A global financial institution that processes credit card transactions is planning a major overhaul of its security governance structure. The CISO wants to implement a risk framework that specifically addresses the security requirements for handling payment card data while also providing comprehensive coverage for enterprise IT governance. Which combination of frameworks would best meet these requirements?
The correct answer is the combination of PCI DSS and COBIT. The Payment Card Industry Data Security Standard (PCI DSS) is specifically designed for organizations that handle credit card information, making it essential for the financial institution's credit card processing operations. It provides detailed requirements for securing cardholder data. Control Objectives for Information and Related Technology (COBIT) is a framework that focuses on IT governance and management across the enterprise, offering a comprehensive approach to aligning IT with business objectives.
ISO 27001 is a good general security framework but doesn't specifically address payment card requirements like PCI DSS does. NIST CSF is more focused on cybersecurity and is often used in the US public sector. While SABSA is an excellent security architecture framework, it doesn't provide the specific payment card industry controls needed. FedRAMP is primarily for cloud services in U.S. government agencies and wouldn't be appropriate for a global financial institution's core operations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the main goals of PCI DSS?
Open an interactive chat with Bash
How does COBIT integrate with IT governance?
Open an interactive chat with Bash
Why is ISO 27001 not sufficient for payment card data security?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access