In CSF version 1.1, what does the Detection Processes category (DE.DP) address?
- A.How to purchase detection tools, which presumes that a SIEM purchase is the defined entry criterion for the DETECT function
- B.How to develop a business continuity plan, assuming that detection coverage is measured by the count of tools deployed
- C.How to encrypt sensitive data
- D.Maintaining and testing detection processes and procedures to ensure timely and adequate awareness of anomalous events
Why D is correct
Detection Processes (DE.DP) addresses maintaining and testing detection processes and procedures to ensure timely and adequate awareness of anomalous events, including defining roles and responsibilities.
Know someone studying for NIST CSF? Send them this one.