- Home
- All questions
- Question 375
CISM study material · question 375 of 1000
An access review confirms permissions are enforced technically but finds no policy defining them and no periodic review. Which two elements of the CSF 2.0 outcome are missing? Choose two.
Show the answer
Answer: A. Permissions defined in a policy
C. Permissions periodically reviewed
CSF 2.0 subcategory PR.AA-05 requires access permissions, entitlements and authorisations to be defined in policy, managed, enforced and reviewed, incorporating least privilege and separation of duties.
Source: NIST CSWP 29 (NIST) — Appendix A PR.AA-05