Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceHard
A global enterprise is evaluating its cloud strategy and aims to create a unified approach to managing risks across its on-premises, private cloud, and public cloud environments. The objective is to provide a holistic view of risk to senior management and ensure consistent risk treatment regardless of where assets reside. Which framework is BEST suited for achieving this comprehensive, integrated risk management approach?
- ANational Institute of Standards and Technology (NIST) Risk Management Framework (RMF).
- BISO/IEC 27001 Information Security Management System (ISMS).
- CCloud Security Alliance (CSA) Cloud Controls Matrix (CCM).
- DPayment Card Industry Data Security Standard (PCI DSS).
Show answer & explanationAnswer & explanation
Correct answer: A. National Institute of Standards and Technology (NIST) Risk Management Framework (RMF).
The NIST Risk Management Framework (RMF) provides a comprehensive, structured, and flexible approach to managing security and privacy risk for information systems and organizations. It is designed to be applicable across diverse environments, including hybrid and multi-cloud, making it ideal for a holistic, integrated risk management approach.
Why the other options are wrong
- B. ISO 27001 provides requirements for an ISMS, which includes risk management, but NIST RMF is often considered more prescriptive and tailored for federal systems, making it highly suitable for comprehensive enterprise-wide risk management across hybrid environments.
- C. CSA CCM is a good set of cloud-specific controls, but it's a control framework, not a comprehensive risk management framework for an entire enterprise across all environments.
- D. PCI DSS is a specific standard for protecting payment card data, not a general enterprise-wide risk management framework for diverse environments.
NIST Risk Management Framework (RMF)
A comprehensive, six-step process developed by NIST to manage security and privacy risks for information systems and organizations, applicable across diverse environments including hybrid and multi-cloud.
- Provides a structured approach to risk management.
- Applicable to federal agencies and widely adopted by private sector.
- Emphasizes continuous monitoring and risk posture awareness.
Memory trick: For holistic risk, NIST RMF is the best fit.