- Home
- All questions
- Question 5
CISM study material · question 5 of 1000
A manager is drafting the agenda for the quarterly cybersecurity risk discussion under CSF 2.0. Which item belongs on that agenda that a purely threat-focused agenda would omit?
Show the answer
Answer: A. Strategic opportunities, characterised as positive risks
CSF 2.0 treats positive risk as in scope and asks that strategic opportunities be characterised and included in the same cybersecurity risk discussions as negative risks.
Source: NIST CSWP 29 (NIST) — Appendix A GV.RM-07