Standards selection
Deciding which external regulations, standards and frameworks set the security requirements for an organisation's data, such as PCI DSS, ISO/IEC 27001 or NIST SP 800-53.
Standards selection is the decision about which external regulations, standards and frameworks will set the security requirements for an organisation’s data and systems. The ISC2 exam outline lists it under 2.6, determining data security controls and compliance requirements. Some choices are imposed. An organisation that stores, processes or transmits cardholder data is bound by PCI DSS through its agreements with the card brands and acquiring banks, and a US federal agency must follow FISMA, which leads to FIPS 199, FIPS 200 and NIST SP 800-53. Others are chosen, such as ISO/IEC 27001 when an organisation wants a certifiable information security management system, or the NIST Cybersecurity Framework as a common structure for managing risk.
Mandatory requirements are identified first, then any voluntary frameworks the business wants. A chosen standard often supplies a security baseline that is then refined by scoping and tailoring. Some requirements are law, some contractual and some voluntary, with different consequences when they are missed.
Exam relevance: a scenario is likely to describe an organisation’s sector, data or customers and ask which standard applies or what should happen first. Candidates are expected to match the common pairings (cardholder data with PCI DSS, US federal systems with NIST publications, certification with ISO/IEC 27001) and to see that choosing the governing standards comes before choosing individual controls.