ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A new cloud service provider is seeking to attract enterprise clients who handle sensitive data. To demonstrate their commitment to data protection and meet various industry-specific regulations, they implement ISO 27001. This certification helps them prove adherence to a set of established security practices. What term best describes this activity of demonstrating conformity to rules and requirements?
- ADisaster Recovery
- BRisk Tolerance
- CSecurity Awareness Training
- DCompliance
Show answer & explanationAnswer & explanation
Correct answer: D. Compliance
Compliance refers to the act of conforming to a rule, standard, law, or requirement. Obtaining ISO 27001 certification demonstrates compliance with an internationally recognized information security standard.
Why the other options are wrong
- A. Disaster Recovery focuses on business continuity after a major event, not adherence to security practices.
- B. Risk tolerance is the acceptable deviation from achieving objectives related to risk.
- C. Security Awareness Training educates employees, but is not the act of conforming to rules itself.
Compliance
The act of conforming to a rule, standard, law, or requirement. In cybersecurity, it involves adhering to regulations, policies, and industry best practices.
- Mandatory for many industries (e.g., healthcare, finance).
- Requires ongoing monitoring and auditing.
- Failure can result in fines, legal action, and reputational damage.
Memory trick: Following the rules keeps the business cool.