- Article
Cybersecurity Strategy Development: Towards an Integrated Approach Based on COBIT and ISO 27000 Series Standards
- Bilgin Metin,
- Sibel Berfun Sevim and
- Martin Wynn
This article presents a practical guide for developing a cybersecurity strategy that integrates COBIT 2019 with the ISO/IEC 27000 series of standards. Although COBIT 2019 provides strong frameworks for IT strategy and governance, it does not specifically prescribe a cybersecurity strategy. This article addresses this gap in the strategy literature by building upon the ISO/IEC 27000 series, which is designed to be adaptable for organizations of all types and sizes, as well as being suitable for various regulatory and technological environments. First, a synthesis of COBIT 2019 and the ISO/IEC standards (particularly 27014, 27001, 27036, and 27701) identifies six key themes for a cybersecurity strategy. A more specific qualitative content analysis of ISO/IEC 27014 (which focuses on board-level information security governance) and COBIT 2019 (which outlines execution mechanics) confirms the validity of these themes with traceability at the clause and objective levels. To operationalize these themes, a three-step method is put forward: setting alignment objectives and scope; translating these into IT strategy decisions using COBIT governance and management objectives and practices; and establishing a cybersecurity strategy through ISO/IEC 27001. Additionally, ISO/IEC 27701 for privacy and ISO/IEC 27036 for supplier governance are incorporated where relevant. An illustrative example is provided using anonymized data from public sources, and the applicability and limitations of the research findings are discussed.
5 December 2025



