CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceHard

A security architect is designing a system for a critical infrastructure organization. Due to the high impact of any disruption, they are evaluating a framework that provides detailed guidance on identifying, protecting, detecting, responding to, and recovering from cyber incidents. The organization also needs to demonstrate compliance with various government regulations. Which of the following frameworks is best suited for this purpose?

  1. AISO 27001
  2. BITIL v4
  3. CCOBIT 5
  4. DNIST Cybersecurity Framework (CSF)
Show answer & explanation

Correct answer: D. NIST Cybersecurity Framework (CSF)

The NIST Cybersecurity Framework (CSF) is specifically designed for critical infrastructure, providing a flexible, risk-based approach to cybersecurity management structured around the five core functions: Identify, Protect, Detect, Respond, and Recover. Its adaptability makes it suitable for demonstrating compliance with various regulations.

Why the other options are wrong

  • A. ISO 27001 is an international standard for Information Security Management Systems (ISMS), but NIST CSF is more directly aligned with the 'Identify, Protect, Detect, Respond, Recover' functions and critical infrastructure focus.
  • B. ITIL v4 is focused on IT service management, not primarily on cybersecurity incident lifecycle management for critical infrastructure.
  • C. COBIT 5 is an IT governance framework, broader than just cybersecurity and not specifically tailored for critical infrastructure's incident lifecycle.

NIST Cybersecurity Framework (CSF)

A voluntary framework for organizations to manage and reduce cybersecurity risk, particularly for critical infrastructure. It is structured around five core functions: Identify, Protect, Detect, Respond, and Recover.

  • Voluntary, risk-based framework.
  • Designed for critical infrastructure.
  • Five core functions: Identify, Protect, Detect, Respond, Recover.

Memory trick: NIST CSF: Critical infrastructure's 5-step cyber shield.

More Governance, Risk and Compliance questions