- Home
- All questions
- Question 635
CISM study material · question 635 of 1000
Which two roles does NIST say must be involved in security categorisation, showing it is not a single team's task? Choose two.
Show the answer
Answer: D. Authorising officials
B. Information owners and system owners
SP 800-100 makes categorisation an enterprise-wide activity involving senior officials — information officers, security officers, authorising officials, system owners and information owners together.
Source: NIST SP 800-100 (NIST) — Sec. 8.5 Security Control Selection