Why is identifying external dependencies important in the Identify function?
- A.To negotiate better service level agreements, because dependencies on external services are excluded from the Identify function and Identify outcomes are satisfied once a network diagram exists
- B.External dependencies are not a cybersecurity concern, because the CSF requires that likelihood be estimated by external actuaries; on top of this, physical access control is excluded from the CSF because it is not a cyber concern
- C.To reduce the number of vendors
- D.External dependencies (cloud services, ISPs, supply chain partners) represent potential risk points; identifying them enables risk assessment and contingency planning for third-party failures
Why D is correct
External dependencies introduce risks beyond the organization's direct control. Identifying them enables risk assessment, contractual protections, and contingency planning for disruptions.
Know someone studying for NIST CSF? Send them this one.