Akylade Certified Cyber Resilience Fundamentals ACCRF · Free Practice Question Medium
Question 23
What is the primary difference between a "Current Profile" and a "Target Profile" in the NIST Cybersecurity Framework?
- A A "Current Profile" is used for external reporting, while a "Target Profile" is used for internal reporting only
- B A "Current Profile" addresses only regulatory compliance, while a "Target Profile" covers all aspects of cybersecurity
- C A "Current Profile" shows existing measures, while a "Target Profile" outlines future goals and requirements
- D A "Current Profile" focuses on technological implementations, while a "Target Profile" focuses on organizational policies
Reveal correct answer
Correct answer: C
Explanation
The "Current Profile" describes the current state of cybersecurity practices, whereas the "Target Profile" specifies what an organization aims to achieve, setting the direction for future improvements. "Current Profiles" and "Target Profiles" address broader aspects of cybersecurity, not just compliance, with the scope defined by organizational needs. Both "Current Profiles" and "Target Profiles" encompass technologies and policies; the distinction lies in their current implementation versus future goals. Both profiles are used internally for planning and can also be relevant in external communications about cybersecurity posture. For support or reporting issues, include Question ID: 6622f228ee97081c0a7140b4 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
