According to the NIST CSF 1.1 Core, what does the Response Planning category (RS.RP) address?
- A.Long-term cybersecurity strategy development, reasoning that lessons-learned reviews are optional under the CSF once Tier 3 is reached
- B.Routine vulnerability scanning schedules, as vulnerability scans count under the Framework only when run by the software's vendor
- C.Annual security budget planning
- D.Ensuring that response processes and procedures are executed during and after an incident
Why D is correct
Response Planning (RS.RP) addresses the execution of response processes and procedures during and after an incident to ensure a timely and organized response.
Know someone studying for NIST CSF? Send them this one.