問題文
A hospital group's steering committee wants to know how far cybersecurity risk decisions are already embedded in the way the enterprise makes decisions overall. Which part of the Framework is meant to answer that particular question?
選択肢
- The Framework gives the job of describing the characteristics of cybersecurity risk practices to Informative References, so that part is what answers the question the committee raised.
- The Framework gives the job of describing the characteristics of cybersecurity risk practices to Implementation Tiers, so that part is what answers the question the committee raised.
- The Framework gives the job of describing the characteristics of external privacy process to Informative References, so that part is what answers the question the committee raised.
- The Framework gives the job of describing the characteristics of external privacy process to Implementation Tiers, so that part is what answers the question the committee raised.