Question 1 of 30
In a corporate environment, a security team is tasked with implementing a security framework that aligns with both the NIST Cybersecurity Framework and ISO/IEC 27001 standards. The team must ensure that their approach not only addresses risk management but also incorporates continuous monitoring and improvement. Which of the following strategies best exemplifies a comprehensive approach to achieving these objectives while ensuring compliance with both frameworks?
Establishing a risk management program that includes regular risk assessments, incident response planning, and continuous monitoring of security controls, while also documenting and reviewing policies and procedures regularly to adapt to emerging threats and vulnerabilities.
Implementing a one-time risk assessment followed by a static set of security controls that are not regularly reviewed or updated, focusing solely on compliance with ISO/IEC 27001 without considering the dynamic nature of cybersecurity threats.
Developing a security awareness training program for employees that is conducted annually, without integrating feedback mechanisms or updates based on the latest threat intelligence or incidents.
Focusing exclusively on technical controls such as firewalls and intrusion detection systems, while neglecting the importance of organizational policies, employee training, and incident response planning.

Preparing for CISCO 300-915 Developing Solutions using Cisco IoT & Edge Platforms? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free