nerdexam
CompTIA

CAS-002 · Question #896

A company Chief Information Officer (CIO) is unsure which set of standards should govern the company's IT policy. The CIO has hired consultants to develop use cases to test against various…

The correct answer is C. Issue a policy specifying best practice security standards and a baseline to be implemented. The CIO should establish a unified best-practice baseline that satisfies the overlapping controls found across multiple compliance frameworks rather than managing each standard independently.

Integration of Computing, Communications and Business Disciplines

Question

A company Chief Information Officer (CIO) is unsure which set of standards should govern the company's IT policy. The CIO has hired consultants to develop use cases to test against various government and industry security standards. The CIO is convinced that there is large overlap between the configuration checks and security controls governing each set of standards. Which of the following selections represent the BEST option for the CIO?

Options

  • AIssue a RFQ for vendors to quote a complete vulnerability and risk management solution to the
  • BIssue a policy that requires only the most stringent security standards be implemented throughout
  • CIssue a policy specifying best practice security standards and a baseline to be implemented
  • DIssue a RFI for vendors to determine which set of security standards is best for the company.

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    75% (27)
  • D
    17% (6)

Why each option

The CIO should establish a unified best-practice baseline that satisfies the overlapping controls found across multiple compliance frameworks rather than managing each standard independently.

AIssue a RFQ for vendors to quote a complete vulnerability and risk management solution to the

An RFQ (Request for Quotation) solicits vendor pricing for a specific solution but does not resolve the fundamental internal policy decision about which standards and controls to adopt.

BIssue a policy that requires only the most stringent security standards be implemented throughout

Mandating only the most stringent controls ignores business context and cost-benefit trade-offs, potentially imposing unnecessary overhead where less restrictive controls would fully satisfy requirements.

CIssue a policy specifying best practice security standards and a baseline to be implementedCorrect

Issuing a policy that specifies best-practice standards and a common baseline allows the organization to satisfy multiple overlapping frameworks simultaneously without duplicating effort for each one. Because consultants confirmed significant overlap between standards, a single unified baseline can address requirements across all relevant frameworks. This approach is practical, defensible, and scalable as new regulatory requirements emerge.

DIssue a RFI for vendors to determine which set of security standards is best for the company.

An RFI (Request for Information) gathers market information from vendors but does not produce an internal policy decision or resolve the standards overlap the CIO needs to address.

Concept tested: Unified security baseline policy across overlapping standards

Source: https://www.nist.gov/cyberframework

Topics

#security baseline#security standards#IT governance#policy management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice