An organization wants a flexible, outcome-based structure to organize its OT cybersecurity program around five high-level functions.
Which framework provides Identify, Protect, Detect, Respond, and Recover as its core functions (with a sixth, Govern, added in version 2.0)?
- A.IEC 61511
- B.NERC CIP
- C.The NIST Cybersecurity Framework (CSF)
- D.API 1164
Why C is correct
The NIST Cybersecurity Framework organizes activities under core functions; CSF 1.1 used Identify, Protect, Detect, Respond, and Recover, and CSF 2.0 added Govern. Its outcome-based, voluntary structure is widely applied to OT to organize risk management without prescribing specific technologies.
Know someone studying for OT Security Fundamentals? Send them this one.