Isaca NIST-COBIT-2019 Practice Test 1

Which of the following is MOST important for successful execution of CSF implementation Step 6 - Determine, Analyze, and Prioritize Gaps?
Have management review and approve the gap analysis.
Engage external experts to perform a cost-benefit analysis.
Engage business and IT process owners for internal expertise.
According to the ISACA guide, engaging business and IT process owners for internal expertise is most important for successful execution of CSF implementation Step 6, as they can provide valuable insights into the current and desired states of the processes, the gaps and potential solutions, and the costs and benefits of the implementation1. They can also help to align the cybersecurity program with the business objectives and risk appetite of the organization.
Reference Implementing the NIST Cybersecurity Framework Using COBIT 2019, page 17.