Study. uk . com
  1. Home
  2. All questions
  3. Question 54

CISM study material · question 54 of 1000

A manager must explain to a new starter what the organisation's information security policy actually is, in NIST's terms. Which description is correct?

  1. The aggregate of directives, rules and practices prescribing how the organisation manages, protects and distributes information
  2. The catalogue of technical controls implemented on each system, from which the organisation's overall security posture is derived at any point in time
  3. The schedule of audits and assessments for the coming year, against which the organisation's compliance with its external obligations is measured
  4. The record of accepted residual risk for each business process, maintained by the risk executive function and revisited whenever a further exception to the baseline is granted
Show the answer

Answer: A. The aggregate of directives, rules and practices prescribing how the organisation manages, protects and distributes information

SP 800-100 defines information security policy as an aggregate of directives, rules and practices that prescribes how an organisation manages, protects and distributes information.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.5 Policy and Guidance

Challenge yourself on this topic → Study as cards