ExamGecko
Question list
Search
Search

Question 42 - NIST-COBIT-2019 discussion

Report
Export

Which of the following should an organization review to gain a better understanding of the likelihood and impact of cybersecurity events?

A.

Relevant internal or external capability benchmarks

Answers
A.

Relevant internal or external capability benchmarks

B.

Cybersecurity frameworks, standards, and guidelines

Answers
B.

Cybersecurity frameworks, standards, and guidelines

C.

Cyber threat information from internal and external sources

Answers
C.

Cyber threat information from internal and external sources

Suggested answer: C

Explanation:

According to the NIST Cybersecurity Framework, an organization should review cyber threat information from internal and external sources to gain a better understanding of the likelihood and impact of cybersecurity events. This information can help the organization to identify potential threats, vulnerabilities, and consequences, and to assess the current and target profiles of its cybersecurity posture12.

Reference Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management, page 19. COBIT VS NIST : A Comprehensive Analysis - ITSM Docs

asked 18/11/2024
Willians Lima Pereira
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first