CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard
A Chief Information Officer (CIO) is evaluating the organization's information security program and wants to ensure it is aligned with industry best practices and regulatory requirements. The CIO is particularly interested in a security framework that provides a comprehensive, risk-based approach to managing information security. Which framework would be MOST suitable for this purpose?
- ASarbanes-Oxley Act (SOX)
- BPayment Card Industry Data Security Standard (PCI DSS)
- CGeneral Data Protection Regulation (GDPR)
- DISO/IEC 27001
Show answer & explanationAnswer & explanation
Correct answer: D. ISO/IEC 27001
ISO/IEC 27001 is an international standard for Information Security Management Systems (ISMS) that provides a holistic, risk-based approach to managing information security. It is comprehensive and applicable across various industries and regulatory landscapes.
Why the other options are wrong
- A. SOX is an act related to financial reporting and corporate governance, not a comprehensive information security framework.
- B. PCI DSS is a standard specifically for organizations handling credit card data, not a general comprehensive security program framework.
- C. GDPR is a data privacy regulation, not a security management framework, although it has security implications.
ISO/IEC 27001
An international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) within the context of the organization's overall business risks.
- Provides a risk-based approach.
- Technology-neutral and vendor-neutral.
- Certifiable standard, widely recognized globally.
Memory trick: Frameworks guide security, regulations enforce it.