Study. uk . com
  1. Home
  2. All questions
  3. Question 607

CISM study material · question 607 of 1000

An organisation produces its system security plan as an output of the authorisation process. What sequence does NIST require?

  1. The plan is developed and reviewed before the authorisation process begins
  2. The plan is produced by the assessor rather than the owner
  3. The plan is produced only where the system has been categorised as being high impact
  4. The plan is produced during authorisation and finalised afterwards
Show the answer

Answer: A. The plan is developed and reviewed before the authorisation process begins

SP 800-100 requires the plan to be written and reviewed first, with certification and accreditation only starting once that is done — the plan is an input, not an output.

Source: NIST SP 800-100 (NIST) — Sec. 8.2 Security Planning Roles

Challenge yourself on this topic → Study as cards