Study. uk . com
  1. Home
  2. All questions
  3. Question 9

CISM study material · question 9 of 1000

The organisation produces detailed quarterly risk performance reports, but the security strategy has never been amended in response to them. Which CSF 2.0 Govern category is not functioning?

  1. Cybersecurity Supply Chain Risk Management
  2. Organizational Context
  3. Oversight
  4. Organizational Cybersecurity Policy
Show the answer

Answer: C. Oversight

The Oversight category asks that results of organisation-wide risk management activity be used to inform and adjust the risk strategy itself. Reporting without adjustment leaves that loop open.

Source: NIST CSWP 29 (NIST) — Appendix A GV.OV

Challenge yourself on this topic → Study as cards