CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard
A new project is being initiated to develop a mobile application for a healthcare provider. The project manager is conducting an initial risk assessment. Which of the following frameworks would be MOST appropriate for guiding the security and privacy considerations throughout the entire Systems Development Life Cycle (SDLC) for this project?
- AISO 27001
- BITIL 4
- CNIST SP 800-53
- DCOBIT 2019
Show answer & explanationAnswer & explanation
Correct answer: C. NIST SP 800-53
NIST SP 800-53 provides a comprehensive catalog of security and privacy controls for federal information systems and organizations, which can be tailored and applied throughout the SDLC to ensure that security is built-in from the start, especially relevant for sensitive data like healthcare information.
Why the other options are wrong
- A. ISO 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), but NIST SP 800-53 provides a more detailed and direct catalog of controls applicable to the SDLC.
- B. ITIL 4 is a framework for IT service management, focused on service delivery and operations, not SDLC security.
- D. COBIT 2019 is an IT governance framework, focusing on enterprise-wide IT management, not granular SDLC security controls.
NIST SP 800-53
A publication by the National Institute of Standards and Technology (NIST) that provides a catalog of security and privacy controls for all U.S. federal information systems, but widely adopted globally.
- Comprehensive catalog of controls.
- Guidance for federal agencies, but applicable broadly.
- Supports risk management framework (RMF) implementation.
Memory trick: NIST for controls, ISO for the system, COBIT for governance, ITIL for service.