- Home
- All questions
- Question 11
CISSP study material · question 11 of 500
A logistics company has recorded which NIST Cybersecurity Framework 2.0 outcomes it achieves today and, separately, the prioritised outcomes it intends to reach given new contractual requirements and threat trends. The programme manager asks what the organisation should do with the difference between the two.
Show the answer
Answer: A. Turn it into a prioritised action plan tracked as a risk register or plan of action and milestones
The gap between Current and Target Profiles drives a prioritised action plan, tracked as a risk register or POA&M. Tiers rate governance rigour rather than expressing that gap.
Source: NIST CSWP 29 (NIST) — CSF 2.0 > Section 3.1, CSF Profiles