- Home
- All questions
- Question 637
CISM study material · question 637 of 1000
How does NIST define adequate security?
Show the answer
Answer: D. Security commensurate with the risk and the magnitude of harm from loss, misuse, or unauthorised access to or modification of information
SP 800-100's definition sets security in proportion to the risk and to how much harm would follow from information being lost, misused, accessed without authority or altered.
Source: NIST SP 800-100 (NIST) — Sec. 8.5 footnote 62