ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 160 - SY0-601 discussion

Report
Export

A Chief Information Security Officer (CISO) is evaluating (he dangers involved in deploying a new ERP system tor the company. The CISO categorizes the system, selects the controls mat apply to the system, implements the controls, and then assesses the success of the controls before authorizing the system Which of the following is the CISO using to evaluate Hie environment for this new ERP system?

A.
The Diamond Model of Intrusion Analysis
Answers
A.
The Diamond Model of Intrusion Analysis
B.
CIS Critical Security Controls
Answers
B.
CIS Critical Security Controls
C.
NIST Risk Management Framevtoik
Answers
C.
NIST Risk Management Framevtoik
D.
ISO 27002
Answers
D.
ISO 27002
Suggested answer: C

Explanation:

The CISO is using the NIST Risk Management Framework (RMF) to evaluate the environment for the new ERP system. The RMF is a structured process for managing risks that involves categorizing the system, selecting controls, implementing controls, assessing controls, and authorizing the system.

Reference: CompTIA Security+ Study Guide, Exam SY0-601, 4th Edition, Chapter 4: Risk Management, pp. 188-191.

asked 02/10/2024
Cristian Melo
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first