Study. uk . com
  1. Home
  2. All questions
  3. Question 143

CISSP study material · question 143 of 500

A small water utility asks whether adopting CISA's Cross-Sector Cybersecurity Performance Goals will make it fully secure. How should the goals be characterised?

  1. An audit standard against which organisations are formally certified.
  2. Mandatory for critical infrastructure operators and sufficient on their own.
  3. Voluntary and deliberately partial: a prioritised subset of practices offering a starting point, not full coverage.
  4. A complete control catalogue equivalent to SP 800-53 moderate baseline.
Show the answer

Answer: C. Voluntary and deliberately partial: a prioritised subset of practices offering a starting point, not full coverage.

The performance goals are voluntary and intentionally partial, offering a prioritised handful of practices as a starting point rather than comprehensive coverage.

Source: CISA Cross-Sector Cybersecurity Performance Goals (CISA) — Cross-Sector Cybersecurity Performance Goals > overview

Challenge yourself on this topic → Study as cards