- Home
- All questions
- Question 162
CISM study material · question 162 of 1000
A manager is asked to state the purpose of information security governance in one sentence for the annual report. Which formulation matches NIST's?
Show the answer
Answer: C. Ensuring appropriate controls are implemented proactively and cost-effectively in support of the mission, while evolving risks are managed
SP 800-100 frames governance as making sure controls arrive ahead of trouble and at sensible cost, serving the mission, while the risks the organisation faces keep changing.
Source: NIST SP 800-100 (NIST) — Ch. 2 Information Security Governance