312-50V9 · Question #419
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?
The correct answer is D. Legislative, contractual, standards based. OSSTMM recognizes three types of compliance - legislative, contractual, and standards based - which together cover the legal, agreed-upon, and industry-framework dimensions of security obligations.
Question
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?
Options
- ALegal, performance, audit
- BAudit, standards based, regulatory
- CContractual, regulatory, industry
- DLegislative, contractual, standards based
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- C3% (1)
- D89% (34)
Why each option
OSSTMM recognizes three types of compliance - legislative, contractual, and standards based - which together cover the legal, agreed-upon, and industry-framework dimensions of security obligations.
"Performance" is not a compliance category recognized by OSSTMM; performance relates to operational metrics rather than a compliance obligation type.
"Audit" is a process used to verify compliance, not a type of compliance itself within the OSSTMM framework.
"Industry" is not a distinct OSSTMM compliance category; industry-specific requirements would fall under either legislative or standards-based compliance depending on their source.
According to the OSSTMM framework, legislative compliance refers to laws and government regulations that must be followed, contractual compliance refers to obligations defined in agreements between parties, and standards-based compliance refers to adherence to published technical or procedural standards. These three categories collectively define the full scope of external compliance requirements an organization faces.
Concept tested: OSSTMM three compliance types
Source: https://www.isecom.org/OSSTMM.3.pdf
Topics
Community Discussion
No community discussion yet for this question.