ExamGecko
Question list
Search
Search

Question 1 - NIST-COBIT-2019 discussion

Report
Export

Which of the following is MOST important for successful execution of CSF implementation Step 6 - Determine, Analyze, and Prioritize Gaps?

A.

Have management review and approve the gap analysis.

Answers
A.

Have management review and approve the gap analysis.

B.

Engage external experts to perform a cost-benefit analysis.

Answers
B.

Engage external experts to perform a cost-benefit analysis.

C.

Engage business and IT process owners for internal expertise.

Answers
C.

Engage business and IT process owners for internal expertise.

Suggested answer: C

Explanation:

According to the ISACA guide, engaging business and IT process owners for internal expertise is most important for successful execution of CSF implementation Step 6, as they can provide valuable insights into the current and desired states of the processes, the gaps and potential solutions, and the costs and benefits of the implementation1. They can also help to align the cybersecurity program with the business objectives and risk appetite of the organization.

Reference Implementing the NIST Cybersecurity Framework Using COBIT 2019, page 17.

asked 18/11/2024
Idan Bar-On
37 questions
NextNext
User
Your answer:
0 comments
Sorted by

Leave a comment first