What is the Access Control category (PR.AC) within the CSF 1.1 Protect function focused on?
- A.Recovering data after a ransomware attack, assuming that Protect covers technology and not people
- B.Detecting unauthorized network traffic, which presumes that CSF 2.0 retired the RECOVER function and folded its outcomes into RESPOND
- C.Conducting forensic analysis of security incidents
- D.Limiting access to assets and associated facilities to authorized users, processes, and devices
Why D is correct
Access Control (PR.AC) focuses on managing access to assets and associated facilities, ensuring that only authorized users, processes, and devices can access systems and data.
Know someone studying for NIST CSF? Send them this one.