Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard

A large enterprise is evaluating different approaches to manage its cybersecurity posture. They are considering adopting a standardized set of guidelines and best practices, such as NIST Cybersecurity Framework or ISO 27001, to help them establish, implement, maintain, and continually improve their information security. This strategic decision is about implementing a:

  1. ASecurity Policy
  2. BSecurity Standard
  3. CSecurity Framework
  4. DSecurity Baseline
Show answer & explanation

Correct answer: C. Security Framework

NIST CSF and ISO 27001 are examples of security frameworks. A security framework provides a structured set of guidelines, best practices, and processes to help organizations manage and improve their overall cybersecurity posture, establishing a common language and approach.

Why the other options are wrong

  • A. A security policy is a specific rule or set of rules within an organization, not a broad structured approach like NIST CSF.
  • B. While ISO 27001 is a 'standard', the question describes adopting a 'set of guidelines and best practices... to establish, implement, maintain, and continually improve', which is the broader function of a framework. Frameworks often incorporate standards.
  • D. A security baseline is a minimum security configuration or state, not a comprehensive management system.

Security Framework

A structured set of guidelines, best practices, and processes designed to help organizations manage and improve their overall cybersecurity posture.

  • Provides a common language and systematic approach to security.
  • Examples include NIST Cybersecurity Framework, ISO 27001.
  • Helps establish, implement, maintain, and continually improve information security.

Memory trick: Frameworks provide the 'FRAME' for 'WORK'ing on security.

More Security Concepts questions