Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Cobit 5 iso 27001 mapping

18/03/2021 Client: saad24vbs Deadline: 2 Day

CSIA 350: Cybersecurity in Business & Industry

Project #1: Integrating NIST’s Cybersecurity Framework with Information Technology Governance Frameworks
Scenario
You have been assigned to your company’s newly established Risk Management Advisory Services team. This team will provide information, analysis, and recommendations to clients who need assistance with various aspects of IT Risk Management.

Your first task is to prepare a 3 to 4 page research paper which provides an analysis of the IT Governance, IT Management, and Risk Management issues and problems that might be encountered by an e-Commerce company (e.g. Amazon, e-Bay, PayPal, etc.). Your paper should also include information about governance and management frameworks that can be used to address these issues. The specific frameworks that your team leader has asked you to address are:

· ISO/IEC 27000 Family of Standards for Information Security Management Systems

· ISACA’s Control Objectives for Information Technology (COBIT) version 5

· NIST’s Cybersecurity Framework (also referred to as the “Framework for Improving Critical Infrastructure Security”)

The Risk Management Advisory team has performed some initial research and determined that using these three frameworks together can help e-Commerce companies ensure that they have processes in place to enable identification and management of information security related risks particularly those associated with the IT infrastructure supporting online sales, payment, and order fulfillment operations. (This research is presented in the Background section below.) Your research paper will be used to extend the team’s initial research and provide additional information about the frameworks and how each one supports a company’s risk management objectives (reducing the risks arising from cyber threats and cyberattacks against information, information systems, and information infrastructures). Your research should also investigate and report on efforts to date to promote the use both frameworks at the same time.

Your audience will be members of the Risk Management Services team. These individuals are familiar with risk management processes and the e-Commerce industry. Your readers will NOT have in-depth knowledge of either framework. For this reason, your team leader has asked you to make sure that you include a basic overview of these frameworks at the beginning of your paper for the benefit of those readers who are not familiar with CSF and COBIT.

Background
Security Controls
Security controls are actions which are taken to “control” or manage risk. Security controls are sometimes called “countermeasures” or “safeguards.” For this assignment, it is important to understand that it is not enough to pick or select controls and then buy or implement technologies which implement those controls. A structure is required to keep track of the controls and their status -- implemented (effective, not effective) and not implemented. The overarching structure used to manage controls is the Information Security Management System.

Information Security Management System (ISMS)
An Information Security Management System is the set of policies, processes, procedures, and activities used to structure the organizational unit which is responsible for managing the cybersecurity or information security program in a business. Companies can and do design their own structure for this program including: scope, responsibilities, and resources. Many companies, however, choose to use a defined standard to provide guidance for the structure and functions assigned to this organization. The ISO/IEC 27000 family of standards is one of the most frequently adopted and is comprised of best practices for the implementation of an information security program. The ISO/IEC 27001 standard specifies the requirements for and structure of the overall Information Security Management System and ISMS program. The ISO/IEC 27002 standard provides a catalog of security controls which can/should be implemented by the ISMS program. For additional information about the standards, please see this blog https://www.itgovernance.co.uk/blog/what-is-the-iso-27000-series-of-standards.

Note: there are a number of free resources which describe the contents and purposes of the ISO/IEC 27000 family of standards. For your work in this course, you do not need access to the official standards documents (which are not freely available).

Control Objectives for Information Technology (COBIT)
COBIT is a framework that defines governance and management principles, processes, and organizational structures for enterprise Information Technology. COBIT includes a requirement for implementation of an Information Security Management System and is compatible with the ISO/IEC 27000 series of standards for ISMS implementation.

COBIT 5 has five process areas which are specified for the Governance and Management of enterprise IT. These areas are:

· Evaluate, Direct, and Monitor (EDM)

· Align, Plan, and Organize (APO)

· Build, Acquire, and Implement (BAI)

· Deliver, Service, and Support (DSS)

· Monitor, Evaluate, and Assess (MEA)

Beginning with version 5, COBIT has incorporated Information Security as part of the framework. Three COBIT 5 processes specifically address information security: APO 13 “Manage Security,” DSS04 “Manage Continuity,” and DSS05 “Manage Security Services.”[footnoteRef:1] [1: Source: http://www.isaca.org/COBIT/Documents/COBIT-5-for-Information-Security-Introduction.pdf ]

NIST Cybersecurity Framework (CSF)
The NIST Framework for Improving Critical Infrastructure Security, commonly referred to as the Cybersecurity Framework or CSF, was developed in collaboration with industry, government, and academia to provide a common language and common frame of reference for describing the activities required to manage cyber-related risks and, in so doing, protect and defend against cyber attacks. Unlike many NIST guidance documents, the CSF was designed specifically for businesses – to meet their needs and support attainment of business objectives. Originally designed for companies operating in the 16 critical infrastructure sectors, the CSF is now being required of federal government agencies and departments and their contractors. The Executive Summary of the NIST CSF version 1.1 provides additional background and supporting information about the purposes, goals, and objectives of the CSF.

The Cybersecurity Framework is presented in three parts:

· Core Functions (Identify, Protect, Detect, Respond, Recover)

· Implementation Tiers (risk management processes and practices)

· Profiles (specific to a business or industry – goals and desired outcomes)

Commonalities between ISO/IEC 27000, COBIT, and NIST CSF
There are a number of common elements between the information security frameworks defined in the ISO/IEC 27000 family of standards, the COBIT standard, and the NIST Cybersecurity Framework. Each of these frameworks addresses risks that must be addressed by businesses that depend upon digital forms of information, information systems, and information infrastructures. Each framework presents structured lists of IT Governance and IT Management activities (processes and practices) which must be adopted and implemented in order to effectively manage risk and protect digital assets from harm or loss. Each framework also provides a list or catalog security. Each framework also provides lists of goals or objectives which must be met in order to assure the effectiveness of controls implemented to defend against cyber threats and attacks.

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Financial Assignments
Math Exam Success
Chartered Accountant
Quick Mentor
Calculation Master
University Coursework Help
Writer Writer Name Offer Chat
Financial Assignments

ONLINE

Financial Assignments

I will cover all the points which you have mentioned in your project details.

$34 Chat With Writer
Math Exam Success

ONLINE

Math Exam Success

I have read and understood all your initial requirements, and I am very professional in this task.

$39 Chat With Writer
Chartered Accountant

ONLINE

Chartered Accountant

I am known as Unrivaled Quality, Written to Standard, providing Plagiarism-free woork, and Always on Time

$34 Chat With Writer
Quick Mentor

ONLINE

Quick Mentor

I have read your project details. I can do this within your deadline.

$15 Chat With Writer
Calculation Master

ONLINE

Calculation Master

I have read your project details. I can do this within your deadline.

$35 Chat With Writer
University Coursework Help

ONLINE

University Coursework Help

I will cover all the points which you have mentioned in your project details.

$18 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

Lnat practice multiple choice - 4.5 9 distance in kilometers codehs - Career spectrum scavenger hunt - Difference between protista and fungi - The early abbasid caliphate hugh n kennedy - You got a ticket in your hand essay - Znajdź Najlepsze Dzwonki MP3 Tutaj! - NURS340REPLY - Swot analysis of ferrero rocher - Strategic plan part iii: balanced scorecard and communication plan - If common stock is issued for an amount greater - Group project - Smith chart matching network - Aace thyroid ultrasound course - Discussion - What does a patent examiner do - Film Review - Resource pooling architecture in cloud computing - Crescent pure case study marketing research - Everybody loves raymond aunt serena - Randomized Clinical Trial” (Nyamathi et al.,2015), - Are original xbox dvd drives interchangeable - Observing chemical reactions lab report - Animal farm chapter 9 summary - Microbiology - Fun home chapter 1 pdf - Concepts and theories in nursing - Lincoln hall university of nottingham - Wrong one - Rosa dias costume designer - How do ticker timers work - Insights Into Criminal Behavior - Essay - Anderson's business law 23rd edition pdf free download - Review the steps of the Systems Development Life Cycle (SDLC) and reflect on the scenario presented. - EARLY CHILDHOOD - A linear downward sloping demand curve is - Biology - Macroeconomics chapter 1 - Staple stock walmart - Essay - Another word for body odor - Money madness poem stanza wise explanation - Pooled standard deviation calculator excel - There are only two naturally occurring isotopes of copper - Growth and Development - Which one doesn't belong shapes - If zappos wanted to utilize data mining they might - Society and culture pip ideas - Clipsal phone mech wiring - Change of base formula - Label plant cell worksheet - Draw an aoa network diagram representing the project - Please enter your pin followed by the hash key myntra - Where do decomposers come from - Who owns the elder wand after dumbledore - Abbey college rto manager - Unconditional positive regard definition - Father joseph tran perth - Timberjack parts case study - Bill inmon vs ralph kimball - The Destruction of The Fahrenheit 451 - Crowned head of an oni - Torrance j.colvin - Harvard global supply chain management simulation - 21967 brookside ave elkhorn ne - Giving voice to values curriculum - Which theory is criticized for being too mechanistic - The most important person in my life essay father - Role play nurse script - Immigrants from the Middle East Before and After 9/11 - Telescopes from the ground up - Parts of a recipe - The rotor shaft of the helicopter is subjected to - Giorgione's painting the tempest paved the way for future - Is 31 a rational number - Patricia benner domains of nursing practice - Scale model of the solar system activity - Discussion - Chapter 26 the triumph of conservatism 1969 1988 - Today learning exp 105 - Walkera g 3d manual - Bolman and deal four frames - Is yeast an r selected or k selected species - Baw baw planning permits - Understanding the difference between a discriminative stimulus - Movement analysis worksheet what is kinesiology - Planting caladium bulbs upside down - Dewey decimal system example - 2 coments each one 150 words (CITATION AND REFERENCE) - Commonwealth coat of arms flag - Enthalpy of neutralization of hcl and naoh lab report - Organizational development case study analysis - One ethic dilemma and the role of the ethics committee in the health services system. - Counseling older clients - Shadow health neurological assessment subjective data - Where does lululemon manufacture - Working memory model phonological loop - Problem - Solution Essay - Duckweed population growth lab answers