Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Netskope NSK101 Exam - Topic 3 Question 53 Discussion

Which two common security frameworks are used today to assess and validate a vendor's security practices? (Choose two.)
B) Building Security in Maturity Model and C) ISO 27001
A) Data Science Council of America
D) NIST Cybersecurity Framework

Netskope NSK101 Exam - Topic 3 Question 53 Discussion

Actual exam question for Netskope's NSK101 exam
Question #: 53
Topic #: 3
[All NSK101 Questions]

Which two common security frameworks are used today to assess and validate a vendor's security practices? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, C

The Building Security in Maturity Model (BSIMM) is a framework that measures and compares the security activities of different organizations. It helps organizations to assess their current security practices and identify areas for improvement. ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and improving an information security management system. It helps organizations to manage their information security risks and demonstrate their compliance with best practices. Data Science Council of America (DASCA) is not a security framework, but a credentialing body for data science professionals. NIST Cybersecurity Framework (NIST CSF) is a security framework, but it is not commonly used to assess and validate a vendor's security practices, as it is more focused on improving the cybersecurity of critical infrastructure sectors in the United States.Reference:[BSIMM], [ISO 27001], [DASCA], [NIST CSF].


Contribute your Thoughts:

0/2000 characters
Tamala
5 hours ago
I definitely remember discussing ISO 27001 and NIST, but I’m worried I might mix them up with other frameworks we studied.
upvoted 0 times
...
Rossana
5 days ago
I’m a bit confused; I thought the Building Security in Maturity Model was relevant, but I’m not sure if it’s as common as the other two.
upvoted 0 times
...
Launa
11 days ago
I feel like the NIST Cybersecurity Framework was covered in a practice question, but I can't recall if it was paired with ISO 27001 or something else.
upvoted 0 times
...
Ashanti
16 days ago
I think I remember ISO 27001 being mentioned a lot in our study materials, but I'm not entirely sure about the second one.
upvoted 0 times
...

Save Cancel