A transit agency must map controls for both federal grant auditors and card-payment compliance. Which approach best structures governance?
Select an answer to reveal the explanation.
Short Explanation
Auditors hate scavenger hunts. A recognized framework is the filing cabinet; grant and card rules become labeled folders inside it. One-off checklists that vanish after each visit leave the next auditor — and your own team — starting from scratch.
Full Explanation
Recognized security control frameworks provide a structured taxonomy for selecting, documenting, and assessing controls. Mapping federal grant and payment-card obligations into frameworks such as NIST or ISO/IEC 27001 (with PCI DSS requirements mapped where relevant) yields reusable evidence and consistent governance. Ad hoc, disposable checklists or single-standard tunnel vision fail when multiple compliance drivers apply simultaneously.