NIST CSF Practice Question: How does the Govern function address legal and regulatory compliance? | CyberCertPrep
NISTNIST CSFGovern FunctionEASYFree question
How does the Govern function address legal and regulatory compliance?
A.Compliance is handled separately from governance
B.By hiring lawyers to handle all cybersecurity decisions
C.By avoiding activities that might trigger regulatory requirements
D.By ensuring the organization understands and incorporates applicable legal, regulatory, and contractual requirements into its cybersecurity program
Why D is correct
The Govern function ensures the organization identifies, understands, and incorporates all applicable legal, regulatory, and contractual cybersecurity requirements into its risk management program.
Know someone studying for NIST CSF? Send them this one.
Where this fits in the NIST CSF exam
Govern Function
NIST CSF 2.0 Govern function: organizational context, risk-management strategy, roles, policy, and oversight.
This question belongs to the "Govern" domain, which makes up about 10% of the NIST CSF exam.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
What does the Organizational Context category (GV.OC) in the Govern function address?