Standards Selection

Organizations use security standards to assess security programs and risks, improve defenses, and meet regulatory requirements across various industries and jurisdictions.

2 slides · 1 min read · Domain 2

Slide 1

Organizations may choose to adopt specific standards, sometimes called frameworks, to support the development and management of their information security posture.

Industry standards and best practices help organizations understand baseline security controls, assess the current state of their security programs, and identify what is required to strengthen the organization. Governments and industry groups have created frameworks to guide and assist organizations in the daunting task of protecting assets. Examples include the Payment Card Industry Data Security Standard (PCI DSS), ISO/IEC 27001 and 27002, and the European Union's General Data Protection Regulation (GDPR). Some standards may be legally required, depending on the type of organization and the nature of its activities.

As a security professional, you should be familiar with a wide range of standards and frameworks, as well as the organizations that develop these standards. These range from U.S.-based entities, such as the National Institute of Standards and Technology (NIST), to transnational entities, such as the European Union Agency for Cybersecurity (ENISA), the International Telecommunication Union (ITU), and the International Organization for Standardization (ISO).

Test this domain