Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is evaluating the current state of the information security program against industry best practices. The organization has established basic security controls, but there is no clear roadmap for future improvements, and security initiatives are often reactive. Which of the following frameworks would be MOST appropriate for the CISO to adopt to establish a structured approach for continuous improvement and maturity measurement?
- ANIST Cybersecurity Framework (CSF)
- BISO/IEC 27001
- CPayment Card Industry Data Security Standard (PCI DSS)
- DCOBIT 5
Show answer & explanationAnswer & explanation
Correct answer: A. NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) is designed to help organizations improve their cybersecurity posture through a structured, risk-based approach. Its core functions (Identify, Protect, Detect, Respond, Recover) and implementation tiers make it ideal for establishing a roadmap for continuous improvement and measuring maturity, especially when moving beyond basic controls.
Why the other options are wrong
- B. ISO/IEC 27001 is excellent for establishing an Information Security Management System (ISMS) and achieving certification, but NIST CSF is often more directly focused on improving and measuring cybersecurity posture in a continuous manner.
- C. PCI DSS is a prescriptive standard primarily focused on protecting cardholder data, not a general framework for overall security program maturity and continuous improvement.
- D. COBIT 5 (now COBIT 2019) is an IT governance framework that includes security but is broader than just cybersecurity program improvement and might be overkill for this specific need.
NIST Cybersecurity Framework (CSF)
A voluntary framework consisting of standards, guidelines, and best practices to manage cybersecurity risk. It is designed to be flexible and scalable for organizations of all sizes and sectors.
- Provides a risk-based approach to cybersecurity.
- Includes five core functions: Identify, Protect, Detect, Respond, Recover.
- Offers implementation tiers for maturity measurement and continuous improvement.
Memory trick: NIST Gives the Steps to Rise and Thrive.