312-50V11 · Question #545
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?
The correct answer is D. Legislative, contractual, standards based. OSSTMM v3 defines three specific compliance categories - legislative, contractual, and standards based - which together cover all sources of security obligations an organization may face.
Question
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?
Options
- ALegal, performance, audit
- BAudit, standards based, regulatory
- CContractual, regulatory, industry
- DLegislative, contractual, standards based
How the community answered
(43 responses)- A2% (1)
- B5% (2)
- C5% (2)
- D88% (38)
Why each option
OSSTMM v3 defines three specific compliance categories - legislative, contractual, and standards based - which together cover all sources of security obligations an organization may face.
Performance and audit are not compliance types defined in OSSTMM - performance relates to operational metrics and audit is a process, neither of which is listed as a compliance category in the methodology.
Audit is not one of the three OSSTMM compliance types; while audits may verify compliance, OSSTMM does not classify audit itself as a compliance category alongside standards-based and regulatory.
Regulatory is not the OSSTMM-specified term - the correct term is legislative; and industry alone is not precise enough, as OSSTMM uses the term standards based to distinguish compliance driven by formal standards bodies.
OSSTMM v3 formally identifies legislative compliance (obligations arising from laws and government regulations), contractual compliance (obligations arising from agreements between business parties), and standards-based compliance (obligations arising from adherence to professional or industry standards bodies). These three categories are intentionally broad to capture every possible source of a security requirement. Testers use this framework to scope engagements and ensure all applicable compliance drivers are addressed.
Concept tested: OSSTMM three compliance types
Source: https://www.isecom.org/OSSTMM.3.pdf
Topics
Community Discussion
No community discussion yet for this question.