- Home
- All questions
- Question 124
CISSP study material · question 124 of 500
A CSF 2.0 assessment finds that cybersecurity plays no part in hiring, induction or performance management, and that no executive is accountable for cyber risk. Which two Govern outcomes are unmet? Choose two.
Show the answer
Answer: C. Leadership is accountable for cyber risk and fosters a risk-aware, ethical culture.
A. Cybersecurity is included in human resources practices.
Both gaps sit under Roles, Responsibilities and Authorities: leadership accountability with a risk-aware ethical culture, and cybersecurity built into human resources practices.
Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.RR-01 and GV.RR-04