- Home
- All questions
- Question 56
CISM study material · question 56 of 1000
A drafter builds the organisation's security policy purely from an external control framework, with no other input. Which two further inputs does NIST expect the policy to be built from? Choose two.
Show the answer
Answer: C. Applicable legislation
B. The organisation's own internal requirements
NIST states security policy should be based on a combination of appropriate legislation, applicable standards and guidance, and internal organisational requirements — three inputs together rather than one.
Source: NIST SP 800-100 (NIST) — Sec. 2.2.5 Policy and Guidance