Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard
A newly appointed Chief Information Security Officer (CISO) is tasked with establishing a unified, organization-wide approach to managing cybersecurity risks. The CISO wants to adopt a set of guidelines and best practices that provide a common language and systematic methodology for identifying, assessing, and responding to cyber threats. Which foundational security concept should the CISO prioritize implementing?
- ASecurity awareness training program
- BSecurity frameworks
- CSecurity operations center (SOC)
- DAdvanced persistent threat (APT) intelligence
Show answer & explanationAnswer & explanation
Correct answer: B. Security frameworks
The CISO needs a 'unified, organization-wide approach' with 'guidelines and best practices' and a 'systematic methodology'. This perfectly describes the purpose of 'security frameworks' like NIST CSF or ISO 27001, which provide the structure for managing security.
Why the other options are wrong
- A. Awareness training educates employees; it's a component, not the overarching methodology.
- C. A SOC is an operational unit, not a foundational methodology for overall risk management.
- D. APT intelligence is a specific type of threat data, not a comprehensive management approach.
Security Frameworks
A structured set of guidelines, best practices, and standards that organizations can use to manage and improve their cybersecurity risk posture and establish a comprehensive security program.
- Provide a common language and systematic approach to security.
- Examples include NIST Cybersecurity Framework, ISO 27001, CIS Controls.
- Help organizations comply with regulations and achieve security objectives.
Memory trick: Frameworks build the foundation for a strong security house.