Skip to content

Cost and Management Audit · Information Systems Security Audit

IT Governance Frameworks and Cyber Law for CMA Final

Updated 11 October 2026 · Fact-checked

IT governance frameworks guide how an organisation directs, secures and runs its IT. COBIT governs and manages enterprise IT, ISO 27001 sets requirements for an information security management system, and ITIL guides IT service management. The IT Act 2000 makes hacking, data theft and similar acts offences. Match each to its purpose to answer.

Understand IT Governance Frameworks and Cyber Law

Start with the problem. A company runs on IT. Someone must decide who controls it, how it is kept secure, how services reach users, and what the law expects. No single tool does all of this, so different frameworks cover different parts.

COBIT is a governance and management framework for enterprise IT, issued by ISACA. It links business goals to IT goals and sets out processes and controls. Think of it as the board-level and management-level view: is IT delivering value, are risks managed, are resources used well? Auditors use it as a benchmark to assess IT controls.

ISO/IEC 27001 is an international standard for an Information Security Management System (ISMS). It is about protecting confidentiality, integrity and availability of information. The organisation assesses risks, selects controls, documents them, and keeps improving them. An organisation can be certified against it by an independent body. Its focus is security only.

ITIL is a set of good practices for IT service management: how to design, deliver, support and improve IT services such as incident handling, change management and service desk. Its focus is service quality, not governance or security as such.

The Information Technology Act, 2000 is the Indian law on electronic records, digital signatures and cyber offences. It gives legal recognition to electronic records and defines offences such as unauthorised access, data damage, identity theft, cheating by personal computer resource, and publishing obscene material. It also provides for penalties and compensation for damage to computer systems. Frameworks are voluntary good practice. The Act is binding law.

For the exam, keep one line for each: COBIT = govern and manage IT, ISO 27001 = secure information, ITIL = deliver IT services, IT Act = legal duties and offences.

Key rules to remember

Security triad (CIA)
Information security = Confidentiality + Integrity + Availability
The core objective protected by an ISMS under ISO 27001.
ISMS improvement cycle
Plan → Do → Check → Act
A way to remember that an ISMS is continually reviewed and improved, not a one-time project.
Framework purpose match
COBIT = governance; ISO 27001 = security management; ITIL = service management
Use this to choose the right framework in a scenario question.
Legal status
Frameworks = voluntary good practice; IT Act 2000 = binding law
ISO 27001 certification is voluntary unless a regulator or contract requires it.

How to solve IT Governance Frameworks and Cyber Law questions

Use this method for any question on frameworks or cyber law.

  1. 1Read the question and decide whether it asks about governance, security, service delivery or legal liability.
  2. 2Name the matching framework or the Act, and state its purpose in one sentence.
  3. 3Describe the key features that fit the scenario, such as risk assessment for ISO 27001 or incident management for ITIL.
  4. 4Apply it to the facts given: the company, the weakness or the act committed.
  5. 5For a cyber law question, identify the act done (unauthorised access, data damage, identity theft) and state the offence or civil liability in plain words.
  6. 6Link to the auditor's role: what the cost or management auditor should check or report.
  7. 7Close with a clear recommendation or conclusion.

Quickest way: Purpose-matching shortcut

When to use it: Use it for MCQs and for short comparison questions when time is tight.

  1. Ask what the question is about: govern, secure, serve or punish.
  2. Govern points to COBIT, secure points to ISO 27001, serve points to ITIL, punish or compensate points to the IT Act.
  3. Reject options that give a framework a job that belongs to another.
  4. If two frameworks seem to fit, pick the one whose main purpose matches the key word in the question.

Common mistakes in IT Governance Frameworks and Cyber Law

  • Treating COBIT and ITIL as the same thing.

    Both deal with IT processes, so they sound alike.

    Fix: COBIT is about governance and control of enterprise IT. ITIL is about managing IT services. Say this in one line each.

  • Saying ISO 27001 covers all IT management.

    Students assume any ISO standard on IT is broad.

    Fix: It covers information security management only: risk assessment, controls and continual improvement of the ISMS.

  • Calling the frameworks legally mandatory.

    They are used so widely that they feel like rules.

    Fix: They are voluntary good practice. Only law, regulator directions or contracts make them compulsory.

  • Confusing certification with compliance with law.

    A certificate sounds like proof of legal compliance.

    Fix: ISO 27001 certification shows an ISMS meets the standard. It does not by itself prove compliance with the IT Act.

  • Quoting IT Act section numbers from memory without being sure.

    Students try to impress with numbers.

    Fix: Describe the offence clearly in words. Give a section number only if you are certain of it.

  • Writing definitions with no application to the case.

    Students recall notes instead of reading the scenario.

    Fix: Tie each framework to the facts and end with what the auditor should check or recommend.

Worked examples

Example 1

A manufacturing company in Pune has frequent server outages, unresolved user complaints and no formal change approval. The board also wants assurance that IT supports business goals. Which frameworks would you suggest and why?

Show the solution
  1. Split the problem into two needs: service delivery issues and board-level assurance.
  2. Outages, unresolved complaints and unapproved changes are service management weaknesses, so ITIL fits. It offers incident, problem and change management practices.
  3. Board assurance that IT supports business goals is a governance need, so COBIT fits. It links business goals to IT goals and defines processes and controls.
  4. Add that ISO 27001 may be considered separately if information security is a concern, but the facts given do not point to it first.

Answer: Adopt ITIL practices to fix incident, problem and change management, and use COBIT to govern IT and give the board assurance that IT supports business objectives.

Example 2

An employee of a company in Chennai, without permission, accesses the cost database of the company and deletes product costing files. Explain the legal position under the IT Act 2000 and what the cost auditor should do.

Show the solution
  1. Identify the acts: access to a computer system without permission, and destruction or deletion of data.
  2. State the law in plain words: the IT Act, 2000 treats unauthorised access and damage to data as contraventions that make the person liable to pay compensation to the affected party, and where done dishonestly or fraudulently, as an offence punishable with imprisonment or fine.
  3. Note that the company is the affected party and can claim compensation.
  4. For the auditor: assess the effect on cost records, since the Cost Records Rules require proper records to be maintained.
  5. Check access controls, backups and recovery, and whether the incident was reported and investigated.
  6. Recommend stronger logical access controls, regular backups and an ISMS aligned to ISO 27001.

Answer: The employee's unauthorised access and deletion of data attract compensation liability and, if dishonest or fraudulent, criminal liability under the IT Act, 2000. The cost auditor should evaluate the impact on cost records, test access and backup controls, and recommend an ISMS and tighter access controls.

Exam tips

  • Expect MCQs that ask which framework fits a described need. Learn the one-line purpose of each.
  • In case scenarios, always name the framework and then apply it to the facts. Definitions alone earn little.
  • Comparison questions are common. Compare on purpose, focus, issuing body or nature, and whether it is certifiable or voluntary.
  • For cyber law, describe offences in plain words and link them to the auditor's duty to review controls and records.
  • Finish answers with a practical recommendation.

Practice questions from Information Systems Security Audit

IT Governance Frameworks and Cyber Law: frequently asked questions

What is the difference between COBIT and ITIL?

COBIT is a framework for governing and managing enterprise IT, with focus on control, risk and value. ITIL is a set of practices for managing IT services such as incidents and changes. COBIT answers who directs and controls IT, ITIL answers how services are delivered.

What does ISO 27001 cover?

It sets requirements for an information security management system. The organisation assesses risks, selects and documents controls, and improves them continually to protect confidentiality, integrity and availability. Organisations can get certified by an independent body.

Is ISO 27001 certification compulsory in India?

No, it is voluntary in general. It may become necessary if a regulator, customer or contract requires it.

Which IT Act 2000 provisions matter for CMA Final?

Focus on the legal recognition of electronic records and digital signatures, and the provisions on unauthorised access, data damage, identity theft and other cyber offences. Learn them in plain words and apply them to scenarios.