CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

A security architect is designing a new cloud-based data analytics platform that will process sensitive customer financial information. The architect needs to ensure that the platform adheres to strict data privacy regulations, including GDPR and CCPA, while also maintaining high availability and performance. Which of the following governance frameworks would be MOST appropriate to guide the design and implementation of security controls for this platform?

  1. ANIST CSF (National Institute of Standards and Technology Cybersecurity Framework)
  2. BITIL (Information Technology Infrastructure Library)
  3. CISO 27001 (International Organization for Standardization 27001)
  4. DPMBOK (Project Management Body of Knowledge)
Show answer & explanation

Correct answer: C. ISO 27001 (International Organization for Standardization 27001)

ISO 27001 provides a comprehensive framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Its focus on risk management and alignment with legal and regulatory requirements makes it highly suitable for platforms handling sensitive data under strict privacy regulations.

Why the other options are wrong

  • A. NIST CSF is a valuable framework for managing cybersecurity risk, but ISO 27001 offers a more formal, certifiable standard for an entire ISMS, which is often preferred for demonstrating regulatory compliance.
  • B. ITIL focuses on IT service management and operations, not primarily on information security governance or compliance with data privacy regulations.
  • D. PMBOK is a standard for project management, focusing on project lifecycles, processes, and knowledge areas, not information security governance or regulatory compliance.

ISO 27001

An international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within the context of the organization's overall business risks.

  • Provides a framework for an ISMS.
  • Focuses on risk management and regulatory compliance.
  • Internationally recognized and certifiable.

Memory trick: ISO-late your risks with a certified ISMS.

More Governance, Risk and Compliance questions