- Home
- All questions
- Question 9
CISM study material · question 9 of 1000
The organisation produces detailed quarterly risk performance reports, but the security strategy has never been amended in response to them. Which CSF 2.0 Govern category is not functioning?
Show the answer
Answer: C. Oversight
The Oversight category asks that results of organisation-wide risk management activity be used to inform and adjust the risk strategy itself. Reporting without adjustment leaves that loop open.
Source: NIST CSWP 29 (NIST) — Appendix A GV.OV