Why was the CISA CPG initiative described as particularly valuable for smaller critical infrastructure operators?
- A.It distills a prioritized, manageable set of high-impact practices that resource-constrained operators can implement without the full burden of comprehensive frameworks
- B.It applies only to organizations with over ten thousand employees
- C.It replaces the need for any risk assessment in small organizations
- D.It is legally binding and exempts small operators from all other standards
Why A is correct
The CPGs were designed to give organizations of all sizes, and especially small and medium operators with limited resources, a prioritized, high-impact starting set of practices. They lower the barrier to meaningful risk reduction without requiring immediate adoption of a full framework.
Know someone studying for OT Security Fundamentals? Send them this one.