CISSP Domain 1 – Test Question - Managing risk and internal controls in the enterprise
CISSP Domain 1 – Governance, Risk, and Compliance
Mastering Risk and Internal Controls with COBIT
Question:
Which of the following frameworks is MOST associated with managing risk and internal controls in the enterprise?
Answer: ✅ COBIT
Correct Answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is an enterprise IT governance framework developed by ISACA. It’s designed specifically to help organizations manage risk, align IT with business goals, and establish robust internal control mechanisms.
Why COBIT is the Best Fit:
-
Governance-centric: COBIT provides a governance and management framework that bridges the gap between technical issues, business risks, and control requirements.
-
Enterprise-level focus: It addresses enterprise-wide control and risk, not just technical configurations or isolated systems.
-
Control Objectives: The core of COBIT is built around control objectives, making it highly suitable for implementing and evaluating internal controls and risk management across an enterprise.
Why the Other Options Are Incorrect:
B. ISO/IEC 27001 – Incorrect
ISO 27001 is an international standard for Information Security Management Systems (ISMS). It’s focused on establishing, implementing, and maintaining a security framework, not directly on enterprise risk and internal control structures.
-
Primary Focus: Information security.
-
Use Case: Building an ISMS with risk assessment and treatment plans, but not enterprise governance.
C. NIST SP 800-53 – Incorrect
NIST 800-53 provides a catalog of security and privacy controls primarily for U.S. federal information systems.
-
Primary Focus: Security controls.
-
Use Case: Technical control baselines, not overarching enterprise governance.
D. PCI DSS – Incorrect
The Payment Card Industry Data Security Standard is a specialized framework for protecting cardholder data.
-
Primary Focus: Payment systems and cardholder data security.
-
Use Case: Compliance in retail, financial institutions, and e-commerce—not enterprise-wide risk management.
Key Takeaway:
When the question asks about enterprise-level risk and internal control, think COBIT.
Memory Hook:
COBIT = Controls + Business + IT
It’s your go-to framework for aligning IT with business and ensuring governance and risk are managed at the enterprise level.
CISSP Domain Reference:
Domain 1: Security and Risk Management
-
Topics: Governance frameworks, risk management, compliance
-
COBIT is a must-know framework for governance and control in this domain.
Comments
Post a Comment