ExamGecko
Question list
Search
Search

Question 2 - NIST-COBIT-2019 discussion

Report
Export

How should gaps identified between the current and target profiles be addressed?

A.

Comparing to and acting on the desired Tier level

Answers
A.

Comparing to and acting on the desired Tier level

B.

With a full project engagement to close all gaps

Answers
B.

With a full project engagement to close all gaps

C.

Through a risk based-approach

Answers
C.

Through a risk based-approach

Suggested answer: C

Explanation:

According to the NIST Cybersecurity Framework, gaps identified between the current and target profiles should be addressed through a risk-based approach, which enables an organization to gauge the resources needed and prioritize the mitigation of gaps in a cost-effective manner. This approach also aligns the cybersecurity program with the business objectives and risk appetite of the organization12.

Reference Examples of Framework Profiles | NIST What is the NIST Cybersecurity Framework? | IBM

asked 18/11/2024
THARINDU AMARASINGHE
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first