CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A compliance officer is preparing a report for an upcoming audit against the NIST Cybersecurity Framework (CSF). The organization has recently implemented a new privileged access management (PAM) solution. Which core function of the NIST CSF would be MOST directly supported by reporting on the effectiveness and implementation status of this PAM solution?

  1. AIdentify
  2. BRespond
  3. CDetect
  4. DProtect
Show answer & explanation

Correct answer: D. Protect

Privileged Access Management (PAM) solutions are designed to control, monitor, and secure access to critical systems and data, which directly aligns with the 'Protect' function of the NIST CSF.

Why the other options are wrong

  • A. Identify focuses on understanding the organizational context and risks, not directly on implementing security controls like PAM.
  • B. Respond focuses on taking action regarding a detected cybersecurity incident, not preventing it in the first place.
  • C. Detect focuses on identifying the occurrence of a cybersecurity event, not preventing unauthorized access.

NIST CSF Protect Function

The 'Protect' function of the NIST Cybersecurity Framework outlines safeguards to ensure the delivery of critical infrastructure services, encompassing identity management, access control, data security, and protective technology.

  • Focuses on preventing cybersecurity incidents.
  • Includes access control, awareness training, data security, information protection processes, and maintenance.
  • PAM solutions directly contribute to access control and data security within this function.

Memory trick: I Protect, Detect, Respond, and Recover from cyber threats.

More Reporting and Communication questions