Certified Information Security Manager (CISM)Information Security Risk ManagementHard

A multinational corporation is developing a new cloud-based application that will process sensitive customer data across various geographical regions. The CISO needs to ensure that the application's security architecture is robust and compliant with diverse regulations. Which framework provides a comprehensive, integrated approach to manage governance, risk, and compliance (GRC) across the organization's IT environment?

  1. AA tailored GRC framework incorporating relevant standards and internal policies.
  2. BPayment Card Industry Data Security Standard (PCI DSS).
  3. CISO/IEC 27001.
  4. DNational Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF).
Show answer & explanation

Correct answer: A. A tailored GRC framework incorporating relevant standards and internal policies.

While standards like ISO 27001 and NIST CSF provide excellent guidance, a multinational corporation with diverse regulatory requirements and specific cloud initiatives needs a tailored GRC framework. This framework would integrate elements from relevant external standards (like ISO 27001, NIST, GDPR, etc.) with internal policies and processes to create a comprehensive, customized approach to govern risk and compliance across its unique environment.

Why the other options are wrong

  • B. PCI DSS is specific to payment card data and not a comprehensive GRC framework for all sensitive data and regulations.
  • C. ISO/IEC 27001 is a strong standard for Information Security Management Systems but is not, by itself, a full GRC framework that integrates all aspects of governance and diverse regulatory compliance without tailoring.
  • D. NIST CSF provides a framework for managing cybersecurity risk but doesn't fully encompass all aspects of governance and broader compliance across diverse regulations for a multinational.

Tailored GRC Framework

A customized Governance, Risk, and Compliance (GRC) framework that integrates elements from various industry standards, regulatory requirements, and internal policies to address an organization's unique operational and risk profile.

  • Combines multiple standards and regulations.
  • Addresses specific organizational context and risks.
  • Provides a holistic approach to governance, risk, and compliance.

Memory trick: Global GRC: Tailor-made for diverse rules and risks.

More Information Security Risk Management questions