Study. uk . com
  1. Home
  2. All questions
  3. Question 749

CISM study material · question 749 of 1000

What does NIST say a cybersecurity plan must identify for it to be considered complete?

  1. The budget code funding each activity
  2. The resources and management support needed to carry it out successfully
  3. The date of the next scheduled exercise
  4. The named individual accountable for each step
Show the answer

Answer: B. The resources and management support needed to carry it out successfully

SP 800-61r3 asks each cybersecurity plan to name what it will take to execute — resources and management support — so a plan lacking that is not finished.

Source: NIST SP 800-61 Rev. 3 (NIST) — Table 2 ID.IM-04.R4

Challenge yourself on this topic → Study as cards