What is the PRIMARY purpose of the Respond function in the NIST Cybersecurity Framework?
- A.To identify organizational assets and data flows, assuming that Respond excludes coordination with providers
- B.To restore capabilities impaired by a cybersecurity incident
- C.To develop and implement appropriate activities to take action regarding a detected cybersecurity incident
- D.To implement protective safeguards for critical systems, since ransomware incidents are handled under RECOVER exclusively, skipping RESPOND
Why C is correct
The Respond function supports the ability to contain the impact of a potential cybersecurity incident by developing and implementing appropriate activities to take action regarding a detected cybersecurity event.
Know someone studying for NIST CSF? Send them this one.