Study. uk . com
  1. Home
  2. All questions
  3. Question 162

CISM study material · question 162 of 1000

A manager is asked to state the purpose of information security governance in one sentence for the annual report. Which formulation matches NIST's?

  1. Ensuring every system passes its annual audit without findings
  2. Ensuring the organisation holds certification against a recognised standard, so that an external body has confirmed the programme is adequate for its mission
  3. Ensuring appropriate controls are implemented proactively and cost-effectively in support of the mission, while evolving risks are managed
  4. Ensuring the security budget is fully spent each year
Show the answer

Answer: C. Ensuring appropriate controls are implemented proactively and cost-effectively in support of the mission, while evolving risks are managed

SP 800-100 frames governance as making sure controls arrive ahead of trouble and at sensible cost, serving the mission, while the risks the organisation faces keep changing.

Source: NIST SP 800-100 (NIST) — Ch. 2 Information Security Governance

Challenge yourself on this topic → Study as cards