Study. uk . com
  1. Home
  2. All questions
  3. Question 606

CISM study material · question 606 of 1000

How does NIST characterise system security plans, and what accompanies them for controls not yet in place?

  1. As compliance artefacts produced for the annual audit
  2. As fixed baselines revised only at reauthorisation
  3. As living documents needing periodic review and modification, accompanied by corrective action plans for controls not yet implemented
  4. As technical documents maintained by the system administrator
Show the answer

Answer: C. As living documents needing periodic review and modification, accompanied by corrective action plans for controls not yet implemented

SP 800-100 treats these plans as living: reviewed and amended periodically, and paired with plans of action and milestones covering controls still to be put in.

Source: NIST SP 800-100 (NIST) — Sec. 8.2 Security Planning Roles

Challenge yourself on this topic → Study as cards