Study. uk . com
  1. Home
  2. All questions
  3. Question 155

CISM study material · question 155 of 1000

Which two of the following are categories within the CSF 2.0 Govern function? Choose two.

  1. Incident Recovery Plan Execution and Recovery Communication
  2. Organizational Context
  3. Adverse Event Analysis and Detection
  4. Cybersecurity Supply Chain Risk Management
Show the answer

Answer: B. Organizational Context
D. Cybersecurity Supply Chain Risk Management

Govern comprises Organizational Context, Risk Management Strategy, Roles Responsibilities and Authorities, Policy, Oversight, and Cybersecurity Supply Chain Risk Management. Adverse Event Analysis sits in Detect and Incident Recovery Plan Execution in Recover.

Source: NIST CSWP 29 (NIST) — Appendix A GOVERN (GV)

Challenge yourself on this topic → Study as cards