Study. uk . com
  1. Home
  2. All questions
  3. Question 106

CISM study material · question 106 of 1000

Which two criteria does NIST use to prioritise potential enterprise-level security investments in the capital planning process? Choose two.

  1. The age of the technology being replaced and the support status of its vendor
  2. The financial impact of implementing the appropriate controls
  3. The mission
  4. The number of systems affected
Show the answer

Answer: C. The mission
B. The financial impact of implementing the appropriate controls

SP 800-100 ranks enterprise-level security investments by mission and by what the necessary controls will cost. System-level corrective actions are ranked differently, by system category and by the impact of the fix.

Source: NIST SP 800-100 (NIST) — Sec. 5.2 Integrating Security into CPIC

Challenge yourself on this topic → Study as cards