Authors: Reyhan Syafier Al Hadad ; Hanhan Maulana
DOI: 10.1109/ICSPIS59665.2023.10402713
Abstract:
This study evaluates, compares and discuss the approaches of COBIT and ISO 27001 in auditing the Credit Bureau Automation System (CBAS) at PT XYZ. The authors employ a qualitative comparative analysis to explore and synthesize qualitative information from scholarly sources. This study concludes that ISO 27001 is better suited for auditing CBAS as it has a strong focus on information security and risk management, as well as flexibility to tailor to client needs. In contrast, COBIT has a more generalized scope and covers broader IT topics. However, the authors suggest that both frameworks can complement each other in an audit, depending on the organization’s specific needs. This study also highlights the strengths of COBIT, such as its comprehensive framework that enables organizations to attain their goals in corporate IT governance and management, and suggests a simplified IT risk management maturity audit system based on ‘COBIT 5 for Risk’ to evaluate the maturity of IT risk management in an organization. Overall, this study provides valuable insights into the applicability of COBIT and ISO 27001 in auditing CBAS and offers suggestions for organizations to improve their IT governance and risk management practices. © 2023 IEEE.
Author Keywords:
auditing; COBIT; Credit Bureau Automation System (CBAS); ISO 27001; risk management
This article can be accessed at https://www.scopus.com/pages/publications/85184851519