Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

A Mumbai-based fintech firm wants an independent certificate that its information security management system meets an international benchmark, and it also wants controls on its network to be selected based on a documented risk assessment. Which approach fits best?

The firm should seek certification to ISO/IEC 27001 and record its risk-based control selection in a Statement of Applicability. ISO 27001 is the certifiable ISMS standard, whereas the NIST CSF is a voluntary framework and PCI DSS is limited to payment card data environments.

  1. ASeek certification to ISO/IEC 27001 and document control selection in a Statement of ApplicabilityCorrect
  2. BAdopt the NIST CSF, because it is a certifiable standard issued by an accredited certification body
  3. CRely on a PCI DSS self-declaration, since it certifies the entire organisation's ISMS
  4. DImplement only a perimeter firewall, since certification requires no documentation of controls

Explanation

ISO/IEC 27001 is the certifiable ISMS standard, and a Statement of Applicability records which controls are selected and why, based on risk assessment. NIST CSF is a voluntary framework, not certifiable in itself. PCI DSS covers payment card data environments, not a whole ISMS.

Did you get it right without looking?

One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.

More Network Basics and Security questions