GSEC · Question #280
Training an organization on possible phishing attacks would be included under which NIST Framework Core guidelines?
The correct answer is D. Protect. Security awareness training on phishing falls under the Protect function of the NIST Cybersecurity Framework, which includes the Awareness and Training category (PR.AT).
Question
Training an organization on possible phishing attacks would be included under which NIST Framework Core guidelines?
Options
- ADetect
- BIdentify
- CRespond
- DProtect
How the community answered
(47 responses)- A11% (5)
- B4% (2)
- C4% (2)
- D81% (38)
Why each option
Security awareness training on phishing falls under the Protect function of the NIST Cybersecurity Framework, which includes the Awareness and Training category (PR.AT).
The Detect function covers discovering cybersecurity events after they occur, such as anomaly detection and continuous monitoring, not pre-event training.
The Identify function addresses asset management, governance, and risk assessment to understand organizational context, not workforce training.
The Respond function covers actions taken after a cybersecurity incident has been detected, such as incident response planning and communications.
The NIST CSF Protect function contains the PR.AT (Awareness and Training) category, which specifically covers ensuring personnel understand their cybersecurity responsibilities and are trained to recognize threats such as phishing. Training is a proactive, preventive control aligned with the Protect function's goal of limiting the impact of potential cybersecurity events. This is a foundational element of organizational security posture under the framework.
Concept tested: NIST CSF Protect function awareness and training category
Source: https://www.nist.gov/cyberframework/framework
Topics
Community Discussion
No community discussion yet for this question.