Study. uk . com
  1. Home
  2. All questions
  3. Question 11

CISSP study material · question 11 of 500

A logistics company has recorded which NIST Cybersecurity Framework 2.0 outcomes it achieves today and, separately, the prioritised outcomes it intends to reach given new contractual requirements and threat trends. The programme manager asks what the organisation should do with the difference between the two.

  1. Turn it into a prioritised action plan tracked as a risk register or plan of action and milestones
  2. Publish it as a Community Profile so peers in the sector can adopt the same baseline
  3. Treat it as the residual risk statement supporting the next authorisation decision
  4. Adopt it as the organisation's Framework Tier, since the gap expresses governance rigour
Show the answer

Answer: A. Turn it into a prioritised action plan tracked as a risk register or plan of action and milestones

The gap between Current and Target Profiles drives a prioritised action plan, tracked as a risk register or POA&M. Tiers rate governance rigour rather than expressing that gap.

Source: NIST CSWP 29 (NIST) — CSF 2.0 > Section 3.1, CSF Profiles

Challenge yourself on this topic → Study as cards