nerdexam
(ISC)2

CCSP · Question #147

Which security certification serves as a general framework that can be applied to any type of system or application?

The correct answer is A. ISO/IEC 27001. ISO/IEC 27001 is an international standard that provides a generic framework for an Information Security Management System (ISMS), applicable to organizations of any type or size.

Submitted by tyler.j· Apr 18, 2026Legal, Risk and Compliance

Question

Which security certification serves as a general framework that can be applied to any type of system or application?

Options

  • AISO/IEC 27001
  • BPCI DSS
  • CFIPS 140-2
  • DNIST SP 800-53

How the community answered

(50 responses)
  • A
    88% (44)
  • B
    4% (2)
  • C
    6% (3)
  • D
    2% (1)

Why each option

ISO/IEC 27001 is an international standard that provides a generic framework for an Information Security Management System (ISMS), applicable to organizations of any type or size.

AISO/IEC 27001Correct

ISO/IEC 27001 is a globally recognized international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Its principles and controls are designed to be generic and applicable to any organization, regardless of its type, size, or nature, making it a universal framework.

BPCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is a specific standard focused solely on protecting credit card data and applies only to entities that process, store, or transmit cardholder data.

CFIPS 140-2

FIPS 140-2 (Federal Information Processing Standard) is a U.S. government computer security standard that specifies requirements for cryptographic modules, not a general security management framework for systems or applications.

DNIST SP 800-53

NIST SP 800-53 (National Institute of Standards and Technology Special Publication 800-53) provides a catalog of security and privacy controls for information systems and organizations, primarily used by U.S. federal agencies, and while comprehensive, it's not an international certification framework for *any* system like ISO 27001.

Concept tested: Information Security Management System frameworks

Source: https://www.iso.org/standard/27001

Topics

#Security Standards#Information Security Management System#Compliance Frameworks#ISO 27001

Community Discussion

No community discussion yet for this question.

Full CCSP Practice