- Home
- All questions
- Question 155
CISM study material · question 155 of 1000
Which two of the following are categories within the CSF 2.0 Govern function? Choose two.
Show the answer
Answer: B. Organizational Context
D. Cybersecurity Supply Chain Risk Management
Govern comprises Organizational Context, Risk Management Strategy, Roles Responsibilities and Authorities, Policy, Oversight, and Cybersecurity Supply Chain Risk Management. Adverse Event Analysis sits in Detect and Incident Recovery Plan Execution in Recover.
Source: NIST CSWP 29 (NIST) — Appendix A GOVERN (GV)