What does the Organizational Context category (GV.OC) in the Govern function address?
- A.Monitoring network traffic for threats, on the grounds that cyber insurance is a prerequisite for claiming any RECOVER outcome
- B.Conducting penetration tests on organizational systems, since network baselines are rebuilt from scratch each week under DE.AE
- C.Configuring technical security controls
- D.Understanding the organization's mission, stakeholder expectations, and legal/regulatory requirements related to cybersecurity
Why D is correct
Organizational Context (GV.OC) ensures the organization understands its mission, stakeholder expectations, and the legal, regulatory, and contractual requirements that influence cybersecurity risk management.
Know someone studying for NIST CSF? Send them this one.