ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

A new cloud service provider is seeking to attract enterprise clients who handle sensitive data. To demonstrate their commitment to data protection and meet various industry-specific regulations, they implement ISO 27001. This certification helps them prove adherence to a set of established security practices. What term best describes this activity of demonstrating conformity to rules and requirements?

  1. ADisaster Recovery
  2. BRisk Tolerance
  3. CSecurity Awareness Training
  4. DCompliance
Show answer & explanation

Correct answer: D. Compliance

Compliance refers to the act of conforming to a rule, standard, law, or requirement. Obtaining ISO 27001 certification demonstrates compliance with an internationally recognized information security standard.

Why the other options are wrong

  • A. Disaster Recovery focuses on business continuity after a major event, not adherence to security practices.
  • B. Risk tolerance is the acceptable deviation from achieving objectives related to risk.
  • C. Security Awareness Training educates employees, but is not the act of conforming to rules itself.

Compliance

The act of conforming to a rule, standard, law, or requirement. In cybersecurity, it involves adhering to regulations, policies, and industry best practices.

  • Mandatory for many industries (e.g., healthcare, finance).
  • Requires ongoing monitoring and auditing.
  • Failure can result in fines, legal action, and reputational damage.

Memory trick: Following the rules keeps the business cool.

More Security Principles questions