- Home
- All questions
- Question 52
CISM study material · question 52 of 1000
A procurement completes without any security requirements in the contract, and the security office learns of it only at go-live. Which governance relationship failed?
Show the answer
Answer: A. Between the contracting function and the security officer, whose collaboration should ensure contracting policy carries security requirements
NIST requires the acquisitions and contracting function to collaborate with the security officer so contracting policy addresses security requirements and every contract and procurement complies with security policy.
Source: NIST SP 800-100 (NIST) — Sec. 2.2.3.5 Related Roles — Acquisitions