List of questions
Related questions
Question 307 - 712-50 discussion
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation.
Which of the following industry / sector neutral information security control frameworks should you recommend for implementation?
A.
National Institute of Standards and Technology (NIST) Special Publication 800-53
B.
Payment Card Industry Digital Security Standard (PCI DSS)
C.
International Organization for Standardization – ISO 27001/2
D.
British Standard 7799 (BS7799)
Your answer:
0 comments
Sorted by
Leave a comment first