Guidelines for Information Security Risk Management

Security Standards and Frameworks
Answer Correct answer: B — The NIST Cybersecurity Framework (CSF) provides voluntary guidelines, standards, and best practices for organizations to manage and reduce cybersecurity risk.

Which of the following provides guidelines for the management and reduction of information security risk?

  1. CIS
  2. NIST CSF Correct Answer
  3. ISO
  4. PCI DSS

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the distinction between frameworks/guidelines (NIST CSF) and certification standards (ISO), a common trap in SY0-601 security governance questions.

The NIST Cybersecurity Framework (CSF) provides voluntary guidelines for managing cybersecurity risk, distinguishing it from mandatory standards like ISO or PCI DSS.

Candidates often select ISO because it is a widely recognized standard, but they miss the keyword 'guidelines' which specifically points to the non-mandatory nature of the NIST CSF.

Community Discussion (6 comments)

CircaG 👍 5 Selected: B
B. The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) provides guidelines, standards, and best practices for organizations to manage and reduce cybersecurity risk. It offers a flexible and customizable framework that helps organizations align their cybersecurity activities with business objectives, risk tolerance, and available resources.
chizzuck 👍 1 Selected: B
B. NIST CSF • National Institute of Standards and Technology – Cybersecurity Framework (CSF) – A voluntary commercial framework • Framework Core – Identify, Protect, Detect, Respond, and Recover • Framework Implementation Tiers – An organization’s view of cybersecurity risk and processes to manage the risk • Framework Profile - The alignment of standards, guidelines, and practices to the Framework Core
AspiringNerd 👍 2 Selected: B
NIST CSF is a guideline. ISO are standards.
MortG7 👍 1
The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts.
RamnathKM 👍 1 Selected: C
ISO 27001 https://www.iso.org/standard/27001
paCer66 👍 4
B. The NIST CSF is designed as a guide, whereas ISO 27001 is designed as a standard. The difference here is that NIST CSF serves as an instruction manual and ISO 27001 is more of a test that requires certain measures to pass. In the NIST CSF, there is no certification or audit process.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B. The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) is explicitly designed as a voluntary framework that provides guidelines, standards, and best practices for organizations to manage and reduce cybersecurity risk. It focuses on aligning cybersecurity activities with business objectives without imposing a rigid certification process.

Why the Other Options Are Wrong

Option A (CIS) refers to the Center for Internet Security, whose Critical Security Controls are also guidelines, but the term 'CIS' alone is less specific than the full name of the NIST CSF in this context. Option C (ISO) typically refers to ISO/IEC 27001, which is an international standard requiring certification and audit, rather than just providing guidelines. Option D (PCI DSS) is a compliance standard for payment card data, not a general risk management guideline.

Community Comment Notes

Community consensus strongly favors B, with users highlighting that NIST CSF serves as an instruction manual while ISO is more of a test. As paCer66 noted, "The difference here is that NIST CSF serves as an instruction manual and ISO 27001 is more of a test that requires certain measures to pass." Another user confirmed that NIST CSF is a guideline whereas ISO is a standard.

Official Reference

Exam Strategy

When studying security governance, always differentiate between 'standards' (mandatory, certifiable like ISO 27001 or PCI DSS) and 'frameworks/guidelines' (voluntary, flexible like NIST CSF). Look for keywords like 'voluntary,' 'best practices,' or 'guidelines' to identify the latter.

Frequently Asked Questions

Is NIST CSF a standard or a guideline?

NIST CSF is a framework that provides guidelines and best practices. It is voluntary and does not require certification, unlike ISO 27001.

Why is ISO not the correct answer for guidelines?

ISO 27001 is an international standard that requires formal certification and auditing. The question asks for 'guidelines,' which aligns with the voluntary nature of the NIST CSF.

Related Analysis

← Back to SY0-601 Study Guide