CISSP Security and Risk Management Practice Question
Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ITIL
ITIL (Information Technology Infrastructure Library) is a set of practices for IT service management that focuses on aligning IT services with business needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ISO/IEC 27001
Why it's wrong here
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). While it ensures secure handling of information assets, its primary focus is on managing information security risks and controls across an organization, not on the lifecycle management of IT services themselves.
- ✗
NIST Cybersecurity Framework
Why it's wrong here
The NIST Cybersecurity Framework provides a policy framework of computer security guidelines to help organizations manage and reduce cybersecurity risks. It outlines five core functions—Identify, Protect, Detect, Respond, and Recover—to improve an organization's ability to prevent, detect, and respond to cyber incidents, but it does not detail a service delivery lifecycle.
- ✗
COBIT 2019
Why it's wrong here
COBIT 2019 is a comprehensive framework for enterprise IT governance and management, providing principles, processes, and organizational structures to align IT with business objectives. It focuses on value creation from IT, risk optimization, and resource optimization across the entire enterprise, rather than specifically detailing the lifecycle stages of individual IT services.
- ✓
ITIL
Why this is correct
ITIL (Information Technology Infrastructure Library) is a widely adopted framework providing best practices for IT service management (ITSM). It specifically guides organizations through the entire service lifecycle, encompassing Service Strategy, Design, Transition, Operation, and Continual Service Improvement, making it ideal for managing the full journey of IT services.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.