Study. uk . com
  1. Home
  2. All questions
  3. Question 165

CISM study material · question 165 of 1000

Which two responsibilities does NIST assign to the chief information officer in the security governance model? Choose two.

  1. Developing and maintaining the organisation-wide information security programme
  2. Performing the independent assessment of security practices
  3. Designating the senior information security officer
  4. Approving the disaster declaration
Show the answer

Answer: C. Designating the senior information security officer
A. Developing and maintaining the organisation-wide information security programme

NIST assigns the information officer responsibility for designating the senior security officer, developing and maintaining the organisation-wide programme and its policies, ensuring compliance, and reporting annually on effectiveness.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.3.2 Chief Information Officer

Challenge yourself on this topic → Study as cards