PHD Discussions Logo

Ask, Learn and Accelerate in your PhD Research

Question Icon Post Your Answer

Question Icon

9 months ago in Cybersecurity By Shraddha

Are IT Governance Standards Enough to Protect Critical National Infrastructure?

We use COBIT and ISO27001 for IT governance. Are these considered frameworks for protecting Critical Information Infrastructure (CIIP), or is CIIP a completely separate discipline?

All Answers (1 Answers In All)

By Pranav Answered 2 months ago

That's a crucial distinction. Standards like COBIT, ITIL, ISO27001, and PCI DSS are governance and control frameworks. They provide the essential "how to manage" structure. CIIP is a specific objective—protecting infrastructure vital to national security. You can't separate them; think of governance as the foundation. Strong CIIP is built upon that foundation of good policy, risk management, and processes. The governance frameworks enable and guide the technical, physical, and operational measures you implement for true CIIP.

Your Answer