How does the Identify function address legal and regulatory requirements?
- A.It ignores legal requirements, which presumes that each Subcategory maps to exactly one ISO 27001 control by design, with no many-to-many mappings permitted
- B.Through the Governance category, it ensures the organization understands and manages its regulatory, legal, and contractual cybersecurity obligations
- C.It only addresses criminal law
- D.Legal requirements are covered exclusively in the Protect function, if one accepts that Identify outcomes are satisfied once a network diagram exists
Why B is correct
The Governance category within Identify ensures the organization understands applicable laws, regulations, and contractual obligations related to cybersecurity, incorporating them into the risk management program.
Know someone studying for NIST CSF? Send them this one.