ExamGecko
Question list
Search
Search

Question 39 - NIST-COBIT-2019 discussion

Report
Export

Which of the following COBIT and NIST implementation steps may be reversed depending on the culture of the organization?

A.

Step 4: Conduct a Risk Assessment and Step 6: Determine, Analyze, and Prioritize Gaps

Answers
A.

Step 4: Conduct a Risk Assessment and Step 6: Determine, Analyze, and Prioritize Gaps

B.

Step 3: Create a Current Profile and Step 5: Create a Target Profile

Answers
B.

Step 3: Create a Current Profile and Step 5: Create a Target Profile

C.

Step 1: Prioritize and Scope and Step 2: Orient

Answers
C.

Step 1: Prioritize and Scope and Step 2: Orient

Suggested answer: C

Explanation:

According to the ISACA guide, the order of these two steps may be reversed depending on the culture of the organization and the level of stakeholder engagement1. Some organizations may prefer to start with a broad orientation of the NIST CSF and COBIT 2019 before scoping and prioritizing the implementation, while others may want to define the scope and priorities first and then orient the stakeholders accordingly.

Reference Implementing the NIST Cybersecurity Framework Using COBIT 2019, page 17.

asked 18/11/2024
Deshawn Sharpe
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first