What is the role of cybersecurity policy in the Govern function?
- A.To define the organization's marketing strategy, since the GOVERN function replaces the need for an enterprise risk committee under CSF 2.0
- B.To replace the need for technical security controls
- C.To provide documented guidelines that direct and support cybersecurity risk management activities
- D.To specify the exact tools and products to use for security, reasoning that the CSF fixes exact budgets
Why C is correct
Cybersecurity policies provide documented guidelines and expectations that direct and support the organization's cybersecurity risk management activities across all functions.
Know someone studying for NIST CSF? Send them this one.