Study. uk . com
  1. Home
  2. All questions
  3. Question 635

CISM study material · question 635 of 1000

Which two roles does NIST say must be involved in security categorisation, showing it is not a single team's task? Choose two.

  1. The vendor's own technical account manager for the estate
  2. Information owners and system owners
  3. The external auditor engaged for the year
  4. Authorising officials
Show the answer

Answer: D. Authorising officials
B. Information owners and system owners

SP 800-100 makes categorisation an enterprise-wide activity involving senior officials — information officers, security officers, authorising officials, system owners and information owners together.

Source: NIST SP 800-100 (NIST) — Sec. 8.5 Security Control Selection

Challenge yourself on this topic → Study as cards