Study. uk . com
  1. Home
  2. All questions
  3. Question 64

CISM study material · question 64 of 1000

A security manager notices that individuals with assigned security responsibilities face no consequence when they simply fail to act. Which of NIST's keys to good governance is being neglected?

  1. Assigning security responsibilities only to individuals who have completed the organisation's security training programme
  2. Holding those responsible for security accountable for their actions or lack of actions
  3. Communicating security priorities to stakeholders at every level, so that each of them can see where their own work fits
  4. Integrating security into the strategic and capital planning cycle, so that funding follows the priorities that were set
Show the answer

Answer: B. Holding those responsible for security accountable for their actions or lack of actions

Among the practices NIST lists as critical, individuals responsible for information security within the organisation should be held accountable for their actions or lack of actions.

Source: NIST SP 800-100 (NIST) — Sec. 2.3 Challenges and Keys to Success

Challenge yourself on this topic → Study as cards