CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A security analyst is preparing a report on the organization's adherence to the NIST Cybersecurity Framework (CSF) 'Recover' function. Which of the following metrics would be MOST relevant to include in this report?
- ANumber of identified vulnerabilities per month.
- BMean Time To Recover (MTTR) critical business functions.
- CPercentage of security awareness training completion.
- DNumber of successful phishing emails blocked.
Show answer & explanationAnswer & explanation
Correct answer: B. Mean Time To Recover (MTTR) critical business functions.
The NIST CSF 'Recover' function focuses on activities to restore normal operations after a cybersecurity incident. Mean Time To Recover (MTTR) directly measures the efficiency of these recovery efforts, making it the most relevant metric.
Why the other options are wrong
- A. This relates to the 'Identify' and 'Protect' functions (vulnerability management), not 'Recover'.
- C. This relates to the 'Protect' function (awareness training), not 'Recover'.
- D. This relates to the 'Protect' function (email security), not 'Recover'.
NIST CSF Recover Metrics
Metrics used to evaluate the effectiveness of an organization's capabilities to restore services and data impaired by a cybersecurity incident.
- Focus on resilience and business continuity.
- Includes recovery time objectives (RTO) and recovery point objectives (RPO).
- MTTR is a key indicator of recovery efficiency.
Memory trick: Recover = Restore, so measure recovery time.