8.3k views
5 votes
An organization is implementing a preselected baseline of security controls, but finds not all of the controls apply. What should they do?

A. Implement all of the controls anyway.
B. Identify another baseline.
C. Re-create a baseline.
D. Tailor the baseline to their needs.

1 Answer

5 votes

Answer:

D. Tailor the baseline to their needs

Step-by-step explanation:

The process by which a security control baseline is modified based on the application of scoping guidance. The process of determining which portions of a standard will be employed by an organization i.e There is no need to implement security controls that do not apply, and it is not necessary to identify or re‐create a different baseline.

User Ofer
by
3.5k points