5.1 Cybersecurity & IT Risk Frameworks

Key Takeaways

  • NIST Cybersecurity Framework (CSF) 2.0 expands coverage from critical infrastructure to all enterprise organizations and introduces the 'Govern' function alongside Identify, Protect, Detect, Respond, and Recover.
  • COBIT 2019 establishes an explicit boundary between Governance (evaluating, directing, and monitoring under 5 EDM objectives) and Management (planning, building, running, and monitoring under 35 objectives across APO, BAI, DSS, and MEA).
  • ISO/IEC 27001 specifies requirements for an Information Security Management System (ISMS), while ISO/IEC 27002:2022 provides 93 baseline controls organized across four themes: Organizational, People, Physical, and Technological.
  • The COSO Enterprise Risk Management (ERM) framework integrates cybersecurity risk appetite and tolerance into business strategy and financial performance, bridging technical security metrics to enterprise governance.
  • IT auditors utilize capability maturity models (CMMI Levels 0 to 5) and framework mappings to substantiate management assertions regarding the operating effectiveness of IT General Controls (ITGCs) and SOC 2 Trust Services Criteria.
Last updated: September 2026

5.1 Cybersecurity & IT Risk Frameworks

Quick Answer: Modern enterprises manage cyber risk by aligning information technology operations with recognized governance and cybersecurity frameworks. On the CPA Information Systems and Controls (ISC) exam, candidates must master four foundational frameworks: NIST CSF 2.0 (with its cross-cutting Govern function), COBIT 2019 (distinguishing Governance EDM from Management PBRM across 40 objectives), ISO/IEC 27001/27002 (formal ISMS and 93 controls), and COSO ERM (linking cyber risk appetite to enterprise strategy). IT auditors rely on these frameworks to design audit programs, evaluate IT General Controls (ITGCs), and assess SOC 2 Trust Services Criteria.


1. Why Organizations Adopt IT Governance Frameworks

Enterprise information systems process, store, and transmit massive volumes of financial transactions and proprietary data. In the absence of structured governance, cybersecurity becomes reactive, fragmented, and vulnerable to systemic failure. Framework adoption delivers four indispensable business benefits:

  1. Common Lexicon and Shared Understanding: Frameworks provide standardized terminology across the board of directors, executive leadership, internal audit, and technical IT engineering teams.
  2. Repeatable, Defensible Risk Management: Rather than relying on ad hoc decisions, organizations implement structured risk identification, threat assessment, and control calibration processes.
  3. Regulatory and Legal Defensibility: Adopting industry-standard frameworks provides evidence of "due care" and "due diligence" during regulatory inquiries (e.g., SEC cybersecurity disclosure rules, FTC enforcement) or post-breach litigation.
  4. Audit and Assurance Baseline: Certified Public Accountants (CPAs) and internal auditors utilize frameworks to evaluate the design and operating effectiveness of internal controls over financial reporting (ICFR) and to conduct System and Organization Controls (SOC) attestation engagements.

2. NIST Cybersecurity Framework (CSF) 2.0: Architecture & Core Functions

Originally released by the National Institute of Standards and Technology (NIST) in 2014 for critical infrastructure operators, the framework received a major structural modernization in February 2024 with the publication of NIST CSF 2.0.

Scope Expansion Beyond Critical Infrastructure

NIST CSF 2.0 formally expanded its scope beyond critical infrastructure to apply universally to all organizations—regardless of size, sector, or technical sophistication. Whether auditing a multinational bank, a cloud software vendor, or a mid-sized healthcare provider, CPAs encounter NIST CSF 2.0 as the prevailing benchmark for enterprise cybersecurity posture.

The Six Core Functions

The core of NIST CSF 2.0 comprises six concurrent and continuous functions. The most significant structural change in version 2.0 was the addition of the Govern function, which operates as an overarching, cross-cutting foundation that directs the other five operational functions.

                    ┌─────────────────────────┐
                    │       GOVERN (GV)       │
                    │ Context, Strategy, Risk │
                    │ Roles & Supply Chain    │
                    └────────────┬────────────┘
                                 │ Directs & Informs
         ┌──────────────┬────────┼──────────────┬──────────────┐
         ▼              ▼        ▼              ▼              ▼
  ┌────────────┐ ┌────────────┐ ┌────────────┐ ┌────────────┐ ┌────────────┐
  │IDENTIFY(ID)│ │PROTECT(PR) │ │ DETECT(DE) │ │RESPOND(RS) │ │RECOVER(RC) │
  │  Assets &  │ │ Safeguards │ │ Continuous │ │ Incident   │ │ Resilience │
  │   Risks    │ │  & Access  │ │ Monitoring │ │ Mitigation │ │& Restorat. │
  └────────────┘ └────────────┘ └────────────┘ └────────────┘ └────────────┘
FunctionFunction CodeOperational PurposeKey Categories & CPA Audit Focus
GovernGVEstablishes and monitors the organization's cybersecurity risk management strategy, expectations, roles, and supply chain oversight.Organizational Context: Understanding legal/regulatory requirements.<br/>Risk Management Strategy: Establishing cybersecurity risk appetite.<br/>Cybersecurity Supply Chain Risk Management (C-SCRM): Third-party vendor assessment.<br/>Oversight: Board-level review of cybersecurity posture.
IdentifyIDDetermines current cybersecurity risks to systems, people, assets, data, and capabilities.Asset Management: Inventories of physical hardware, software, and cloud resources.<br/>Risk Assessment: Vulnerability identification and threat likelihood estimation.<br/>Improvement: Incorporating lessons learned into risk processes.
ProtectPRSupports the ability to secure assets and mitigate the impact of potential cybersecurity events.Identity Management & Access Control (IAM): Least privilege, MFA, RBAC.<br/>Awareness & Training: Employee anti-phishing education.<br/>Data Security: Encryption at rest and in transit, data loss prevention (DLP).<br/>Platform Security: Hardening, configuration management, patch schedules.
DetectDEEnables timely discovery and analysis of anomalous cybersecurity events and potential compromises.Continuous Monitoring: Network monitoring, endpoint detection and response (EDR), SIEM log ingestion.<br/>Adverse Event Analysis: Triage of security alerts and indicator of compromise (IoC) detection.
RespondRSSupports the ability to contain and mitigate the operational and financial impact of a cybersecurity incident.Incident Management: Execution of incident response plans (IRPs).<br/>Incident Analysis: Forensics and containment root-cause investigation.<br/>Communication: Coordinated disclosure to executive leadership, regulators, legal counsel, and law enforcement.
RecoverRCSupports timely restoration of normal operations to reduce the effects of a cybersecurity incident.Incident Recovery Plan Execution: Restoring systems from verified clean backups.<br/>Post-Incident Review: Updating recovery strategies and business continuity plans based on actual event retrospectives.

Implementation Tiers (Tiers 1 through 4)

NIST CSF categorizes an organization's cybersecurity practices into four Implementation Tiers. Tiers reflect a progression from informal, reactive responses to agile, risk-informed processes:

  • Tier 1: Partial: Cybersecurity risk management is ad hoc, informal, and reactive. There is limited enterprise-wide awareness, and risk is managed in silos without formal executive oversight.
  • Tier 2: Risk Informed: Risk management practices are approved by management but are not established as an organization-wide policy. Resource allocation is informed by risk, but coordination across business units remains inconsistent.
  • Tier 3: Repeatable: Organization-wide policies exist, are formal, and are consistently implemented across all business units. Practices are regularly reviewed, updated, and communicated to staff.
  • Tier 4: Adaptive: The organization continuously adapts its cybersecurity practices based on lessons learned, predictive analytics, and evolving threat intelligence. The entity actively responds to advanced threats before incidents occur.

Exam Watch: Implementation Tiers do not represent maturity levels that every organization must advance through to reach Tier 4. Instead, an entity selects its target Tier based on its specific business goals, regulatory environment, and risk appetite. A small regional retail business may appropriately operate at Tier 2 or 3, whereas a global payment processor processing trillions in transactions requires Tier 4.

CSF Profiles: Current Profile vs. Target Profile

A Cybersecurity Profile aligns the CSF Functions, Categories, and Subcategories with the organization's business requirements, risk tolerance, and resources. Organizations construct two profiles:

  1. Current Profile ("As-Is"): Documents the cybersecurity outcomes currently being achieved.
  2. Target Profile ("To-Be"): Details the outcomes required to satisfy the organization's target risk management objectives.
  3. Gap Analysis: The delta between Current and Target Profiles defines the prioritized remediation roadmap evaluated by management and auditors.

3. COBIT 2019: Governance vs. Management Demarcation

Developed by the Information Systems Audit and Control Association (ISACA), COBIT 2019 (Control Objectives for Information and Related Technologies) is the premier enterprise IT governance framework. For CPA auditors, COBIT is critical because it bridges enterprise financial reporting objectives with underlying IT control mechanisms.

The Fundamental Demarcation: Governance vs. Management

COBIT 2019 makes a strict conceptual and operational distinction between Governance and Management:

  • Governance: The responsibility of the Board of Directors and executive governing body. Governance ensures that stakeholder needs, conditions, and options are evaluated to determine balanced enterprise objectives; directs prioritization and decision-making; and monitors performance and compliance against agreed-upon direction.
  • Management: The responsibility of Executive Leadership (e.g., CEO, CIO, CISO) and operational staff. Management plans, builds, runs, and monitors activities in alignment with the direction set by the governance body to achieve enterprise objectives.
┌─────────────────────────────────────────────────────────────────────────────┐
│                            ENTERPRISE GOVERNANCE                            │
│                        (Board of Directors / Trustees)                      │
│                                                                             │
│                Evaluate Stakeholder Needs ──▶ Direct Strategy               │
│                                ▲                     │                      │
│                                └──── Monitor ◀───────┘                      │
│                                                                             │
│                           [ EDM Domain: 5 Objectives ]                      │
└──────────────────────────────────────┬──────────────────────────────────────┘
                                       │ Sets Direction & Policy Boundaries
                                       ▼
┌─────────────────────────────────────────────────────────────────────────────┐
│                            ENTERPRISE MANAGEMENT                            │
│                           (Executive Management / IT)                       │
│                                                                             │
│    ┌──────────────┐      ┌──────────────┐      ┌──────────────┐            │
│    │ Plan (APO)   │ ───▶ │ Build (BAI)  │ ───▶ │  Run (DSS)   │            │
│    │ 14 Objectives│      │ 11 Objectives│      │ 6 Objectives │            │
│    └──────────────┘      └──────────────┘      └──────────────┘            │
│            ▲                                          │                    │
│            └──────────── Monitor (MEA) ───────────────┘                    │
│                           4 Objectives                                      │
└─────────────────────────────────────────────────────────────────────────────┘

The Five COBIT 2019 Domains and 40 Core Objectives

COBIT 2019 organizes IT activities into 40 Core Governance and Management Objectives grouped across five distinct domains:

  1. Governance Domain (1 Domain, 5 Objectives):
    • Evaluate, Direct, and Monitor (EDM): Focuses on evaluating stakeholder requirements, directing strategic resource allocation, and monitoring system performance, value delivery, and risk conformity (e.g., EDM03: Ensured Risk Optimization).
  2. Management Domains (4 Domains, 35 Objectives):
    • Align, Plan, and Organize (APO): Addresses overall organization, strategy, IT architecture, human resources, and risk management (14 objectives, e.g., APO12: Managed Risk, APO13: Managed Security).
    • Build, Acquire, and Implement (BAI): Covers the definition, acquisition, implementation, and integration of IT solutions and system changes (11 objectives, e.g., BAI06: Managed IT Changes).
    • Deliver, Service, and Support (DSS): Focuses on the operational delivery of IT services, user support, operations management, incident resolution, and continuity (6 objectives, e.g., DSS01: Managed Operations, DSS05: Managed Security Services).
    • Monitor, Evaluate, and Assess (MEA): Evaluates operational performance, conformance with internal targets, internal control effectiveness, and compliance with external regulations (4 objectives, e.g., MEA02: Managed System of Internal Control).

COBIT Design Factors

A unique innovation in COBIT 2019 is the concept of Design Factors. Recognizing that no two enterprises are identical, COBIT provides 11 design factors (such as Enterprise Strategy, Enterprise Goals, Risk Profile, Threat Landscape, and Sourcing Model) that allow management to tailor an individualized IT governance system.


4. ISO/IEC 27001 & 27002: Information Security Management Systems

The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) publish the global benchmark standards for information security management.

ISO/IEC 27001:2022 (Requirements for an ISMS)

ISO/IEC 27001 specifies the mandatory requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). An ISMS is a systematic approach to managing sensitive enterprise information, encompassing people, processes, and IT systems.

  • Mandatory Clauses (Clauses 4 through 10): To achieve formal third-party accredited certification, an organization must comply with the overarching management clauses: Context of the organization (Clause 4), Leadership (Clause 5), Planning (Clause 6), Support (Clause 7), Operation (Clause 8), Performance evaluation (Clause 9), and Improvement (Clause 10).
  • The Plan-Do-Check-Act (PDCA) Cycle: ISO 27001 is structured around continuous improvement. Organizations plan their security objectives, implement (do) controls, check (monitor and audit) performance, and act (remediate deficiencies).
  • The Statement of Applicability (SoA): A foundational audit document required under Clause 6.1.3. The SoA explicitly lists which controls from Annex A / ISO 27002 have been selected, explains the business rationale for inclusion, describes their implementation status, and provides formal justifications for any excluded controls.

ISO/IEC 27002:2022 (Control Catalog Modernization)

While ISO 27001 provides the management requirements, ISO/IEC 27002 provides the reference catalog of security controls. In the significant 2022 revision, ISO streamlined the legacy 114 controls across 14 categories down to 93 controls structured into 4 practical themes:

ThemeNumber of ControlsScope & Operational Focus
Organizational Controls37 ControlsPolicies, asset management, information classification, supplier relationships, cloud governance, and incident reporting.
People Controls8 ControlsBackground screening, terms of employment, security awareness, remote working policies, and disciplinary processes.
Physical Controls14 ControlsPhysical security perimeters, physical entry controls, securing offices, clear desk/clear screen policies, and equipment maintenance.
Technological Controls34 ControlsAuthentication, privileged access rights, access restrictions, cryptographic controls, secure coding, configuration management, and vulnerability management.

[!NOTE] Control Attributes in ISO 27002:2022: The 2022 standard introduced five metadata "attributes" for each control: Control Type (#Preventive, #Detective, #Corrective), Information Security Properties (#Confidentiality, #Integrity, #Availability), Cybersecurity Concepts (#Identify, #Protect, #Detect, #Respond, #Recover), Operational Capabilities (#Governance, #Asset_management, etc.), and Security Domains (#Governance_and_Ecosystem, #Protection, etc.). This allows seamless cross-mapping between ISO 27002 and the NIST Cybersecurity Framework.


5. COSO Enterprise Risk Management (ERM): Integrating Cyber Risk

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) publishes the premier internal control and risk management frameworks recognized in U.S. corporate governance and SOX compliance. In 2017, COSO updated its core risk model with Enterprise Risk Management—Integrating with Strategy and Performance and subsequently published targeted guidance on cyber risk.

The Five Interconnected COSO ERM Components

COSO ERM views risk management not as an isolated compliance checklist, but as an integral discipline woven into strategy formation and daily operational execution.

  1. Governance and Culture: The board of directors maintains oversight of enterprise cyber risk. Management cultivates an ethical security culture where cybersecurity awareness is emphasized across all organizational tiers.
  2. Strategy and Objective-Setting: The organization defines its Cyber Risk Appetite—the broad amount and type of risk it is willing to accept in pursuit of strategic value. Cyber risk tolerances (the acceptable variation in performance) are established for core financial and operating systems.
  3. Performance: Risks that could impair the achievement of strategic objectives are identified, assessed for severity (impact and likelihood), prioritized, and addressed through risk responses (Accept, Avoid, Reduce, or Share).
  4. Review and Revision: The organization evaluates changes in the business environment, threat landscape, and regulatory mandates, adjusting its cybersecurity risk practices accordingly.
  5. Information, Communication, and Reporting: Transparent communication of cybersecurity metrics and residual risk to executive leadership and the board of directors.

Translating Technical Metrics into Financial and Operational Terms

A key challenge evaluated on the CPA ISC exam is the translation of low-level technical metrics into enterprise risk terminology suitable for board reporting:

Technical Metric                        COSO ERM Business Impact
┌────────────────────────────────┐      ┌────────────────────────────────┐
│ Unpatched CVEs / Scan Scores   │ ───▶ │ Financial Exposure / Downtime  │
│ Firewall Block Logs            │ ───▶ │ Customer Trust & Reputation    │
│ Phishing Simulation Fail Rates │ ───▶ │ Regulatory Sanctions (SEC/FTC) │
│ Incident Resolution Latency    │ ───▶ │ Operational Disruption Costs   │
└────────────────────────────────┘      └────────────────────────────────┘

6. Comprehensive Framework Comparison Matrix

Understanding the distinct scope, authority, and intended use of each framework is essential for distinguishing between frameworks on the CPA examination.

DimensionNIST CSF 2.0COBIT 2019ISO/IEC 27001:2022COSO ERM (2017)
Issuing OrganizationNational Institute of Standards & Technology (U.S. Dept. of Commerce)ISACA (Global IT Governance Professional Association)ISO & IEC (International Standardization Bodies)COSO (AICPA, AAA, FEI, IIA, IMA)
Primary Target AudienceCISOs, Security Engineers, IT Auditors, Enterprise ExecutivesCIOs, IT Directors, Board Governance Committees, IT AuditorsCISOs, Compliance Officers, Security Operations, Third-Party AuditorsBoard of Directors, CFOs, CROs, Audit Committees, Financial Auditors
Core Architectural FocusSix Core Functions (GV, ID, PR, DE, RS, RC) & TiersGovernance (EDM) vs. Management (APO, BAI, DSS, MEA) across 40 objectivesRequirements for an ISMS (Clauses 4-10) + 93 Controls (ISO 27002)Five ERM components & 20 risk management principles
Primary Business PurposeOrganizing, prioritizing, and communicating cybersecurity posture and reducing cyber riskAligning IT operations and investments with overarching enterprise business goalsEstablishing a certifiable information security management systemEmbedding enterprise risk management into strategic planning and financial governance
Formal CertificationNone (Voluntary guidance; organizations perform self-assessments)None (Maturity benchmarking; no formal organizational certification)Yes (Accredited third-party certification audits valid for 3 years)None (Management assessment framework; no formal entity certification)
Typical Audit / Attestation UseBenchmarking SOC 2 Trust Services Criteria; federal/defense complianceITGC design evaluation; internal IT audit charters; SOX 404 IT scopingThird-party vendor due diligence; international customer assuranceSOX 404 top-down risk assessment; overall enterprise governance

7. Mapping Framework Maturity to Audit Assertions and ITGCs

When planning an attestation or financial audit engagement, CPAs must connect technical framework controls to financial statement assertions and internal control baselines.

Capability Maturity Model Integration (CMMI) Scale

Auditors frequently benchmark an organization's framework maturity using the 6-level CMMI scale:

  • Level 0 (Incomplete): The process is not performed or fails to achieve its stated objectives.
  • Level 1 (Initial): Work is completed unpredictably, reactively, and without standardized documentation. Control success depends entirely on individual heroics.
  • Level 2 (Managed): Processes are planned, performed, measured, and controlled at the project level, but vary across departments.
  • Level 3 (Defined): Processes are formally documented, standardized, and integrated across the entire enterprise.
  • Level 4 (Quantitatively Managed): Processes are controlled using statistical and quantitative measurement techniques.
  • Level 5 (Optimizing): The organization focuses on continuous process improvement through agile innovation and automated feedback loops.

Mapping Frameworks to Financial Statement Audit Assertions

Effective cybersecurity frameworks protect the Integrity, Confidentiality, and Availability of accounting information systems, directly substantiating management assertions:

  • Existence / Occurrence: Strong identity and access controls (NIST PR.AA, COBIT DSS05) ensure that only authorized users can initiate transactions, mitigating the risk of fictitious revenue or inventory entries.
  • Completeness: Automated input validation and interface monitoring (COBIT BAI03, ISO 27002 8.26) ensure all valid transactions reach the general ledger without omission.
  • Accuracy / Valuation: Change management controls (COBIT BAI06, NIST PR.PS) ensure that database calculation algorithms, automated depreciation schedules, and tax engines are not maliciously altered.
  • Cutoff: Time synchronization controls (ISO 27002 8.17) ensure transaction timestamps reflect accurate financial reporting periods.
Loading diagram...
Enterprise Cybersecurity Governance & Framework Hierarchy
Test Your Knowledge

In February 2024, the National Institute of Standards and Technology released NIST CSF 2.0. Which of the following represents the major structural addition made to the core functions of the framework, and what is its primary operational focus?

A
B
C
D
Test Your Knowledge

Under the COBIT 2019 framework developed by ISACA, how does the framework demarcate the responsibilities between enterprise IT 'Governance' and enterprise IT 'Management'?

A
B
C
D
Test Your Knowledge

An organization is preparing for an independent ISO/IEC 27001 certification audit. Which document is mandatory under Clause 6.1.3 to formally document which of the 93 controls from ISO/IEC 27002:2022 are included or excluded, along with the justifications for exclusions?

A
B
C
D