A multinational financial services company needs to implement a security control framework that focuses on business objectives and IT governance while providing a comprehensive set of controls for enterprise security. Which of the following frameworks would BEST meet these requirements?
COBIT (Control Objectives for Information and Related Technology) is the correct answer because it specifically focuses on aligning IT with business objectives and provides comprehensive governance and management of enterprise IT. COBIT is designed to bridge the gap between business requirements, control requirements, and technical issues, making it particularly suitable for financial organizations that need strong IT governance.
NIST SP 800-53 is more focused on security controls for federal information systems, though it can be adapted for private sector use. While comprehensive for security controls, it doesn't have the same emphasis on business-IT alignment that COBIT provides.
PCI DSS is specifically designed for payment card security and would be too narrow in scope for overall enterprise security governance.
FedRAMP is a U.S. government program focusing on security assessment and authorization for cloud services, which would not address the broad enterprise IT governance needs of the financial services company.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is COBIT and how does it benefit organizations?
Open an interactive chat with Bash
How does COBIT differ from NIST SP 800-53?
Open an interactive chat with Bash
Why are PCI DSS and FedRAMP not suitable for the financial services company's needs?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Oh snap!
Loading...
Loading...
Loading...
Information Technology Package Join Premium for Full Access