Study. uk . com
  1. Home
  2. All questions
  3. Question 618

CISM study material · question 618 of 1000

Why must a system and its information be categorised before the security plan is written?

  1. The impact level shapes both where the system boundary is drawn and the initial control baseline selected
  2. Categorisation determines which template the plan uses
  3. Categorisation determines the plan's approval authority
  4. Categorisation fixes the plan's review frequency
Show the answer

Answer: A. The impact level shapes both where the system boundary is drawn and the initial control baseline selected

SP 800-100 states that before the plan can be developed, the system and its information must be categorised on an impact analysis, and that the impact levels must be considered when boundaries are drawn and when selecting the initial control baseline.

Source: NIST SP 800-100 (NIST) — Sec. 8.4.1 System Boundary Analysis

Challenge yourself on this topic → Study as cards