nerdexam
Isaca

CISM · Question #135

A PRIMARY benefit of adopting an information security framework is that it provides:

The correct answer is A. standardized security controls. A primary benefit of adopting an information security framework is that it provides standardized security controls, offering a structured approach to managing information security risks.

Submitted by diego_uy· Apr 18, 2026Information Security Governance

Question

A PRIMARY benefit of adopting an information security framework is that it provides:

Options

  • Astandardized security controls.
  • Bcommon exploitability indices.
  • Ccredible emerging threat intelligence.
  • Dsecurity and vulnerability reporting guidelines.

How the community answered

(27 responses)
  • A
    89% (24)
  • C
    4% (1)
  • D
    7% (2)

Why each option

A primary benefit of adopting an information security framework is that it provides standardized security controls, offering a structured approach to managing information security risks.

Astandardized security controls.Correct

Information security frameworks, like NIST CSF or ISO 27001, offer a comprehensive set of guidelines and best practices that lead to the implementation of standardized security controls across an organization. These controls provide a consistent baseline for security, ensuring that different systems and processes meet a defined level of protection and compliance.

Bcommon exploitability indices.

Common exploitability indices are related to vulnerability assessment and penetration testing, not a primary benefit of a security framework.

Ccredible emerging threat intelligence.

Credible emerging threat intelligence is typically provided by specialized intelligence services, not directly by adopting a security framework.

Dsecurity and vulnerability reporting guidelines.

While a framework might *influence* reporting, its primary benefit is not defining specific reporting guidelines but rather establishing the controls themselves.

Concept tested: Benefits of security frameworks

Topics

#Information Security Frameworks#Security Controls#Standardization#Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice