What framework should you pick?
I commonly am asked questions such as “Do you prefer COBIT or ITIL?” or “We really like the benefits of framework X but there is so much more readily available for Y, what do you think?”
In 2007, the Global Information Security Survey, which represents 5,555 overall respondents covering all regions of the world had the following to say:
| Overall | NoAmerica | Europe | Asia | |
| ITIL | 45% | 43% | 50% | 46% |
| COBIT | 25% | 32% | 27% | 19% |
| BS7799 / ISO17799 / 27001 | 36% | 29% | 43% | 39% |
| SAS 70 | 18% | 28% | 11% | 13% |
| PCI | 23% | 34% | 17% | 18% |
It looks like ITIL is out on the top. I think this mostly due to the fact that ITIL has a lot of literature available in the market and there are many people that have used it so it is easier to implement for some organizations.
Source: CSO Magazine










