nerdexam
EC-Council

312-50V11 · Question #545

What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?

The correct answer is D. Legislative, contractual, standards based. OSSTMM v3 defines three specific compliance categories - legislative, contractual, and standards based - which together cover all sources of security obligations an organization may face.

Information Security and Ethical Hacking Fundamentals

Question

What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?

Options

  • ALegal, performance, audit
  • BAudit, standards based, regulatory
  • CContractual, regulatory, industry
  • DLegislative, contractual, standards based

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    5% (2)
  • D
    88% (38)

Why each option

OSSTMM v3 defines three specific compliance categories - legislative, contractual, and standards based - which together cover all sources of security obligations an organization may face.

ALegal, performance, audit

Performance and audit are not compliance types defined in OSSTMM - performance relates to operational metrics and audit is a process, neither of which is listed as a compliance category in the methodology.

BAudit, standards based, regulatory

Audit is not one of the three OSSTMM compliance types; while audits may verify compliance, OSSTMM does not classify audit itself as a compliance category alongside standards-based and regulatory.

CContractual, regulatory, industry

Regulatory is not the OSSTMM-specified term - the correct term is legislative; and industry alone is not precise enough, as OSSTMM uses the term standards based to distinguish compliance driven by formal standards bodies.

DLegislative, contractual, standards basedCorrect

OSSTMM v3 formally identifies legislative compliance (obligations arising from laws and government regulations), contractual compliance (obligations arising from agreements between business parties), and standards-based compliance (obligations arising from adherence to professional or industry standards bodies). These three categories are intentionally broad to capture every possible source of a security requirement. Testers use this framework to scope engagements and ensure all applicable compliance drivers are addressed.

Concept tested: OSSTMM three compliance types

Source: https://www.isecom.org/OSSTMM.3.pdf

Topics

#OSSTMM#compliance types#legislative#testing methodology

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice