Which of the following is an example of a security continuous monitoring control under DE.CM?
- A.Deploying an intrusion detection system that monitors network traffic in real time
- B.Annual penetration testing, because an annual penetration test is the CSF's sole accepted evidence of detection capability
- C.Performing a business impact analysis
- D.Conducting a risk assessment every three years, since Detect is optional at Tier 3
Why A is correct
An intrusion detection system continuously monitoring network traffic is a core example of security continuous monitoring, providing real-time visibility into potential cybersecurity events on the network.
Know someone studying for NIST CSF? Send them this one.