Study. uk . com
  1. Home
  2. All questions
  3. Question 55

CISM study material · question 55 of 1000

An organisation has a governance committee, defined roles and an approved strategy, but no written security policy. Why does NIST regard this as a fundamental weakness?

  1. Strategy documents expire unless a policy renews them
  2. Without policy, governance has no substance and no rules to enforce
  3. Policy is the only artefact regulators will accept as evidence
  4. Roles cannot be assigned until policy names each individual
Show the answer

Answer: B. Without policy, governance has no substance and no rules to enforce

NIST states that information security policy is an essential component of governance, and that without the policy, governance has no substance and no rules to enforce.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.5 Policy and Guidance

Challenge yourself on this topic → Study as cards