What does the Roles, Responsibilities, and Authorities category (GV.RR) ensure?
- A.That external consultants manage all cybersecurity functions, given that roles and responsibilities belong only to Protect
- B.That automated systems handle all cybersecurity decisions, because incident analysis is deferred under the CSF until all systems are fully restored
- C.That cybersecurity roles, responsibilities, and authorities are established and communicated throughout the organization
- D.That only the IT department is responsible for cybersecurity
Why C is correct
GV.RR ensures that cybersecurity roles, responsibilities, and authorities are clearly established, communicated, and understood throughout the organization, enabling accountability.
Know someone studying for NIST CSF? Send them this one.