Study. uk . com
  1. Home
  2. All questions
  3. Question 842

CISM study material · question 842 of 1000

Which source of improvement does CSF 2.0 name that involves parties outside the organisation?

  1. Security tests and exercises conducted in coordination with suppliers and relevant third parties
  2. Benchmarking against published sector reports
  3. Threat intelligence purchased from commercial providers
  4. Independent audits commissioned by the board
Show the answer

Answer: A. Security tests and exercises conducted in coordination with suppliers and relevant third parties

CSF 2.0's ID.IM-02 draws improvements from security tests and exercises, expressly including those run jointly with suppliers and other relevant third parties.

Source: NIST CSWP 29 (NIST) — Appendix A ID.IM-02

Challenge yourself on this topic → Study as cards