Study. uk . com
  1. Home
  2. All questions
  3. Question 5

CISSP study material · question 5 of 500

A bank is adopting the NIST Cybersecurity Framework 2.0 and the board asks which decisions belong to the Govern function that sits at the centre of the Core. Choose three.

  1. Establishing roles, authorities and policy so cyber risk feeds enterprise risk management
  2. Maintaining an inventory of the hardware, software and services the organisation uses
  3. Setting the organisation's cybersecurity risk strategy and stating its risk appetite
  4. Managing the cybersecurity risk arising from the organisation's supply chain
Show the answer

Answer: C. Setting the organisation's cybersecurity risk strategy and stating its risk appetite
A. Establishing roles, authorities and policy so cyber risk feeds enterprise risk management
D. Managing the cybersecurity risk arising from the organisation's supply chain

Govern covers organisational context, risk strategy and appetite, supply chain risk, roles, policy and oversight, folding cyber risk into enterprise risk management. Asset inventory belongs to Identify.

Source: NIST CSWP 29 (NIST) — CSF 2.0 > Section 2, Introduction to the CSF Core

Challenge yourself on this topic → Study as cards