Study. uk . com
  1. Home
  2. All questions
  3. Question 637

CISM study material · question 637 of 1000

How does NIST define adequate security?

  1. Security sufficient to prevent all unauthorised access to the information that is held, whatever the cost of achieving that may finally turn out to be
  2. Security certified by an accredited external assessor
  3. Security meeting the minimum baseline set for the system's own impact level, with no further adjustment required at all once that baseline is in place
  4. Security commensurate with the risk and the magnitude of harm from loss, misuse, or unauthorised access to or modification of information
Show the answer

Answer: D. Security commensurate with the risk and the magnitude of harm from loss, misuse, or unauthorised access to or modification of information

SP 800-100's definition sets security in proportion to the risk and to how much harm would follow from information being lost, misused, accessed without authority or altered.

Source: NIST SP 800-100 (NIST) — Sec. 8.5 footnote 62

Challenge yourself on this topic → Study as cards