Study. uk . com
  1. Home
  2. All questions
  3. Question 436

CISM study material · question 436 of 1000

NIST identifies people as arguably the weakest element in securing systems. Which controls does it name as those that address the risk people introduce?

  1. Awareness activities and role-based training
  2. Background screening and the enforced separation of duties
  3. Continuous monitoring and the analysis of the system logs
  4. Multi-factor authentication and privileged access management
Show the answer

Answer: A. Awareness activities and role-based training

NIST states awareness activities and role-based training are the only security controls that can minimise the inherent risk resulting from the people who use, manage, operate and maintain systems and networks.

Source: NIST SP 800-100 (NIST) — Ch. 4 Awareness and Training

Challenge yourself on this topic → Study as cards