Study. uk . com
  1. Home
  2. All questions
  3. Question 555

CISM study material · question 555 of 1000

Which two product considerations does NIST list for security product selection? Choose two.

  1. Security-critical dependencies on other products
  2. The vendor's marketing budget
  3. Known vulnerabilities and the need to test and implement relevant patches
  4. The colour scheme of the management interface
Show the answer

Answer: A. Security-critical dependencies on other products
C. Known vulnerabilities and the need to test and implement relevant patches

SP 800-100's product considerations include total life cycle cost, ease of use, scalability, interoperability, test requirements, known vulnerabilities, patching, review against organisational policies, security-critical dependencies, and interactions with the existing infrastructure.

Source: NIST SP 800-100 (NIST) — Table 12-5 Product Selection Considerations

Challenge yourself on this topic → Study as cards