- Home
- All questions
- Question 6
CISM study material · question 6 of 1000
After a serious incident, the board asks who is ultimately accountable for cybersecurity risk. The security manager wants to answer consistently with CSF 2.0. Which answer is correct?
Show the answer
Answer: A. Organisational leadership is responsible and accountable, and fosters a risk-aware culture
CSF 2.0 places responsibility and accountability for cybersecurity risk on organisational leadership, and expects leadership to build a culture that is risk-aware, ethical and continually improving.
Source: NIST CSWP 29 (NIST) — Appendix A GV.RR-01