212-82 · Question #129
As the IT security manager for a burgeoning e-commerce company, you're keen on implementing a formal risk management framework to proactively tackle security risks associated with the company's…
The correct answer is B. NIST Cybersecurity Framework (CSF) - Offers a general, customizable approach. Given the need for a scalable and adaptable risk management framework for a burgeoning e-commerce company, the NIST Cybersecurity Framework (CSF) is the most relevant choice.
Question
As the IT security manager for a burgeoning e-commerce company, you're keen on implementing a formal risk management framework to proactively tackle security risks associated with the company's rapid online expansion. Given your focus one-commerce and the need for scalability, which risk management framework is likely the most relevant?
Options
- AISO 27001 - Provides a comprehensive information security management system (ISMS).
- BNIST Cybersecurity Framework (CSF) - Offers a general, customizable approach.
- CPCI DSS (Payment Card Industry Data Security Standard) - Targets credit card data security
- DCOBIT (Control Objectives for Information and Related Technology) - Focuses on IT governance
How the community answered
(32 responses)- A13% (4)
- B78% (25)
- C6% (2)
- D3% (1)
Why each option
Given the need for a scalable and adaptable risk management framework for a burgeoning e-commerce company, the NIST Cybersecurity Framework (CSF) is the most relevant choice.
ISO 27001 provides a comprehensive Information Security Management System (ISMS), but its implementation can be extensive and prescriptive, potentially being more heavyweight than necessary for a rapidly growing company needing an adaptable framework.
The NIST Cybersecurity Framework (CSF) offers a flexible, risk-based, and customizable approach to managing cybersecurity risk, making it highly suitable for rapidly expanding e-commerce operations. Its adaptive nature allows organizations to tailor controls to their specific scale and evolving threat landscape, providing a common language for cybersecurity risk without being overly prescriptive.
PCI DSS (Payment Card Industry Data Security Standard) is a compliance standard specifically for organizations handling credit card data, making it a component of risk management rather than a general, overarching risk management framework for all security risks.
COBIT (Control Objectives for Information and Related Technology) primarily focuses on IT governance and ensuring IT aligns with business goals, which is broader than a specific cybersecurity risk management framework.
Concept tested: Cybersecurity risk management frameworks
Source: https://www.nist.gov/cyberframework
Topics
Community Discussion
No community discussion yet for this question.