QuestionQ295

Risk Response and Reporting

An organization has hired an external consultant to evaluate its cybersecurity program. Which of the following findings is MOST important to remediate?

  • A Lack of a cyber risk profile
  • B Lack of cyber risk awareness training
  • C Lack of a dedicated cybersecurity team
  • D Lack of accountability
Explanation

Accountability establishes clear ownership, decision authority, and oversight for cybersecurity risk. It is a governance prerequisite for directing and sustaining risk profiling, awareness training, resourcing, and other program activities. NIST CSF 2.0 states that organizational leadership is responsible and accountable for cybersecurity risk and that related roles, responsibilities, and authorities must be established and communicated.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!