Study. uk . com
  1. Home
  2. All questions
  3. Question 248

CISM study material · question 248 of 1000

A researcher reports a flaw in the organisation's public application and receives no acknowledgement for weeks because no route exists to handle such reports. Which CSF 2.0 outcome is missing?

  1. Incidents are declared when events meet defined criteria
  2. Vulnerabilities in assets are identified, validated and recorded in the organisation's own tracking system
  3. Processes for receiving, analysing and responding to vulnerability disclosures are established
  4. Cyber threat intelligence is received from information sharing forums and used to enrich the organisation's analysis
Show the answer

Answer: C. Processes for receiving, analysing and responding to vulnerability disclosures are established

CSF 2.0 subcategory ID.RA-08 asks for established processes to receive, analyse and respond to vulnerability disclosures, which is what an inbound report from an outside party requires.

Source: NIST CSWP 29 (NIST) — Appendix A ID.RA-08

Challenge yourself on this topic → Study as cards