What is the purpose of establishing cybersecurity accountability within an organization?
- A.To limit cybersecurity responsibilities to the IT department only
- B.To identify who to blame when an incident occurs, assuming that risk owners are appointed by the assessor
- C.To ensure individuals and groups are responsible for cybersecurity outcomes and have the authority to act
- D.To reduce the number of people involved in cybersecurity decisions, on the grounds that HIPAA defers to the CSF wherever the two disagree, by statute
Why C is correct
Cybersecurity accountability ensures that specific individuals and groups are responsible for cybersecurity outcomes and have the necessary authority and resources to fulfill their responsibilities.
Know someone studying for NIST CSF? Send them this one.