CCSK · Question #32
Select the best definition of 'compliance' from the options below.
The correct answer is D. The awareness and adherence to obligations, including the assessment and prioritization of. This question tests the formal definition of compliance in a security and regulatory governance context. The correct answer captures the full scope of compliance as awareness, adherence, and structured prioritization of obligations.
Question
Select the best definition of 'compliance' from the options below.
Options
- AThe development of a routine that covers all necessary security measures.
- BThe diligent habits of good security practices and recording of the same.
- CThe timely and efficient filing of security reports.
- DThe awareness and adherence to obligations, including the assessment and prioritization of
- EThe process of completing all forms and paperwork necessary to develop a defensible paper trail.
How the community answered
(43 responses)- A2% (1)
- B16% (7)
- C7% (3)
- D72% (31)
- E2% (1)
Why each option
This question tests the formal definition of compliance in a security and regulatory governance context. The correct answer captures the full scope of compliance as awareness, adherence, and structured prioritization of obligations.
Developing a routine covering security measures describes a procedural or policy activity, not compliance, which specifically requires awareness of and adherence to defined external and internal obligations.
Diligent habits of good security practices describe due care or security hygiene, not compliance - compliance is obligation-driven and externally defined, not habit-based.
Timely filing of security reports is one narrow activity that may support compliance evidence but does not constitute a definition of compliance as a discipline.
Compliance is formally defined as the awareness of and adherence to obligations - encompassing laws, regulations, contractual requirements, and internal policies - along with the assessment and prioritization of corrective actions where gaps are identified. This definition reflects both the proactive monitoring dimension and the structured remediation response, distinguishing compliance from mere documentation or routine security habits.
Completing forms and paperwork for a defensible paper trail describes documentation practices that may support compliance evidence but do not define what compliance is.
Concept tested: Definition of compliance in security governance
Source: https://csrc.nist.gov/glossary/term/compliance
Topics
Community Discussion
No community discussion yet for this question.