Courseiva
Security and Risk ManagementmediumMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Which governance framework is specifically designed to help organizations manage and protect their information assets by providing a comprehensive set of controls based on a risk management approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ISO/IEC 27001

ISO/IEC 27001 is an international standard for information security management systems (ISMS) that provides a risk-based approach to managing information security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ISO/IEC 27001

    Why this is correct

    ISO/IEC 27001 is the international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Its primary purpose is to provide a systematic approach for organizations to manage and protect their sensitive information assets, ensuring their confidentiality, integrity, and availability. This framework is specifically designed to help organizations manage information security risks effectively and achieve certification.

  • NIST Cybersecurity Framework

    Why it's wrong here

    The NIST Cybersecurity Framework (CSF) is a voluntary framework designed to help organizations, particularly critical infrastructure, manage and reduce cybersecurity risks. It provides a flexible, risk-based approach to improving cybersecurity posture through five core functions: Identify, Protect, Detect, Respond, and Recover. While excellent for cybersecurity risk management, it does not prescribe a formal, auditable management system for all information assets in the comprehensive manner of ISO 27001.

  • COBIT 2019

    Why it's wrong here

    COBIT 2019 (Control Objectives for Information and Related Technologies) is a comprehensive framework for enterprise governance of information and technology (EGIT). It provides principles, processes, and organizational structures to help organizations govern and manage their IT assets and information holistically, aligning IT with business objectives and managing IT-related risks. While information is central, COBIT's scope is broader, encompassing overall IT governance rather than a specific information security management system.

  • ITIL

    Why it's wrong here

    ITIL (Information Technology Infrastructure Library) is a widely adopted framework providing detailed practices for IT service management (ITSM). It focuses on aligning IT services with business needs, covering the entire service lifecycle from strategy and design to operation and continual improvement. ITIL is primarily concerned with the efficient and effective delivery and support of IT services, rather than the overarching governance and security management of information assets themselves.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.