Study. uk . com
  1. Home
  2. All questions
  3. Question 166

CISM study material · question 166 of 1000

Which two duties does NIST place with the senior information security officer? Choose two.

  1. Periodically testing and evaluating the effectiveness of security policies, procedures and practices
  2. Periodically assessing the risk and magnitude of harm from unauthorised access or disruption
  3. Signing contracts with external service providers on behalf of the organisation and approving their security terms
  4. Chairing the investment review board that ranks the organisation's security spending for the coming year
Show the answer

Answer: B. Periodically assessing the risk and magnitude of harm from unauthorised access or disruption
A. Periodically testing and evaluating the effectiveness of security policies, procedures and practices

The senior security officer periodically assesses risk and the magnitude of potential harm, maintains risk-based cost-effective policy, trains staff with significant responsibilities, and periodically tests and evaluates the effectiveness of practices.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.3.3 Senior Agency Information Security Officer

Challenge yourself on this topic → Study as cards