Study. uk . com
  1. Home
  2. All questions
  3. Question 37

CISM study material · question 37 of 1000

A reviewer cannot tell why the security strategy contains a particular goal, because nothing links it to anything the business has stated it wants. What quality is the strategy lacking?

  1. Traceability to the organisation's strategic and performance plans
  2. Approval by the authorising official
  3. A quantified return on investment
  4. Alignment with an external control framework
Show the answer

Answer: A. Traceability to the organisation's strategic and performance plans

NIST expects the security strategy's content to be clearly traceable to higher-level organisational strategic and performance plans, so each security goal can be followed back to a business goal.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.1 Strategic Planning

Challenge yourself on this topic → Study as cards