nerdexam
EC-Council

312-50V9 · Question #419

What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?

The correct answer is D. Legislative, contractual, standards based. OSSTMM recognizes three types of compliance - legislative, contractual, and standards based - which together cover the legal, agreed-upon, and industry-framework dimensions of security obligations.

Introduction to Ethical Hacking

Question

What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?

Options

  • ALegal, performance, audit
  • BAudit, standards based, regulatory
  • CContractual, regulatory, industry
  • DLegislative, contractual, standards based

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    89% (34)

Why each option

OSSTMM recognizes three types of compliance - legislative, contractual, and standards based - which together cover the legal, agreed-upon, and industry-framework dimensions of security obligations.

ALegal, performance, audit

"Performance" is not a compliance category recognized by OSSTMM; performance relates to operational metrics rather than a compliance obligation type.

BAudit, standards based, regulatory

"Audit" is a process used to verify compliance, not a type of compliance itself within the OSSTMM framework.

CContractual, regulatory, industry

"Industry" is not a distinct OSSTMM compliance category; industry-specific requirements would fall under either legislative or standards-based compliance depending on their source.

DLegislative, contractual, standards basedCorrect

According to the OSSTMM framework, legislative compliance refers to laws and government regulations that must be followed, contractual compliance refers to obligations defined in agreements between parties, and standards-based compliance refers to adherence to published technical or procedural standards. These three categories collectively define the full scope of external compliance requirements an organization faces.

Concept tested: OSSTMM three compliance types

Source: https://www.isecom.org/OSSTMM.3.pdf

Topics

#OSSTMM#compliance types#legislative#contractual

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice