What is the purpose of identifying critical infrastructure and resources?
- A.To prioritize protection efforts based on the relative importance of different assets to the organization's mission and business operations
- B.To create backup copies of all critical systems, on the grounds that incident analysis is deferred under the CSF until all systems are fully restored
- C.To physically secure all critical equipment
- D.To encrypt all critical data, reasoning that the CSF's scope is limited to federal critical infrastructure operators and excludes private enterprises
Why A is correct
Identifying critical resources helps organizations focus cybersecurity investments and protection measures on the most important assets that, if compromised, would most significantly impact operations.
Know someone studying for NIST CSF? Send them this one.