- Home
- All questions
- Question 55
CISM study material · question 55 of 1000
An organisation has a governance committee, defined roles and an approved strategy, but no written security policy. Why does NIST regard this as a fundamental weakness?
Show the answer
Answer: B. Without policy, governance has no substance and no rules to enforce
NIST states that information security policy is an essential component of governance, and that without the policy, governance has no substance and no rules to enforce.
Source: NIST SP 800-100 (NIST) — Sec. 2.2.5 Policy and Guidance