The city's cyber-insurance questionnaire asks which standard the SOC follows. How should the analyst treat Splunk in that answer?
Select an answer to reveal the explanation.
Short Explanation
Splunk is the evidence room, not the certificate on the wall. Tell the insurer the city follows ISO or NIST and that ES investigations and reports support that ISMS. Do not write "Splunk" in the standard blank.
Full Explanation
ISO 27001 and NIST-based programs are the standards an insurer is asking about. Enterprise Security operationalizes monitoring, investigation, and reporting that support an aligned ISMS; it is not itself a certifying standard or Annex A. CIM is a data-normalization schema, not ISO. Leaving the field blank understates the platform's role; Splunk supports the ISMS, it is not the standard.