- Home
- All questions
- Question 607
CISM study material · question 607 of 1000
An organisation produces its system security plan as an output of the authorisation process. What sequence does NIST require?
Show the answer
Answer: A. The plan is developed and reviewed before the authorisation process begins
SP 800-100 requires the plan to be written and reviewed first, with certification and accreditation only starting once that is done — the plan is an input, not an output.
Source: NIST SP 800-100 (NIST) — Sec. 8.2 Security Planning Roles