nerdexam
(ISC)2

HCISPP · Question #269

Which of the BEST internationally recognized standard for evaluating security products and systems?

The correct answer is B. Common Criteria (CC). Common Criteria (ISO/IEC 15408) is the internationally recognized standard specifically designed for evaluating the security properties of IT products and systems. It provides a framework for defining security requirements (Protection Profiles), specifying security claims…

Regulatory and Standards Environment

Question

Which of the BEST internationally recognized standard for evaluating security products and systems?

Options

  • APayment Card Industry Data Security Standards (PCI-DSS)
  • BCommon Criteria (CC)
  • CHealth Insurance Portability and Accountability Act (HIPAA)
  • DSarbanes-Oxley (SOX)

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    94% (34)
  • D
    3% (1)

Explanation

Common Criteria (ISO/IEC 15408) is the internationally recognized standard specifically designed for evaluating the security properties of IT products and systems. It provides a framework for defining security requirements (Protection Profiles), specifying security claims (Security Targets), and independently evaluating products at defined assurance levels (EAL 1–7). Governments and organizations worldwide use CC evaluations to certify products before procurement. The other options are not product evaluation standards: PCI-DSS governs payment card data security for merchants; HIPAA is U.S. healthcare privacy and security regulation; and SOX (Sarbanes-Oxley) addresses financial reporting and internal controls for public companies.

Topics

#Common Criteria#Security product evaluation#International standards

Community Discussion

No community discussion yet for this question.

Full HCISPP Practice