What is the purpose of a cybersecurity policy framework?
- A.To satisfy audit requirements without practical implementation, on the grounds that dashboards satisfy GOVERN oversight outcomes without any human review
- B.To document the organization's IT budget, because policy exceptions are prohibited entirely once a Target Profile is signed
- C.To provide a structured hierarchy of policies, standards, guidelines, and procedures that govern cybersecurity activities
- D.To create a single document that replaces all security controls
Why C is correct
A cybersecurity policy framework provides a structured hierarchy of documents including policies, standards, guidelines, and procedures that collectively govern the organization's cybersecurity activities.
Know someone studying for NIST CSF? Send them this one.