Study. uk . com
  1. Home
  2. All questions
  3. Question 42

CISM study material · question 42 of 1000

An organisation is deciding how centralised its security governance should be. Which two factors does NIST name as bearing on that decision? Choose two.

  1. How diverse or homogeneous the organisation's mission is
  2. The number of physical locations and the distance between them
  3. The number of open findings in the last audit
  4. The vendor of the organisation's endpoint protection
Show the answer

Answer: B. The number of physical locations and the distance between them
A. How diverse or homogeneous the organisation's mission is

NIST lists organisation size, mission diversity, existing infrastructure, governance requirements, budget size, security capability, the number of and distance between locations, and decision-making practices.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.2 Governance Structures

Challenge yourself on this topic → Study as cards