An organization wants a flexible, outcome-based structure to organize its OT cybersecurity program around five high-level functions. Which framework provides Identify, Protect, Detect, Respond, and Recover as its core functions (with a sixth, Govern, added in version 2.0)?
- A.The NIST Cybersecurity Framework (CSF)
- B.IEC 61511
- C.API 1164
- D.NERC CIP
Why A is correct
The NIST Cybersecurity Framework organizes activities under core functions; CSF 1.1 used Identify, Protect, Detect, Respond, and Recover, and CSF 2.0 added Govern. Its outcome-based, voluntary structure is widely applied to OT to organize risk management without prescribing specific technologies.
Know someone studying for OT Security Fundamentals? Send them this one.