Information Technology Specialist (ITS) Cybersecurity Practice Exam

Disable ads (and more) with a membership for a one time $2.99 payment

Study for the ITS Cybersecurity Exam. Test yourself with flashcards and multiple choice questions, each featuring hints and explanations. Get ready for your exam!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which security framework focuses on continuous compliance and monitoring?

  1. NIST Cybersecurity Framework

  2. CIS Controls

  3. ISO 27001

  4. COBIT

The correct answer is: NIST Cybersecurity Framework

The NIST Cybersecurity Framework is designed to help organizations manage and reduce cybersecurity risk by providing a set of standards, guidelines, and best practices. One of its core components is its focus on continuous compliance and monitoring, which emphasizes ongoing evaluation of cybersecurity policies and practices to adapt to changing threats and vulnerabilities. This framework encourages organizations to continuously assess their security posture by monitoring cybersecurity risks, ensuring that they are compliant with established standards and practices. The iterative nature means that organizations regularly revisit their security strategies and controls, enabling them to maintain an effective and resilient cybersecurity program. While the other frameworks like CIS Controls, ISO 27001, and COBIT provide various levels of guidance on security practices, they do not emphasize continuous compliance and monitoring as strongly as the NIST Cybersecurity Framework does. For example, while ISO 27001 is focused on establishing an Information Security Management System (ISMS) requiring periodic review and assessment, it does not intrinsically prioritize real-time monitoring or continuous compliance in the same structured way as NIST. Thus, the NIST Cybersecurity Framework stands out for its emphasis on an ongoing, adaptable approach to cybersecurity compliance and monitoring.