21. A U.S.-based company wants to improve its information security practices and needs guidelines for identifying critical infrastructure and its potential cybersecurity risks. Which standard provides these guidelines?

Answer: C

Explanation:

NIST Framework provides guidelines for identifying critical infrastructure and its potential cybersecurity risks.

The NIST Framework is specifically designed to help organizations manage and reduce cybersecurity risk by providing a policy framework of computer security guidance. It includes guidelines for identifying critical infrastructure and assessing potential risks associated with it.

A) ITIL Framework

The ITIL (Information Technology Infrastructure Library) Framework focuses on IT service management and best practices for aligning IT services with business needs. While it may touch on aspects of security, it does not provide comprehensive guidelines specifically for identifying critical infrastructure or addressing cybersecurity risks.

B) Six Sigma

Six Sigma is a set of techniques and tools for process improvement, primarily used to enhance business processes and quality control. It does not address cybersecurity or the identification of critical infrastructure, making it irrelevant to the question at hand.

C) NIST Framework

The NIST Framework is a comprehensive set of guidelines that specifically addresses cybersecurity risk management and includes detailed methods for identifying critical infrastructure. It is widely recognized and utilized by organizations for establishing robust information security practices, making it the correct choice.

D) IEEE 802

The IEEE 802 standards are primarily concerned with networking technologies and protocols, particularly local area networks (LANs). While they may include some security aspects related to networking, they do not provide the guidelines needed for identifying critical infrastructure or assessing cybersecurity risks.

Conclusion

The NIST Framework is the definitive choice for organizations looking to enhance their cybersecurity practices, as it offers specific guidelines for identifying critical infrastructure and managing associated risks. In contrast, the other options either focus on unrelated areas or lack comprehensive cybersecurity guidance, thus failing to meet the needs outlined in the question.