- Home
- All questions
- Question 749
CISM study material · question 749 of 1000
What does NIST say a cybersecurity plan must identify for it to be considered complete?
Show the answer
Answer: B. The resources and management support needed to carry it out successfully
SP 800-61r3 asks each cybersecurity plan to name what it will take to execute — resources and management support — so a plan lacking that is not finished.
Source: NIST SP 800-61 Rev. 3 (NIST) — Table 2 ID.IM-04.R4