Governance Frameworks, Compliance, and the Regulatory Environment

COSO, COBIT, service management, and major external compliance regimes.

This chapter explains the governance and compliance frameworks that shape how organizations manage technology risk. ISC questions in this area usually turn on knowing which framework or regulatory lens best fits the situation.

In This Chapter

How to Use This Chapter

  • Read this chapter when frameworks and regulations are blending together.
  • Focus on the purpose of each framework and what kind of control problem it helps solve.
  • Revisit it whenever a question asks which governance or compliance structure is most relevant.

In this section

Revised on Friday, April 24, 2026