Study. uk . com
  1. Home
  2. All questions
  3. Question 52

CISM study material · question 52 of 1000

A procurement completes without any security requirements in the contract, and the security office learns of it only at go-live. Which governance relationship failed?

  1. Between the contracting function and the security officer, whose collaboration should ensure contracting policy carries security requirements
  2. Between the configuration control board and the change requester, whose joint review should have caught the missing security clauses before the go-live
  3. Between the inspector general and the audit committee, whose independent reporting line should have surfaced the procurement before the contract was signed
  4. Between the system owner and the information owner
Show the answer

Answer: A. Between the contracting function and the security officer, whose collaboration should ensure contracting policy carries security requirements

NIST requires the acquisitions and contracting function to collaborate with the security officer so contracting policy addresses security requirements and every contract and procurement complies with security policy.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.3.5 Related Roles — Acquisitions

Challenge yourself on this topic → Study as cards