Study. uk . com
  1. Home
  2. All questions
  3. Question 383

CISM study material · question 383 of 1000

A manager asks where organisation-level security requirements are recorded, and where such requirements may originate. Which answer is correct?

  1. They come from the selected control baseline and from nowhere else at all, and each one of them is recorded in the system security plan for the particular system it applies to
  2. They come from legislation, policy, directives, regulations, standards or operational needs, and organisation-level ones are recorded in the security programme plan
  3. They come only from the rules that the applicable regulator has published, and every one of them is then recorded as its own entry in the organisation's enterprise risk register
  4. They come from the enterprise architecture and from the target designs that it holds, and all of them are recorded in the organisation's own architecture repository for reuse
Show the answer

Answer: B. They come from legislation, policy, directives, regulations, standards or operational needs, and organisation-level ones are recorded in the security programme plan

SP 800-39 notes security requirements can be obtained from legislation, policies, directives, regulations, standards and operational requirements, and that organisation-level requirements are documented in the information security programme plan.

Source: NIST SP 800-39 (NIST) — Sec. 2.2 Multitiered Risk Management

Challenge yourself on this topic → Study as cards