Which of the following recommendations should an organization take into account when applying the proposed implementation approach for a cybersecurity program?

Which of the following recommendations should an organization take into account when applying the proposed implementation approach for a cybersecurity program?
A . Integrating new technologies
B . Segregating the cybersecurity program from existing processes
C . Applying the principles of continual Improvement

Answer: C

Explanation:

When implementing a cybersecurity program, it is essential to apply the principles of continual improvement. This approach ensures that the program evolves in response to new threats, vulnerabilities, and business requirements, thereby maintaining its effectiveness over time. Continual improvement is a key principle in many standards, including ISO/IEC 27001, which promotes the Plan-Do-Check-Act (PDCA) cycle for ongoing enhancement of the ISMS.

Integrating new technologies is important but should be done within the framework of continual improvement to ensure that they are effectively incorporated and managed. Segregating the cybersecurity program from existing processes is not recommended as cybersecurity should be integrated into all business processes to ensure comprehensive protection.

Reference: ISO/IEC 27001:2013 – Promotes continual improvement as a fundamental principle for maintaining and enhancing the ISMS.

NIST SP 800-53 – Emphasizes the importance of continuous monitoring and improvement of security controls to adapt to the evolving threat landscape.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments