2026 Licensing & Certification Curricula (Securities, Cloud, IT, Real Estate, Bar & CPA) are now live
Chapter 5 • Domain 55.1

5.1 Enterprise Cybersecurity Governance, NIST CSF 2.0, and ISO 27001

Navigate industry governance frameworks including NIST CSF 2.0, ISO/IEC 27001, and regulatory compliance standards like GDPR, HIPAA, and PCI-DSS.

🎯 Key CompTIA Security+ Exam Takeaways

  • NIST CSF 2.0 structures cybersecurity programs across six Core Functions: Govern, Identify, Protect, Detect, Respond, Recover.
  • ISO/IEC 27001 provides the global benchmark standard for establishing, certifying, and auditing an Information Security Management System (ISMS).
  • GDPR protects European citizen data privacy, mandating 72-hour breach notification and granting users rights including data portability and erasure.
  • PCI-DSS v4.0 enforces technical and operational safeguards on systems that store, process, or transmit payment cardholder data.
  • HIPAA Security Rule mandates administrative, physical, and technical safeguards for electronic protected health information (ePHI).

Cybersecurity governance establishes the executive policies, strategic direction, organizational roles, and accountability required to manage digital risk effectively. Leading organizations align their programs with established industry frameworks rather than building ad-hoc security measures.

The National Institute of Standards and Technology (NIST) published Cybersecurity Framework (CSF) 2.0, organizing cybersecurity into six foundational Core Functions: Govern (establishing organizational context, strategy, and risk management policies), Identify (cataloging assets and risks), Protect (deploying defensive safeguards), Detect (monitoring anomalies and indicators of compromise), Respond (taking action against detected incidents), and Recover (restoring services). Internationally, ISO/IEC 27001 provides the formal standard for certifying an Information Security Management System (ISMS), supported by Annex A security controls.

Organizations must also navigate complex regulatory compliance mandates. The European Union's General Data Protection Regulation (GDPR) enforces stringent personal data privacy protections, requiring organizations to report personal data breaches to regulatory authorities within 72 hours and granting individuals the 'right to be forgotten' (erasure). In healthcare, HIPAA mandates administrative, physical, and technical safeguards for protected health information (PHI). In e-commerce and retail, the Payment Card Industry Data Security Standard (PCI-DSS) enforces strict encryption, access control, and network segmentation rules to safeguard credit card numbers.

⚠️ Common Pearson VUE Exam Traps

  • Assuming compliance equals security; satisfying minimum regulatory checklist requirements does not automatically protect an enterprise from advanced persistent threats.
  • Overlooking GDPR's strict 72-hour notification deadline; failing to alert supervisory authorities within 72 hours of discovering a breach triggers massive fines.

Knowledge Checkpoint

Knowledge Checkpoint • Section 5.1

NIST released Cybersecurity Framework (CSF) 2.0, introducing a major structural evolution to the original five functions (Identify, Protect, Detect, Respond, Recover). Which new, overarching function was added to establish organizational cybersecurity strategy, policy oversight, and enterprise risk governance?