- Home
- All questions
- Question 54
CISM study material · question 54 of 1000
A manager must explain to a new starter what the organisation's information security policy actually is, in NIST's terms. Which description is correct?
Show the answer
Answer: A. The aggregate of directives, rules and practices prescribing how the organisation manages, protects and distributes information
SP 800-100 defines information security policy as an aggregate of directives, rules and practices that prescribes how an organisation manages, protects and distributes information.
Source: NIST SP 800-100 (NIST) — Sec. 2.2.5 Policy and Guidance