nerdexam
EC-Council

212-82 · Question #129

As the IT security manager for a burgeoning e-commerce company, you're keen on implementing a formal risk management framework to proactively tackle security risks associated with the company's…

The correct answer is B. NIST Cybersecurity Framework (CSF) - Offers a general, customizable approach. Given the need for a scalable and adaptable risk management framework for a burgeoning e-commerce company, the NIST Cybersecurity Framework (CSF) is the most relevant choice.

Submitted by ricky.ec· Mar 6, 2026Cloud Security Risks & Threat Mitigation

Question

As the IT security manager for a burgeoning e-commerce company, you're keen on implementing a formal risk management framework to proactively tackle security risks associated with the company's rapid online expansion. Given your focus one-commerce and the need for scalability, which risk management framework is likely the most relevant?

Options

  • AISO 27001 - Provides a comprehensive information security management system (ISMS).
  • BNIST Cybersecurity Framework (CSF) - Offers a general, customizable approach.
  • CPCI DSS (Payment Card Industry Data Security Standard) - Targets credit card data security
  • DCOBIT (Control Objectives for Information and Related Technology) - Focuses on IT governance

How the community answered

(32 responses)
  • A
    13% (4)
  • B
    78% (25)
  • C
    6% (2)
  • D
    3% (1)

Why each option

Given the need for a scalable and adaptable risk management framework for a burgeoning e-commerce company, the NIST Cybersecurity Framework (CSF) is the most relevant choice.

AISO 27001 - Provides a comprehensive information security management system (ISMS).

ISO 27001 provides a comprehensive Information Security Management System (ISMS), but its implementation can be extensive and prescriptive, potentially being more heavyweight than necessary for a rapidly growing company needing an adaptable framework.

BNIST Cybersecurity Framework (CSF) - Offers a general, customizable approach.Correct

The NIST Cybersecurity Framework (CSF) offers a flexible, risk-based, and customizable approach to managing cybersecurity risk, making it highly suitable for rapidly expanding e-commerce operations. Its adaptive nature allows organizations to tailor controls to their specific scale and evolving threat landscape, providing a common language for cybersecurity risk without being overly prescriptive.

CPCI DSS (Payment Card Industry Data Security Standard) - Targets credit card data security

PCI DSS (Payment Card Industry Data Security Standard) is a compliance standard specifically for organizations handling credit card data, making it a component of risk management rather than a general, overarching risk management framework for all security risks.

DCOBIT (Control Objectives for Information and Related Technology) - Focuses on IT governance

COBIT (Control Objectives for Information and Related Technology) primarily focuses on IT governance and ensuring IT aligns with business goals, which is broader than a specific cybersecurity risk management framework.

Concept tested: Cybersecurity risk management frameworks

Source: https://www.nist.gov/cyberframework

Topics

#Risk management framework#NIST CSF#E-commerce security#Scalability

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice