CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

A security architect is tasked with establishing a robust governance framework for a rapidly growing fintech startup. The startup processes sensitive financial data and operates across multiple jurisdictions. The architect needs a framework that provides a comprehensive approach to information security, covering organizational structure, policies, processes, and risk management, while also being internationally recognized for demonstrating due diligence to regulators and partners. Which of the following frameworks is MOST suitable for this requirement?

  1. AGDPR
  2. BPCI DSS
  3. CNIST SP 800-53
  4. DISO/IEC 27001
Show answer & explanation

Correct answer: D. ISO/IEC 27001

ISO/IEC 27001 is an internationally recognized standard for Information Security Management Systems (ISMS), providing a comprehensive framework for managing information security risks. It covers organizational structure, policies, processes, and risk management, making it highly suitable for a fintech startup operating across multiple jurisdictions and needing to demonstrate due diligence.

Why the other options are wrong

  • A. GDPR is a data privacy regulation, not an information security governance framework.
  • B. PCI DSS is a standard for handling credit card data, not a general information security governance framework.
  • C. NIST SP 800-53 is a catalog of security and privacy controls for U.S. federal information systems, less focused on an overall ISMS framework for international business.

ISO/IEC 27001

An international standard that provides requirements for an Information Security Management System (ISMS).

  • Establishes, implements, operates, monitors, reviews, maintains, and improves an ISMS.
  • Widely recognized globally for information security best practices.
  • Focuses on managing information security risks systematically.

Memory trick: ISO-late your risks with a global standard.

More Governance, Risk and Compliance questions