Study. uk . com
  1. Home
  2. All questions
  3. Question 6

CISM study material · question 6 of 1000

After a serious incident, the board asks who is ultimately accountable for cybersecurity risk. The security manager wants to answer consistently with CSF 2.0. Which answer is correct?

  1. Organisational leadership is responsible and accountable, and fosters a risk-aware culture
  2. Accountability transfers to the managed service provider under contract
  3. Accountability sits with each system owner for their own system
  4. The chief information security officer alone holds accountability
Show the answer

Answer: A. Organisational leadership is responsible and accountable, and fosters a risk-aware culture

CSF 2.0 places responsibility and accountability for cybersecurity risk on organisational leadership, and expects leadership to build a culture that is risk-aware, ethical and continually improving.

Source: NIST CSWP 29 (NIST) — Appendix A GV.RR-01

Challenge yourself on this topic → Study as cards