IIA CYBERSECURITY TOPICAL REQUIREMENT AND ISO/IEC 27001
Haris Hamidović · MEST Journal · 2025
Cyber security protects an organization's information assets from unauthorized users, disruption, alteration, or destruction and strengthens the overall control environment to reduce risk. Cyber attacks can lead to direct and indirect effects that are often significant, as computers, networks, programs, data, and sensitive information are critical components of most organizations. Because organizations rely heavily on information technology resources, a clearly defined cybersecurity plan, objectives, inherent risks, and effective controls should be a priority for management. The IIA Cybersecurity Topical Requirement provides a consistent, comprehensive approach to assessing the design and implementation of cybersecurity governance, risk management, and control processes. The IIA's activities on the Cybersecurity Topical Requirement development will certainly contribute to increasing the cyber security level in business organizations. Given that it is possible to map the requirements from the IIA Cybersecurity Topical Requirement with the requirements from the ISO/IEC 27001 standard, it would be more than useful to use the existing good practices and experience related to the use of ISO/IEC 27001 and related standards in terms of practical implementation and assessment of compliance with IIA requirements. In this paper, we present one of the possible ways how the good practices of the international standard ISO/IEC 27001 can be used to assess the level of compliance with the IIA Cybersecurity Topical Requirement.