Study. uk . com
  1. Home
  2. All questions
  3. Question 59

CISM study material · question 59 of 1000

Physical security policy grants building access on one basis while information security policy grants system access on another, and the two contradict for contractors. What does NIST advise?

  1. Keep the policies separate so that each discipline retains authority over its own domain, and resolve contractor cases individually as they arise
  2. Coordinate all internal security policies so crosscutting objectives such as access control are implemented consistently
  3. Escalate each contradiction to the board as it arises, so that the directors rather than the policy owners decide who may enter and who may log in
  4. Give physical security policy precedence in all cases, on the grounds that denying access to the building also denies access to the systems inside it
Show the answer

Answer: B. Coordinate all internal security policies so crosscutting objectives such as access control are implemented consistently

NIST asks that as part of periodic review and initial development, organisations ensure all internal security policies including physical and personnel are sufficiently coordinated for crosscutting and convergent objectives such as access control.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.5 Policy and Guidance

Challenge yourself on this topic → Study as cards