- Home
- All questions
- Question 35
CISM study material · question 35 of 1000
A candidate is asked to define information security governance in management terms rather than technical ones. Which definition matches NIST's?
Show the answer
Answer: D. A framework and management structure giving assurance that security strategy supports business objectives, complies with law through policy and internal control, and assigns responsibility
NIST defines security governance as establishing and maintaining a framework and supporting management structure and processes that assure strategy alignment with business objectives, legal compliance through policy and internal controls, and assignment of responsibility, in order to manage risk.
Source: NIST SP 800-100 (NIST) — Ch. 2 Information Security Governance