ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium

A global e-commerce company is preparing for its annual external audit. The auditors request documentation detailing the formal process by which security controls are selected, implemented, and managed to reduce identified risks to an acceptable level. Which document or concept are the auditors most likely referring to?

  1. ABusiness Continuity Plan (BCP)
  2. BIncident Response Plan (IRP)
  3. CRisk Management Framework (RMF)
  4. DDisaster Recovery Plan (DRP)
Show answer & explanation

Correct answer: C. Risk Management Framework (RMF)

The auditors are asking for the formal process of managing risks, from selection and implementation of controls to reducing risks to an acceptable level. This entire lifecycle is encapsulated within a Risk Management Framework (RMF).

Why the other options are wrong

  • A. A BCP details how to maintain business functions during disruptions.
  • B. An IRP outlines steps for responding to security incidents.
  • D. A DRP focuses on recovering IT systems and data after a disaster.

Risk Management Framework (RMF)

A structured approach to integrating security and privacy into the system development life cycle and throughout the entire organization.

  • Provides a systematic process for managing security risks.
  • Typically includes steps like categorizing, selecting, implementing, assessing, authorizing, and monitoring.
  • Aids in ensuring compliance and reducing organizational risk.

Memory trick: Plans for every security scenario, from daily risks to disasters.

More Security and Risk Management questions