A manufacturing group has adopted ISO/IEC 27001 for its certified information security management system, but the board now wants assurance that security investment decisions, accountability, and benefits realisation align with wider enterprise IT governance. The information security manager is asked which framework best complements the existing standard to address that specific gap. Which choice is most appropriate?
- AAdopt COBIT to provide enterprise governance and management objectives that connect security to business value and accountability. Correct
- BReplace ISO/IEC 27001 with the NIST Cybersecurity Framework to obtain a governance-led structure for the whole programme.
- CImplement ISO/IEC 27002 so the organisation has a richer catalogue of controls to satisfy the board's request.
- DMap the ISMS to ISO/IEC 27004 so security metrics demonstrate governance to the board.
Why A is correct: COBIT is a governance and management framework that links IT and security activities to enterprise objectives, value delivery, and clear accountability, which is exactly the assurance the board is seeking.
Why B is wrong: The NIST CSF does include a Govern function, which makes this tempting, but it is a voluntary control and outcome framework rather than an enterprise IT governance model, and discarding a certified ISMS to gain governance is disproportionate and unnecessary.
Why C is wrong: ISO/IEC 27002 expands control guidance, which sounds helpful, but the board asked about investment decisions, accountability, and benefits realisation, which are governance concerns that a control catalogue does not address.
Why D is wrong: ISO/IEC 27004 covers measurement of information security performance, which is useful for reporting, but measurement alone does not establish the value, accountability, and decision rights that enterprise governance requires.