ExamGecko
Question list
Search
Search

Question 45 - NIST-COBIT-2019 discussion

Report
Export

Which of the following is MOST likely to cause an organization's NIST Cybersecurity Framework (CSF) implementation to fail?

A.

Organizational training on the CSF is not provided.

Answers
A.

Organizational training on the CSF is not provided.

B.

Potential benefits of proposed improvements are not considered.

Answers
B.

Potential benefits of proposed improvements are not considered.

C.

The implementation timeline is too long.

Answers
C.

The implementation timeline is too long.

Suggested answer: B

Explanation:

One of the most likely causes of an organization's NIST CSF implementation failure is that the potential benefits of proposed improvements are not considered, which means that the organization does not conduct a cost-benefit analysis of the solutions to address the gaps between the current and target profiles. This can result in a lack of justification, prioritization, and alignment of the implementation plan with the organization's mission drivers, risk appetite, and resource constraints12.

Reference 7 Steps to Implement & Improve Cybersecurity with NIST 3 Security Issues Overlooked By the NIST Framework

asked 18/11/2024
Fiston LOMATE
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first