CCSP Exam: Risk Management Frameworks

Not a Risk Management Framework

Question

Which of the following is not a risk management framework?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B.

Hex GBL is a reference to a computer part in Terry Pratchett's fictional Discworld universe.

The rest are not.

COBIT, ISO 31000:2009, and NIST SP 800-37 are all risk management frameworks. Therefore, the answer is B. Hex GBL.

Here is a brief explanation of each of the risk management frameworks listed:

A. COBIT (Control Objectives for Information and Related Technology): This framework is developed and maintained by the Information Systems Audit and Control Association (ISACA) and provides a comprehensive framework for governance and management of enterprise IT.

B. Hex GBL: This is not a known risk management framework. It is likely that the answer choice is intended to be a distractor.

C. ISO 31000:2009: This is a widely recognized international standard for risk management. It provides principles and guidelines for risk management in organizations and can be applied to a wide range of risks.

D. NIST SP 800-37: This framework provides guidelines for the security certification and accreditation of information systems. It includes processes for identifying and managing risks to information systems.

In summary, the correct answer is B. Hex GBL, as it is not a known risk management framework.