CAS-003 · Question #556
The Chief Executive Officer (CEO) instructed the new Chief Information Security Officer (CISO) to provide a list of enhancements to the company's cybersecurity operation. As a result, the CISO has…
The correct answer is B. NIST. NIST (National Institute of Standards and Technology) publishes widely adopted cybersecurity frameworks and guidelines-most notably the NIST Cybersecurity Framework (CSF) and the SP 800 series-that cover security operations holistically and are recognized as industry best…
Question
The Chief Executive Officer (CEO) instructed the new Chief Information Security Officer (CISO) to provide a list of enhancements to the company's cybersecurity operation. As a result, the CISO has identified the need to align security operations with industry best practices. Which of the following industry references is appropriate to accomplish this?
Options
- AOSSM
- BNIST
- CPCI
- DOWASP
How the community answered
(54 responses)- A4% (2)
- B89% (48)
- C2% (1)
- D6% (3)
Explanation
NIST (National Institute of Standards and Technology) publishes widely adopted cybersecurity frameworks and guidelines-most notably the NIST Cybersecurity Framework (CSF) and the SP 800 series-that cover security operations holistically and are recognized as industry best practices. OWASP is focused narrowly on web application security, PCI DSS applies specifically to payment card data environments, and OSSM is not a recognized industry-standard cybersecurity framework. When a CISO needs a broad, authoritative reference to benchmark and improve overall security operations, NIST is the appropriate choice.
Topics
Community Discussion
No community discussion yet for this question.