Guidelines for Information Security Risk Management
Which of the following provides guidelines for the management and reduction of information security risk?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between frameworks/guidelines (NIST CSF) and certification standards (ISO), a common trap in SY0-601 security governance questions.
The NIST Cybersecurity Framework (CSF) provides voluntary guidelines for managing cybersecurity risk, distinguishing it from mandatory standards like ISO or PCI DSS.
Candidates often select ISO because it is a widely recognized standard, but they miss the keyword 'guidelines' which specifically points to the non-mandatory nature of the NIST CSF.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is B. The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) is explicitly designed as a voluntary framework that provides guidelines, standards, and best practices for organizations to manage and reduce cybersecurity risk. It focuses on aligning cybersecurity activities with business objectives without imposing a rigid certification process.Why the Other Options Are Wrong
Option A (CIS) refers to the Center for Internet Security, whose Critical Security Controls are also guidelines, but the term 'CIS' alone is less specific than the full name of the NIST CSF in this context. Option C (ISO) typically refers to ISO/IEC 27001, which is an international standard requiring certification and audit, rather than just providing guidelines. Option D (PCI DSS) is a compliance standard for payment card data, not a general risk management guideline.Community Comment Notes
Community consensus strongly favors B, with users highlighting that NIST CSF serves as an instruction manual while ISO is more of a test. As paCer66 noted, "The difference here is that NIST CSF serves as an instruction manual and ISO 27001 is more of a test that requires certain measures to pass." Another user confirmed that NIST CSF is a guideline whereas ISO is a standard.Official Reference
Exam Strategy
When studying security governance, always differentiate between 'standards' (mandatory, certifiable like ISO 27001 or PCI DSS) and 'frameworks/guidelines' (voluntary, flexible like NIST CSF). Look for keywords like 'voluntary,' 'best practices,' or 'guidelines' to identify the latter.
Frequently Asked Questions
Is NIST CSF a standard or a guideline?
NIST CSF is a framework that provides guidelines and best practices. It is voluntary and does not require certification, unlike ISO 27001.
Why is ISO not the correct answer for guidelines?
ISO 27001 is an international standard that requires formal certification and auditing. The question asks for 'guidelines,' which aligns with the voluntary nature of the NIST CSF.