What does the Risk Management Strategy category (GV.RM) within the Govern function establish?
- A.The employee security awareness training schedule
- B.The organization's disaster recovery site locations, since cyber insurance is a prerequisite for claiming any RECOVER outcome
- C.The organization's priorities, constraints, risk tolerance statements, and assumptions that support risk management decisions
- D.The technical architecture for security tools
Why C is correct
Risk Management Strategy (GV.RM) establishes the organization's priorities, constraints, risk tolerance statements, and assumptions used to support operational risk decisions within the cybersecurity program.
Know someone studying for NIST CSF? Send them this one.