Study. uk . com
  1. Home
  2. All questions
  3. Question 26

CISM study material · question 26 of 1000

An organisation is choosing between centralised, decentralised and hybrid governance models for security. Whichever model is selected, what does SP 800-39 insist upon?

  1. A single risk assessment methodology used everywhere
  2. Identical control baselines across every business unit
  3. Direct reporting of every security officer to the board
  4. Clear and unambiguous assignment of accountability for accepting risk
Show the answer

Answer: D. Clear and unambiguous assignment of accountability for accepting risk

SP 800-39 describes centralised, decentralised and hybrid governance models and states that regardless of the model employed, clear assignment and accountability for accepting risk is essential.

Source: NIST SP 800-39 (NIST) — Sec. 2.3.1 Governance

Challenge yourself on this topic → Study as cards