Study. uk . com
  1. Home
  2. All questions
  3. Question 56

CISM study material · question 56 of 1000

A drafter builds the organisation's security policy purely from an external control framework, with no other input. Which two further inputs does NIST expect the policy to be built from? Choose two.

  1. The findings of the most recent penetration test of the estate
  2. The organisation's own internal requirements
  3. Applicable legislation
  4. Vendor documentation for deployed products
Show the answer

Answer: C. Applicable legislation
B. The organisation's own internal requirements

NIST states security policy should be based on a combination of appropriate legislation, applicable standards and guidance, and internal organisational requirements — three inputs together rather than one.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.5 Policy and Guidance

Challenge yourself on this topic → Study as cards