CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceHard
A CISO is reviewing the organization's approach to cybersecurity and is considering adopting a framework that provides a common language for both technical and business stakeholders, enables risk prioritization based on business needs, and helps integrate cybersecurity into overall enterprise risk management. Which framework is designed with these capabilities?
- ANIST CSF
- BITIL
- CCOBIT
- DISO/IEC 27001
Show answer & explanationAnswer & explanation
Correct answer: A. NIST CSF
The NIST Cybersecurity Framework (CSF) is specifically designed to provide a common language for cybersecurity risk between technical and business stakeholders. Its risk-based approach allows organizations to prioritize cybersecurity activities based on business needs and integrate cybersecurity into broader enterprise risk management, making it an excellent fit for the CISO's requirements.
Why the other options are wrong
- B. ITIL is an IT service management framework, not a cybersecurity risk management framework.
- C. COBIT is an IT governance framework, broader than just cybersecurity and less focused on the specific 'common language' and 'business needs' prioritization for cybersecurity risk.
- D. ISO/IEC 27001 is a strong ISMS standard but is often seen as more technical and less focused on providing a common, high-level business language for risk.
NIST Cybersecurity Framework (CSF)
A voluntary framework that provides guidance for organizations to manage and reduce their cybersecurity risk.
- Offers a common language for technical and business stakeholders.
- Risk-based approach allows for prioritization based on business needs.
- Integrates cybersecurity into overall enterprise risk management.
Memory trick: NIST unifies business and tech, like two sides of a coin.