use of COBIT practices requires the use of political policies that
lead to the enhancement of tool integration. De Haes et al. in their conducted research who also
confirmed that there exists a need to expand and revise the governance policies based on the
alterations incorporated in COBIT. The rights and responsibilities of the stakeholders on the new
COBIT processes should be defined in the policies as well as the powers of enforcing the new
policies and the body that will be held accountable. Furthermore, it is advisable to guarantee that
every participant of an organization is aware of the changes in policy and procedures. Hence
through logical connections of cognitive operations with policies that can be applied to the use of
COBIT in certain contexts, the organizations are well placed in enhancing on the challenges
regarding integration of governance. Where the stakeholder buy-in and the governance capability
rises further down the line, the extra of the COBIT processes can be applied with the relevant
policies. That is why phased approach is the best; it offers a manner in which the change can be
put into practice while gradual transitions are made based on the portions that are easy to handle.
Where governance practices are institutionalized, there is improved possibilities to integrate
additional processes thus achieving the right balance between IT and business process
optimization (ISACA2012). These policies and procedures thus improve the practices of COBIT
in an organization as the framework continues to suit needs of different institutions.
Sources
Abomhara, N., & Køien, G. M. (2015). Cyber security and the internet of things: Risk factors,
risks, invaders and incidents. Journal of Cyber Security and Mobility, 4(1), 65–88.
https://doi.org/10.13052/jcsm2245-1439.414
Alberts, C. J., & Dorofee, A. (2010) Rethinking the audit. IT Pro(May/June 2010), 24-26.
Barafort, B., Mesquida, A. L., & Mas, A. (2020). Integrating IT service management
frameworks: A systematic literature review. IT Professional, 22(1), 28-36.
https://doi.org/10.1109/MITP.2019.2963913
Berenbach, B., & Chugur, S. (2022). AI ethics and policy. Project Management Institute. Credo
https://go.openathens.net/redirector/carleton.ca?url=https%3A%2F%2Fsearch.credorefer
ence.com%2Fcontent%2Fentry%2Fpmipmi%2Fai_ethics_and_policy%2F0%3Finstitutio
nId%3D2134
Brown, J. (2022). Preparing for the worst: Creating an incident response plan. Journal of
Information Security, 18(2), 153-167. https://doi.org/10.32674/jis.v18i2.2513
Calderon, R. D. L., Avena, L. A. L., & Caliwag, M. C. (2012). IT governance in a government
organization in the Philippines: A case study. Journal of Global Information Technology
Management , 15(2), 57-87.. https://doi.org/10.1080/1097198X.2012.10845628
Cho, S., Chen, K., & Chi, S. D. (2019). Auditing IT Governance Accountability and Trust: The
Role of COBIT 5. Int'l Management Accounting Conf.(IMAC 2019).
https://scholarworks.sjsu.edu/mktds_pub/2
CIS or Center for Internet Security. (2022). CIS controls. CIS.
https://www.cisecurity.org/controls
COBIT (2019). COBIT 2019 framework: overview and approach. ISACA.
https://www.isaca.org/resources/cobit
Coordinated by the Cybersecurity and Infrastructure Security Agency. (2022). Joint cyber
defense collaborative. https://www.cisa.gov/jcdc
Damianides, M. (2005). Sarbanes-Oxley and IT governance: New information concerning IT
control and compliance. International Journal of Information Systems Management,
22(1), 77–85. https://doi.org/10.1201/1078.10580530/46352.22.1.20051201/90018.10
ISACA. (2012). COBIT 5 framework. ISACA. https://www.isaca.org/resources/cobit
De Haes S, Van Grembergen W. IT governance in the enterprise. Springer.
De Haes, S., & Van Grembergen, W. (2020, May 5). Exploring the correlation between the two
frameworks of COBIT and ITIL. International Journal of IT/Business Alignment and
Governance, 11(1), 34–51. https://doi.org/10.4018/IJITBAG.2020010103
De Haes, S., Van Grembergen, W., & Debreceny, R. S. (2013). COBIT 5 and enterprise
governance of information technology: Components and sources of knowledge in physics
education. Journal of Information Systems, 27(1): 307-324. https://doi.org/10.2308/isys-
50422
De Haes, S., Van Grembergen, W., & Debreceny, R. S. (2013). COBIT 5 and enterprise
governance of information technology: Tools and resources for constructing knowledge.
Journal of Information Systems, 27(1), 307-324. https://doi.org/10.2308/isys-50422
Deloitte. (2022). Tech trends 2022. https://www2.deloitte.com/xe/en/insights/focus/tech-
trends.html
Easterby-Smith, M., Araujo, L., & Burgoyne, J. (1999). Organizational learning and the learning
organization: New trends in theory and practice. SAGE.
Elena Petrov and Mimi Traykov. (2022). An analysis of the literature on the different
cybersecurity capability maturity models for IoT. Computer Standards & Interfaces, 82.
https://doi.org/10.1016/j.csi.2021.103556
Embrey, M. (2018). Evolution of cybersecurity requirements. TechTarget.
https://www.techtarget.com/searchsecurity/tip/Evolution-of-cybersecurity-requirements
ENISA. (2020). Having an efficient risk management & risk assessment system is vital in the
identification of any side effects that may be associated with the use of this drug.
https://www.enisa.europa.eu/topics/threat-risk-management/risk-management
Etsy. (2022). Etsy security policy. https://www.etsy.com/legal/etsy-security-policy/
Federal Trade Commission. (2022, June 22). Gramm-Leach-Bliley Act. https://www.ftc.gov/tips-
advice/business-center/privacy-and-security/gramm-leach-bliley-act
Fox, F. (2009). Handbook on capacity building policy development. Link Community
Development.
Gerke, D., & Ridley, G. (2021). : IT governance frameworks and cybersecurity readiness.
Information Technology & People. https://doi.org/10.1108/ITP-12-2020-0909
Hadar, E., Itzhak, H. B., & Itzhak, B. (2014). Proposed framework for implementing COBIT 5 in
Israeli local authorities. Journal of Global Information Management, 22(4), 1–21.
https://doi.org/10.4018/jgim.2014100101
Hardy, G. (2006). Application of IT governance and COBIT to create value with IT and manage
legal, regulatory and compliance requirements. Information Security Technical Report,
11(1), 55-61.
Hiller, J., & Russell, R. S. (2017). The challenge and imperative of private sector cybersecurity:
A comparative analysis. Computer Law & Security Review , 33(3), 238-245.
https://doi.org/10.1016/j.clsr.2017.03.003
Hilton. (2022). Hilton privacy statement. https://www.hilton.com/en/privacy-statement/
Hua, Jing, and Ravi Bapna. Public–private partnerships for cybersecurity: Returns and
recommendations of government-business cooperation. The Palgrave Handbook of
Cybersecurity and Public Policy 1-27. https://doi.org/10.1007/978-3-030-10576-6_78-1
IBM. (2022). Price of a data breach report 2022.
https://www.ibm.com/downloads/cas/OJDVQGRY
Information Systems Audit and Control Association (ISACA). (2012). COBIT 5: A business
framework that supports the governance and management of enterprise IT. Rolling
Meadows, IL: Author.
Information Systems Audit and Control Association. (2019). COBIT 2019 framework:
introduction and methodology. ISACA. https://www.isaca.org/resources/cobit
Infotech. (2009). COBIT introduction [Powerpoint slides]. SlideShare.
https://www.slideshare.net/infotech/cobit-introduction
ISACA. (2012). COBIT 5: A business framework for the stewardship of enterprise IT. ISACA.
https://www.isaca.org/resources/cobit
https://www.isaca.org/resources/cobit/focus/pages/cobit-5-enabling-processes.aspx
ISACA. (2012). COBIT 5: Enterprise IT governance and management framework. ISACA.
ISACA. (2012). COBIT 5: It is the business framework that is used in the governance and
management of enterprise IT. https://www.isaca.org/resources/cobit
ISACA. (2019). COBIT 2019 framework: introduction and methodology.
https://www.isaca.org/resources/cobit/cobit-2019-design-guide
ISACA. (2020). The introduction of the COBIT framework: A brief overview of the
methodology used. https://www.isaca.org/resources/cobitb
ISACA. (n.d.). An introduction to the COBIT 2019 framework and an outline of its
methodology. https://www.isaca.org/resources/cobit
J. Lee & Y. Lee (2021). Threat modeling for cybersecurity. IEEE Access, 9, 14712–14730.
https://doi.org/10.1109/access.2021.3052284
Smith, J. J. (2022). Cyber threats of the year 2022. Cyberthreat Journal 19(2), 44-61.
https://doi.10.12978/ctj.19-2.4461
Jones, A. (2020). Enterprise cybersecurity risk management. Mcgraw Hill.
Jones, A. (2022). Towards an ethical framework for surveillance in cyberspace enabled by an
increase in remote working. Journal of Business Ethics. https://doi.org/10.1007/s10551-
022-05271
Lee, M. (2021). It was evident from a study of the outlined cybersecurity policies that they
influence business performance. Journal of cyber policy, 6(2), 195–216.
https://doi.org/10.1080/23738871.2021.1908636
Mahmud, R. (2022). Corporate governance mechanisms and IT governance in agile software
organizations. COBIT Focus, 1(1), 41-43. https://www.isaca.org/resources/news-and-
trends/isaca-now-blog/2022/it-governance-in-agile-software-organizations
Online Trust Alliance. (2018, April). Cyber Security as a policy and…policy architectures.
https://www.internetsociety.org/resources/doc/2018/cybersecurity-policies-structures/
Pangil, F., & Johari, J. (2013, November). Analyzing theoretical construct concerning the
adoptability towards public sector IT/IS application. The paper was presented in
Proceedings of the 8th International Conference on Information Technology in Asia
(CITA 13) held in Serdang, Malaysia.
Park, E. H., Kim, J., & Park, M. C. (2022). Information security policy compliance: Application
of both rational choice theory and self-control theory. Information Systems Frontiers,
24(3), 521–539. https://doi.org/10.1007/s10796-019-09946-y
Prasad, A., Green, P., & Heales, J. (2015). On structures in IT governance and the utility of
collaborative structures in organizational structures. Available at: International Journal of
Accounting Information Systems, 13(3), 199-220.
Ridley, G; Young J; & Carroll P (2004). COBIT and its utilization: A framework borrowed from
the literature. HICSS 37, 2004. Proceedings of the. IEEE.
https://doi.org/10.1109/hicss.2004.1265478
Sayana, S. A. (2002 January). The IS audit process. Information Systems Control Journal, 1(1),
3-6.
Shaimergenov, A. E., & Aimuratov, Y. E. (2013). The use of COBIT for managing the process
of education informatization. WASJ, 26(11), 1484-1488.
https://doi.org/10.5829/idosi.wasj.2013.26.11.13801
SIMONSSON, M & JOHNSON, P. (2005, May). Towards defining IT governance-A review of
literature. It is observed in the 18th NFF conference (pp.1-19).
Simonsson, M. & Johnson, P. (2005). While defining IT governance IT governance could be
characterized as: A consolidation of literature. Stockholm University.
Smith, J. (2020). Developing legally sound cybersecurity policies. Journal of Law and Cyber
Warfare, 3(2), 100-122. https://doi.org/10.5038/2378-0789.3.2.1041
Smith, J. (2021). Access controls, awareness, and response: Information security support.
International Journal of Cybersecurity Intelligence and Cybercrime, 4(1), 5-19.
Smith. A. (2021). Exploring security in internet of things (IoT): A review. Volume 2, Number 1,
pp. 1-9, Forensic Science & Technology. https://doi.org/10.3390/jrfst2010001
Tankard, C. (2016). The necessity and consequences of the GDPR for businesses. Network
Security, 2016(6), 5-8. https://doi.org/10.1016/S1353-4858(16)30056-3
Tetlay, A., & John, P. (2022). Security compliance and security risk assessment – which one is
necessary? PhoenixNAP Global IT Services. https://phoenixnap.com/blog/security-
compliance-vs-risk-assessment
The Institute of Internal Auditors, ISACA – Information Systems Audit and Control Association.
(2012). COBIT 5: Enterprise IT governance and management in the context of business.
ISACA.
https://www.isaca.org/resources/cobit
Tuttle, B., & Vandervelde, S. D. (2007). Empirical analysis of COBIT as an internal control
system on information technology. Vol. 8, No. 4, pp 240-263 for International Journal of
Accounting Information Systems. https://doi.org/10.1016/j.accinf.2007.09.001
Velcu, O. (2010). Strategic alignment of ERP implementation stages: A quantitative work.
Information & Management, vol. 47, no. 3, pp. 158–166.
https://doi.org/10.1016/j.im.2010.01.005