Study. uk . com
  1. Home
  2. All questions
  3. Question 707

CISM study material · question 707 of 1000

Does NIST mandate its own incident response life cycle model, and which organisations does it say benefit most from one stressing continuous improvement?

  1. Yes — the model is mandatory for all of those organisations that are above a defined size threshold, which is itself measured by headcount and by the number of the systems that they operate
  2. No — but the older four-phase model still remains the preferred one, and any organisation that departs from it now has to record the reasons why it has chosen to do so
  3. No — organisations should use whichever model suits them, and larger, more technology-dependent bodies benefit most from a continuous improvement emphasis
  4. Yes — the CSF-based model is mandatory for every organisation, whatever its own size may be and whatever the degree to which it depends on the technology it operates
Show the answer

Answer: C. No — organisations should use whichever model suits them, and larger, more technology-dependent bodies benefit most from a continuous improvement emphasis

SP 800-61r3 states organisations should use the framework or model that suits them best, and that larger and more technology-dependent organisations are likely to benefit more from a model emphasising continuous improvement.

Source: NIST SP 800-61 Rev. 3 (NIST) — Sec. 2.1 Incident Response Life Cycle Model

Challenge yourself on this topic → Study as cards