Study. uk . com
  1. Home
  2. All questions
  3. Question 511

CISM study material · question 511 of 1000

When does NIST's example policy require role-based training for staff with significant security responsibilities?

  1. Before they are given access to systems that process sensitive information
  2. Only where the individual requests it
  3. Within ninety days of taking up the role, with full access granted to them in the meantime
  4. At the first annual refresher cycle that follows their appointment into that new role
Show the answer

Answer: A. Before they are given access to systems that process sensitive information

SP 800-50r1's example policy puts role-based training ahead of access for staff with significant security responsibilities, with refresher training annually thereafter.

Source: NIST SP 800-50 Rev. 1 (NIST) — Sec. 2.2.1 Examples of Policy Statements

Challenge yourself on this topic → Study as cards