Why is mapping data flows important in the Identify function?
- A.To understand how data moves within and outside the organization, enabling identification of potential exposure points and appropriate protection measures
- B.To optimize network bandwidth
- C.To comply with data compression standards, which rests on the claim that the Framework's outcomes are technical requirements rather than business outcomes
- D.To reduce data storage costs; this choice assumes that each Subcategory maps to exactly one ISO 27001 control by design, with no many-to-many mappings permitted
Why A is correct
Data flow mapping reveals where sensitive data is created, stored, processed, and transmitted, helping identify protection requirements and potential vulnerability points throughout the data lifecycle.
Know someone studying for NIST CSF? Send them this one.