โ† All CCP Flashcard Decks

NIST CSF & CIS Controls Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 NIST CSF & CIS Controls flashcards as text
  1. Which NIST CSF 2.0 function was added as a new core function compared to the original 2014 version?

    Answer: Govern

    NIST CSF 2.0 added the 'Govern' function to emphasize cybersecurity governance and risk management strategy.

  2. CIS Control 1 (Inventory and Control of Enterprise Assets) is primarily designed to address which risk?

    Answer: Unmanaged or unknown assets that can be exploited

    CIS Control 1 addresses the risk that unmanaged or unknown assets cannot be protected, making them prime targets for attackers.

  3. In the NIST CSF, which category under the 'Identify' function addresses understanding the organization's mission, objectives, and stakeholders?

    Answer: Organizational Context

    The 'Organizational Context' category under Identify helps organizations understand their mission, stakeholders, dependencies, and legal requirements.

  4. CIS Controls are organized into three Implementation Groups (IGs). Which IG is appropriate for large enterprises with dedicated security staff?

    Answer: IG3

    IG3 targets large enterprises with significant cybersecurity resources and addresses sophisticated, targeted attacks.

  5. A company maps its existing security controls to the NIST CSF to identify gaps. This activity is best described as:

    Answer: Current Profile creation

    A Current Profile documents the cybersecurity outcomes an organization currently achieves, enabling gap analysis against a Target Profile.

  6. Which CIS Control specifically addresses the use of application software security practices such as input validation and secure coding?

    Answer: CIS Control 16 (Application Software Security)

    CIS Control 16 focuses on application software security, including secure coding practices, code review, and vulnerability management for applications.

  7. Under NIST CSF's 'Respond' function, which category focuses on executing a response plan and coordinating with stakeholders during an incident?

    Answer: Communications

    The 'Communications' category ensures that response activities are coordinated with internal and external stakeholders, including law enforcement and media as appropriate.