Isaca NIST-COBIT-2019 Practice Test - Questions Answers, Page 5
List of questions
Related questions
The activity of determining an appropriate target capability level for each process occurs within which implementation phase?
Phase 4 - What Needs to Be Done?
Phase 3 - Where Do We Want to Be?
Phase 2 - Where Are We Now?
Which of the following should an organization review to gain a better understanding of the likelihood and impact of cybersecurity events?
Relevant internal or external capability benchmarks
Cybersecurity frameworks, standards, and guidelines
Cyber threat information from internal and external sources
Which of the following is an important consideration when defining the roadmap in COBIT Implementation Phase 3 - Where Do We Want to Be?
Agreed metrics for measuring outcomes
Reporting procedures and requirements
Change-enablement implications
Which of the following is CRITICAL for the success of CSF Step 6: Determine, Analyze and Prioritize Gaps?
Identification of threats and vulnerabilities related to key assets
Experience in behavioral and change management
Clear understanding of the likelihood and impact of cybersecurity events
Which of the following is MOST likely to cause an organization's NIST Cybersecurity Framework (CSF) implementation to fail?
Organizational training on the CSF is not provided.
Potential benefits of proposed improvements are not considered.
The implementation timeline is too long.
Which function of the CSF is addressed by incorporating governance, risk, and compliance (GRC) elements into the implementation plan?
Protect
Detect
Identify
Which of the following is the MOST beneficial result of an effective CSF implementation plan?
Cybersecurity risk management practices are formalized and institutionalized.
Key stakeholders understand the quick wins of the cybersecurity program.
Key stakeholders understand the cybersecurity requirements of the chosen vendors.
When aligning to the NIST Cybersecurity Framework, what should occur after tier levels and framework core outcomes are determined?
Report discovered issues to senior management.
Assign mitigating control development.
Compare current and target profiles.
An organization is concerned that there will be resistance in attempts to close gaps between the current and target profiles. Which of the following is the
BEST approach to gain support for the process?
Implement organization-wide training on the CSF.
Communicate management opinions regarding the project.
Identify quick wins for implementation first.
Which of the following should be a PRIMARY consideration when creating an action plan to address gaps identified in CSF Step 6: Determine, Analyze, and Prioritize Gaps?
Mission drivers
Stakeholder map
IT process descriptions
Question