Study. uk . com
  1. Home
  2. All questions
  3. Question 533

CISM study material · question 533 of 1000

Which three activities does NIST place in the initiation phase of the security services life cycle?

  1. Needs determination, security categorisation and a preliminary risk assessment
  2. Business case, service arrangement and implementation plan
  3. Baselining the existing environment, metrics creation and total cost of ownership analysis
  4. Provider identification, agreement of the terms and the ongoing management of expectations
Show the answer

Answer: A. Needs determination, security categorisation and a preliminary risk assessment

SP 800-100 states the initiation phase is when the need to start the services life cycle is recognised, and consists of needs determination, security categorisation, and the preliminary risk assessment.

Source: NIST SP 800-100 (NIST) — Table 12-1 Services Life Cycle

Challenge yourself on this topic → Study as cards