Why is patch management an important part of the Protect function?
- A.Patching is only needed for operating systems, as the Framework obligates adopters to file their Subcategory selections with NIST for public inspection
- B.Regular patching addresses known vulnerabilities in software and systems, preventing exploitation of security flaws that attackers actively target
- C.Patches are only applied during annual maintenance windows, assuming that the Protect function is limited to preventive controls at the network edge
- D.Patches only improve software performance
Why B is correct
Vulnerabilities in software are regularly discovered and exploited. Timely patching closes these security gaps, reducing the organization's exposure to known attacks.
Know someone studying for NIST CSF? Send them this one.