Using the NIST Framework and COBIT 2019 in Offering Cybersecurity Consulting and Assurance Services
Jeffrey S. Zanzig · Advances in information security, privacy, and ethics book series · 2022
Information processing in a cyber environment offers tremendous benefits but is also accompanied by inevitable dangers including compromised confidentiality and malware such as ransomware that can shut down major segments of a country's operations. A variety of forms of guidance and regulation have been developed to deal with these cybersecurity issues. The professions of public accounting and internal audit have long worked with organizations to protect the integrity of their information systems. Both of these professions are working diligently to guide organization management in the area of cybersecurity. An important aspect of such services is an appropriate framework to use as a basis for advisement and assurance. One such framework is the Framework for Improving Critical Infrastructure Cybersecurity issued by the National Institute of Standards and Technology.