CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceHard
A security architect is designing an information security program for a critical infrastructure organization. The organization needs a framework that provides a flexible, risk-based approach to cybersecurity, allowing for adaptation to evolving threats and technologies, while also enabling communication of cybersecurity risk to a wide range of stakeholders. Which framework is BEST suited for this requirement?
- ACOBIT
- BNIST Cybersecurity Framework (CSF)
- CHIPAA
- DISO/IEC 27001
Show answer & explanationAnswer & explanation
Correct answer: B. NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) is designed to be flexible, adaptable, and risk-based, making it suitable for critical infrastructure. It provides a common language for communicating cybersecurity risk among stakeholders at all levels, from technical teams to senior management, and is not prescriptive, allowing organizations to tailor it to their specific needs and evolving threat landscape.
Why the other options are wrong
- A. COBIT focuses on IT governance and management, broader than just cybersecurity and less tailored for critical infrastructure's risk-based flexibility.
- C. HIPAA is a U.S. regulation for healthcare data, not a general cybersecurity framework for critical infrastructure.
- D. ISO/IEC 27001 is a comprehensive ISMS standard, but NIST CSF is often preferred for its flexibility and focus on critical infrastructure and communication.
NIST Cybersecurity Framework (CSF)
A voluntary framework for organizations to manage and reduce cybersecurity risk.
- Composed of five core functions: Identify, Protect, Detect, Respond, Recover.
- Designed to be flexible and adaptable to various sectors and organizational types.
- Enables communication of cybersecurity risk across an organization.
Memory trick: NIST for critical, flexible, and clear.