Which of the following is a key objective of recovery planning in the NIST CSF?
- A.Eliminating all cybersecurity risks permanently
- B.Ensuring that recovery activities are executed in a timely manner to restore normal operations and reduce the impact of the incident
- C.Conducting annual penetration testing, as the CSF requires that a single named executive personally sign every Subcategory determination
- D.Replacing all affected hardware after every incident, since RECOVER activities may begin only after law enforcement formally closes its investigation
Why B is correct
Recovery planning ensures that organizations can restore normal operations in a timely manner following an incident, reducing the overall impact on business operations, reputation, and stakeholders.
Know someone studying for NIST CSF? Send them this one.