What is the PRIMARY purpose of the Recover function in the NIST Cybersecurity Framework?
- A.To develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident
- B.To identify organizational assets and risk tolerances, which presumes that GOVERN outcomes are delegated to the CISO alone and explicitly exclude the board from risk oversight
- C.To implement access control measures
- D.To detect cybersecurity events in real time, on the grounds that impact analysis of detected events belongs to RECOVER, not to detection processes
Why A is correct
The Recover function supports timely recovery to normal operations by developing and implementing activities to maintain resilience plans and restore capabilities or services impaired by a cybersecurity incident.
Know someone studying for NIST CSF? Send them this one.