Cybersecurity Compliance
Focus on Standards
Copyright (c) 2026 Bottyán Béla, Bottyán László

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Abstract
As the number of cybersecurity threats continues to increase and the technological environment evolves, organizations widely adopt various standards to reduce risks and support compliance. However, few comparisons use a uniform set of criteria and also assess the approaches’ practical applicability and their ability to align with one another. With this in mind, the study specifically examines under what environmental conditions certain standards provide effective support.
The objective of the study is to present, in a synthesizing manner, the COBIT 2019, NIST CSF, C2M2, and ISO/IEC 27001:2022 standards, to compare them along selected attributes, and to illustrate the dilemmas of selection and implementation through a practical case study.
First, the authors define the conceptual boundaries of IT security and cybersecurity, emphasizing that cybersecurity is relevant not only for technical reasons but also from the perspective of organizational and managerial responsibility. Next, they outline COBIT 2019’s IT-governance-focused approach, which centers on maturity levels and performance measurement, and discuss the NIST CSF’s risk-based, industry-agnostic, modular structure. They also present the C2M2 maturity model optimized for critical infrastructures, as well as the certifiable ISMS requirements of ISO/IEC 27001:2022. To compare the standards, the authors developed a bespoke evaluation framework, which assesses the systems’ objectives, applicability, certifiability, industry focus, and implementation complexity, while also underscoring that there is no single “best solution” suitable for all organizations, since selection must take into account, among other factors, an organization’s specific goals and risk profile. As a complementary element, the article includes a case study that aims to illustrate the challenges of practical implementation and the need to formulate improvement recommendations through a gap analysis against ISO/IEC 27001:2022 conducted at a large industrial enterprise.
Based on the comparative analysis, the authors highlight that COBIT 2019 can provide a high level of support for aligning corporate IT governance with business objectives and incorporates a maturity perspective; however, it is not certifiable. Owing to its modular structure and industry-agnostic nature, the NIST CSF is particularly well-suited to managing cybersecurity risks. Although it does not rely on a maturity-based approach, it has the advantage of being able to be maintained alongside other standards. The strength of C2M2 lies in assessing the maturity of critical infrastructure and clearly identifying areas for improvement, and it is applicable not only to IT but also to OT environments. The formal requirements of an Information Security Management System (ISMS) are primarily based on ISO/IEC 27001:2022, which provides the implementing organization with a risk-based control system. Due to its certifiability and wide recognition, it can be regarded as a trust-building instrument in establishing and maintaining business relationships. It should be noted, however, that its implementation may require substantial resources, primarily because of administrative burdens. Complementing these findings, the case study shows that, in a large-enterprise IT environment, a gap analysis requires a deliberate definition of scope and prioritization based on system criticality; otherwise, conducting it may entail disproportionate resource expenditure. As a practical outcome, a structured classification of gaps was developed, which directly supported mitigating high risks, identifying areas with significant improvement potential, and preparing a prioritized action plan.
The most important conclusion of the study is that, also in the context of cybersecurity compliance, there is no single “best solution” that fits all organizations, since the choice must consider, among other factors, an organization’s specific objectives and risk profile; therefore, in many cases, the parallel or combined application of frameworks may deliver the greatest value. Accordingly, the authors identify, as a direction for future research, the development of methodologies that support, in a measurable way, the integration of different standards.
Keywords:
How to Cite
References
- 2013. évi L. törvény az állami és önkormányzati szervek elektronikus információbiztonságáról. Online: https://njt.hu/jogszabaly/2013-50-00-00
BEATO, Jonathan – INDAH FIANTY, Melissa (2024): COBIT 2019 Framework: Evaluating Knowledge and Quality Management Capabilities in a Printing Machine Distributor. Journal of Information Systems and Informatics, 6(1), 1–12. Online: https://doi.org/10.51519/journalisi.v6i1.638
European Union Agency for Cybersecurity (ENISA) (2024): ENISA Threat Landscape 2024. Heraklion: ENISA. Online: https://doi.org/10.2824/0710888
GYARAKI Réka szerk. (2023): Az információbiztonság alapjai. Budapest: Nemzeti Közszolgálati Egyetem. Online: https://doi.org/10.37372/mrttvpt.2023.3
HARISAIPRASAD, Kumaragunta (2020): COBIT 2019 and COBIT 5 comparison. ISACA. Online: https://www.isaca.org/resources/news-and-trends/industry-news/2020/cobit-2019-and-cobit-5-comparison
INDAH FIANTY, Melissa – BRIAN, Maximillian (2023): Leveraging COBIT 2019 Framework to Implement IT Governance in Business Process Outsourcing Company. Journal of Information Systems and Informatics, 5(2). Online: https://doi.org/10.51519/journalisi.v5i2.492
KOCZISZKY György – KARDKOVÁCS Kolos (2020): A compliance szerepe a közösségi értékek és érdekek védelmében. Budapest: Akadémiai. Online: https://doi.org/10.1556/9789634545972
KŐ Andrea szerk. (2014): Informatikai irányítás és menedzsment. Budapest: Nemzeti Közszolgálati Egyetem. Online: http://hdl.handle.net/20.500.12944/10377
KPMG (2013): BCM körkép. Tanulmány az üzletfolytonosság-menedzsment magyarországi helyzetéről. Budapest: KPMG. Online: https://assets.kpmg.com/content/dam/kpmg/pdf/2016/07/20130911-BCM-korkep.pdf
MICHELBERGER Pál (2024): Fejezetek a vállalati biztonságmenedzsmentből. Budapest: Akadémiai. Online: https://doi.org/10.1556/9789634549376
MICHELBERGER Pál – LÁBODI Csaba (2009): Információbiztonság az ellátási láncokban. MEB 2009 – 7th International Conference on Management, Enterprise and Benchmarking. Budapest. Online: https://bit.ly/4wQnA5k
MUHA Lajos (2004): A terrorizmus és az informatikai biztonság. HISEC 2004 Nemzeti adatvédelmi és adatbiztonsági konferencia. Budapest.
National Institute of Standards and Technology (NIST) (2024): NIST Cybersecurity Framework 2.0. Online: https://doi.org/10.6028/NIST.CSWP
Nemzeti Kibervédelmi Intézet (2024): Megjelent a NIST Cybersecurity Framework 2.0. Online: https://nki.gov.hu/it-biztonsag/hirek/megjelent-a-nist-cybersecurity-framework-2-0/
PUTRA, Kevin – WAHYUNINGTYAS, Emmy (2023): E-Learning System Audit at ABC University Using COBIT 5 Framework - MEA (Monitoring, Evaluate and Assess) Domain. MelekIT, 9(2). Online: https://doi.org/10.30742/melekitjournal.v9i2.261
SRI, Nikhil Gupta et al. (2019): Secure Design and Development Cybersecurity Capability Maturity Model (SD2-C2M2): Next-Generation Cyber Resilience by Design. NCS '19: Proceedings of the Northwest Cybersecurity Symposium, 1–9. Online: https://doi.org/10.1145/3332448.3332461
SZÁDECZKY Tamás (2014): Információbiztonsági szabványok. Budapest: Nemzeti Közszolgálati Egyetem. Online: http://hdl.handle.net/20.500.12944/14304
U.S. Department of Energy (2021): Cybersecurity Capability Maturity Model (C2M2) (Version 2.0). Washington, DC: U.S. Department of Energy. Online: https://c2m2.doe.gov/
VÉRTESY László (2012): A közigazgatás ellenőrzése és a közreműködő szervek. In Közigazgatás, ellenőrzés, gazdálkodás. Budapest: Nemzeti Közszolgálati Egyetem, 39–60. Online: https://kti.uni-nke.hu/document/vtkk-uni-nke-hu/vertesy-laszlo-kozigazgatas-ellenorzes-gazdalkodas.original.pdf
VÉRTESY László (2014): Az állami beavatkozás joga és hatékonysága. Budapest: Nemzeti Közszolgálati Egyetem.