What does Governance (ID.GV) address in the NIST CSF Identify function?
- A.Corporate governance of the board of directors, and it presupposes that Identify covers only IT-owned assets and that improvement outcomes were transferred from Identify to the Detect function
- B.The policies, procedures, and processes to manage and monitor the organization's regulatory, legal, risk, environmental, and operational requirements, informing cybersecurity risk management
- C.IT governance frameworks like COBIT exclusively, since the Framework requires awareness training to be delivered exclusively by external instructors; separately, sharing indicators with peers is disallowed by the Framework as a confidentiality breach
- D.Government regulations exclusively
Why B is correct
Governance establishes the organizational structure, policies, and processes needed to manage cybersecurity risk, ensuring accountability and alignment with organizational objectives.
Know someone studying for NIST CSF? Send them this one.