โ† All CCP Flashcard Decks

NIST CSF & CIS Controls Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 NIST CSF & CIS Controls flashcards as text
  1. What is the primary purpose of 'Informative References' in the NIST CSF?

    Answer: Map CSF outcomes to specific standards, guidelines, and practices

    Informative References link CSF categories and subcategories to existing standards (e.g., ISO 27001, CIS Controls, COBIT) to help organizations implement outcomes.

  2. CIS Control 3 (Data Protection) requires organizations to classify data. What is the primary reason for data classification?

    Answer: To apply appropriate protections based on data sensitivity

    Data classification enables organizations to apply proportionate security controls based on the sensitivity and criticality of the data.

  3. An organization at NIST CSF Tier 2 ('Risk Informed') differs from Tier 1 ('Partial') in what key way?

    Answer: Cybersecurity risk awareness exists but isn't organization-wide policy

    At Tier 2, organizations are aware of cybersecurity risk and have some practices in place, but these may not be consistently implemented as organization-wide policy.

  4. Which CIS Control addresses the secure management of network infrastructure devices such as routers, switches, and firewalls?

    Answer: CIS Control 12 (Network Infrastructure Management)

    CIS Control 12 focuses on actively managing and securing network infrastructure devices to prevent unauthorized access and configuration drift.

  5. Under the NIST CSF 'Recover' function, which category ensures lessons from an incident are incorporated into future response plans?

    Answer: Improvements

    The 'Improvements' category under Recover ensures that recovery planning and processes are improved based on lessons learned from incidents.

  6. CIS IG1 is sometimes called 'cyber hygiene.' Which organization would most appropriately implement only IG1 controls?

    Answer: A small business with limited IT resources and low-sensitivity data

    IG1 is designed for small organizations with limited security resources that need essential protections against common, non-targeted attacks.

  7. Which NIST CSF subcategory outcome is best described as: 'Cybersecurity roles and responsibilities for the entire workforce are established'?

    Answer: GV.RR (Roles, Responsibilities, and Authorities)

    GV.RR under the Govern function addresses establishing and communicating cybersecurity roles, responsibilities, and authorities across the organization.