Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A large enterprise is evaluating different security frameworks to improve its overall cybersecurity posture. They are particularly interested in a framework that provides a comprehensive set of guidelines and best practices for managing cybersecurity risk, organized into five core functions: Identify, Protect, Detect, Respond, and Recover. Which cybersecurity framework is being described?
- APCI DSS
- BGDPR
- CISO/IEC 27001
- DNIST Cybersecurity Framework (CSF)
Show answer & explanationAnswer & explanation
Correct answer: D. NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework is renowned for its structure around five core functions: Identify, Protect, Detect, Respond, and Recover, which directly matches the description provided in the scenario.
Why the other options are wrong
- A. PCI DSS (Payment Card Industry Data Security Standard) focuses specifically on protecting credit card data.
- B. GDPR (General Data Protection Regulation) is a data privacy regulation, not a cybersecurity framework with these specific functions.
- C. ISO/IEC 27001 is an international standard for Information Security Management Systems (ISMS), not defined by these five core functions.
NIST Cybersecurity Framework (CSF)
A voluntary framework for organizations to manage and reduce cybersecurity risk, composed of five core functions: Identify, Protect, Detect, Respond, and Recover.
- Developed by the National Institute of Standards and Technology (NIST).
- Provides a common language for cybersecurity risk management.
- Applicable across various sectors and organization sizes.
- Aims to improve critical infrastructure cybersecurity.
Memory trick: NIST's core functions: I Protect Detect, Respond, Recover.