Akylade Certified Cyber Resilience Fundamentals ACCRF · Free Practice Question Medium
Question 20
Which of the following informative references specifically addresses integrating information and communications technology (ICT) risk management programs with the broader enterprise risk portfolio?
- A ISO/IEC 27002
- B CIS Controls
- C NIST SP 800-221A
- D PCI-DSS
Reveal correct answer
Correct answer: C
Explanation
NIST Special Publication 800-221A (SP 800-221A), Information and Communications Technology (ICT) Risk Outcomes: Integrating ICT Risk Management Programs with the Enterprise Risk Portfolio, provides guidance on integrating ICT risk management with enterprise risk management to achieve a comprehensive risk overview. International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 27002 provides guidelines for organizational information security standards and information security management practices, including selection, implementation, and management of controls, focusing on the security techniques rather than integration with enterprise risk. Payment Card Industry Data Security Standard (PCI-DSS) specifies security standards for handling cardholder information within the payment card industry, focusing on security controls rather than integration with broader enterprise risk management. Center for Internet Security (CIS) Critical Security Controls provides a concise set of prioritized cybersecurity best practices, designed to help organizations rapidly improve their defense against cyber threats, focusing primarily on technical security controls rather than broad enterprise risk integration. For support or reporting issues, include Question ID: 661cc224035342b5edd52f11 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
