Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Lead-Cybersecurity-Manager Exam - Topic 4 Question 34 Discussion

Among others, which of the following factors should be considered when selecting a Tier, according to the NIST Framework for Improving Critical Infrastructure Cyber security?
A) Threat environment
B) Number of past cybersecurity incidents
C) Stakeholders' involvement m the process

PECB Lead-Cybersecurity-Manager Exam - Topic 4 Question 34 Discussion

Actual exam question for PECB's Lead-Cybersecurity-Manager exam
Question #: 34
Topic #: 4
[All Lead-Cybersecurity-Manager Questions]

Among others, which of the following factors should be considered when selecting a Tier, according to the NIST Framework for Improving Critical Infrastructure Cyber security?

Show Suggested Answer Hide Answer
Suggested Answer: A

When selecting a Tier according to the NIST Framework for Improving Critical Infrastructure Cybersecurity, several factors must be considered, including the threat environment. The threat environment refers to the external factors that could impact the organization's cybersecurity, such as the presence of threat actors, the nature of the cyber threats, and the sophistication of attacks.

Detailed Explanation:

Threat Environment:

Definition: The external landscape that poses potential threats to an organization's cybersecurity.

Factors: Includes cyber threats from hackers, nation-states, competitors, and other malicious entities.

Relevance: Understanding the threat environment helps in selecting an appropriate Tier that aligns with the level of risk the organization faces.

NIST Framework:

Tier Selection: Tiers range from 1 to 4, representing the organization's approach to cybersecurity risk management (Partial, Risk-Informed, Repeatable, and Adaptive).

Considerations: Threat environment, regulatory requirements, business objectives, and organizational constraints.

Cybersecurity Reference:

NIST Cybersecurity Framework: Provides guidelines for managing cybersecurity risks, emphasizing the importance of considering the threat environment when selecting an appropriate Tier.

NIST SP 800-39: Risk Management Guide for Information Technology Systems, which outlines the need to consider the threat environment in risk management.

By considering the threat environment, organizations can ensure that their cybersecurity measures are appropriately scaled to address potential risks.


Contribute your Thoughts:

0/2000 characters
Gilma
2 hours ago
I thought all three factors were relevant, but I’m leaning towards the threat environment being the most significant based on what we studied.
upvoted 0 times
...
Roosevelt
5 days ago
I feel like the number of past cybersecurity incidents could be important too, but I’m not confident if it’s as critical as the threat environment.
upvoted 0 times
...
Venita
10 days ago
I remember a practice question that mentioned stakeholders' involvement, but I can't recall if it was specifically about tier selection.
upvoted 0 times
...
Raelene
16 days ago
I think the threat environment is definitely a key factor, but I’m not sure about the others. Did we cover how past incidents influence tier selection?
upvoted 0 times
...

Save Cancel