NSK101 · Question #40
Which two common security frameworks are used today to assess and validate a vendor's security practices? (Choose two.)
The correct answer is B. Building Security in Maturity Model C. ISO 27001. The Building Security in Maturity Model (BSIMM) is a framework that measures and compares the security activities of different organizations. It helps organizations to assess their current security practices and identify areas for improvement. ISO 27001 is an international standa
Question
Which two common security frameworks are used today to assess and validate a vendor's security practices? (Choose two.)
Options
- AData Science Council of America
- BBuilding Security in Maturity Model
- CISO 27001
- DNIST Cybersecurity Framework
How the community answered
(68 responses)- A15% (10)
- B79% (54)
- D6% (4)
Explanation
The Building Security in Maturity Model (BSIMM) is a framework that measures and compares the security activities of different organizations. It helps organizations to assess their current security practices and identify areas for improvement. ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and improving an information security management system. It helps organizations to manage their information security risks and demonstrate their compliance with best practices. Data Science Council of America (DASCA) is not a security framework, but a credentialing body for data science professionals. NIST Cybersecurity Framework (NIST CSF) is a security framework, but it is not commonly used to assess and validate a vendor's security practices, as it is more focused on improving the cybersecurity of critical infrastructure sectors in the United States.
Topics
Community Discussion
No community discussion yet for this question.