Study. uk . com
  1. Home
  2. All questions
  3. Question 35

CISM study material · question 35 of 1000

A candidate is asked to define information security governance in management terms rather than technical ones. Which definition matches NIST's?

  1. The independent audit of security controls against a published standard
  2. The selection and configuration of technical controls to protect information assets
  3. The process of detecting, reporting and responding to security incidents
  4. A framework and management structure giving assurance that security strategy supports business objectives, complies with law through policy and internal control, and assigns responsibility
Show the answer

Answer: D. A framework and management structure giving assurance that security strategy supports business objectives, complies with law through policy and internal control, and assigns responsibility

NIST defines security governance as establishing and maintaining a framework and supporting management structure and processes that assure strategy alignment with business objectives, legal compliance through policy and internal controls, and assignment of responsibility, in order to manage risk.

Source: NIST SP 800-100 (NIST) — Ch. 2 Information Security Governance

Challenge yourself on this topic → Study as cards