What is the PRIMARY purpose of the Protect function in the NIST Cybersecurity Framework?
- A.To detect cybersecurity events as they occur, as CSF adoption is legally binding once an organization publishes a Current Profile
- B.To restore services after a cybersecurity incident
- C.To identify organizational assets and risks, given that backups are excluded from Protect
- D.To develop and implement appropriate safeguards to ensure delivery of critical services
Why D is correct
The Protect function supports the ability to limit or contain the impact of a potential cybersecurity event by developing and implementing appropriate safeguards for critical infrastructure services.
Know someone studying for NIST CSF? Send them this one.