Study. uk . com
  1. Home
  2. All questions
  3. Question 124

CISSP study material · question 124 of 500

A CSF 2.0 assessment finds that cybersecurity plays no part in hiring, induction or performance management, and that no executive is accountable for cyber risk. Which two Govern outcomes are unmet? Choose two.

  1. Cybersecurity is included in human resources practices.
  2. Incident recovery communication is planned and rehearsed.
  3. Leadership is accountable for cyber risk and fosters a risk-aware, ethical culture.
  4. Suppliers are known and prioritised by criticality.
Show the answer

Answer: C. Leadership is accountable for cyber risk and fosters a risk-aware, ethical culture.
A. Cybersecurity is included in human resources practices.

Both gaps sit under Roles, Responsibilities and Authorities: leadership accountability with a risk-aware ethical culture, and cybersecurity built into human resources practices.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.RR-01 and GV.RR-04

Challenge yourself on this topic → Study as cards