C or D for me. FISMA (D) includes some maturity assessments in NIST reviews, so I picked D at first. But most practice guides point to CMMC (maybe that's meant by CHMC) as the one actually built for maturity modeling. Official study guide and Splunk blueprint both cover this area, but the question wording makes it tricky. Anyone else pick D?
Q: 5
Which of the following compliance frameworks was specifically created to measure the level of
cybersecurity maturity within an organization?
Options
Discussion
Pretty sure it's C for this one. Had something like this in a mock and CHMC (probably meant CMMC) is the only option that's built to assess cybersecurity maturity levels. PCI-DSS and GDPR don't use maturity levels. Agree?
C imo. Only CMMC (probably what CHMC refers to) is actually designed as a maturity model, the rest are just compliance frameworks. PCI-DSS and GDPR set standards or legal rules but don't have levels for measuring security maturity. FISMA can guide assessments but isn't itself a maturity framework. Pretty confident here, but let me know if I missed something.
B not C
C is right imo. Only CMMC (probably meant by CHMC) is designed to measure maturity, others like PCI-DSS and GDPR are compliance but not maturity models. Seen this on similar practice tests, but correct me if I'm missing something.
Be respectful. No spam.
Question 5 of 15