COBIT Focus Area: Information Security provides guidance related to information security and how to apply COBIT to specific information security topics/practices within an enterprise. The publication is based on the COBIT core guidance for governance and management objectives, and enhances the core guidance by highlighting security-specific practices and activities as well as providing information security-specific metrics.
In COBIT 2019, a focus area describes a certain governance topic, domain or issue that can be addressed by a collection of governance and management objectives and their components. This publication describes information security and details additional metrics and activities that should be considered when implementing or assessing COBIT in the context of information security.
Key publication details include:
- Provides a contemporary view on information security governance and management
- Clarifies roles of governance and management and shows how they relate to each other in the context of information security
- Provides a clear end-to-end view into distinction within the enterprise and during all process steps between information security governance and information security management practices
- Provides a comprehensive and holistic guidance on information security – not only to processes but to all components in an enterprise, including organization structure, skills, policies, etc.
- Additional information security-specific activities, metrics and information flows.