nerdexam
Netskope

NSK101 · Question #40

Which two common security frameworks are used today to assess and validate a vendor's security practices? (Choose two.)

The correct answer is B. Building Security in Maturity Model C. ISO 27001. The Building Security in Maturity Model (BSIMM) is a framework that measures and compares the security activities of different organizations. It helps organizations to assess their current security practices and identify areas for improvement. ISO 27001 is an international standa

Implementing and Managing Cloud Security Policies

Question

Which two common security frameworks are used today to assess and validate a vendor's security practices? (Choose two.)

Options

  • AData Science Council of America
  • BBuilding Security in Maturity Model
  • CISO 27001
  • DNIST Cybersecurity Framework

How the community answered

(68 responses)
  • A
    15% (10)
  • B
    79% (54)
  • D
    6% (4)

Explanation

The Building Security in Maturity Model (BSIMM) is a framework that measures and compares the security activities of different organizations. It helps organizations to assess their current security practices and identify areas for improvement. ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and improving an information security management system. It helps organizations to manage their information security risks and demonstrate their compliance with best practices. Data Science Council of America (DASCA) is not a security framework, but a credentialing body for data science professionals. NIST Cybersecurity Framework (NIST CSF) is a security framework, but it is not commonly used to assess and validate a vendor's security practices, as it is more focused on improving the cybersecurity of critical infrastructure sectors in the United States.

Topics

#ISO 27001#BSIMM#security frameworks#vendor assessment

Community Discussion

No community discussion yet for this question.

Full NSK101 Practice