Study. uk . com
  1. Home
  2. All questions
  3. Question 156

CISM study material · question 156 of 1000

An organisation files its legal, regulatory and contractual cybersecurity obligations under its compliance programme and nowhere else. Where does CSF 2.0 locate that outcome?

  1. Under Organizational Context within the Govern function
  2. Under Improvement within the Identify function
  3. Under Platform Security within the Protect function, alongside configuration hardening
  4. Under Incident Response Reporting within the Respond function, where notification duties are met
Show the answer

Answer: A. Under Organizational Context within the Govern function

CSF 2.0 places understanding and managing legal, regulatory and contractual cybersecurity requirements, including privacy and civil liberties obligations, under Organizational Context in Govern.

Source: NIST CSWP 29 (NIST) — Appendix A GV.OC

Challenge yourself on this topic → Study as cards