- Home
- All questions
- Question 65
CISM study material · question 65 of 1000
Security planning happens in the security office and is presented to the business only once complete, separately from strategic and capital planning. Which NIST governance practice does this violate?
Show the answer
Answer: D. Security activities must be integrated into other enterprise management activities
SP 800-100 requires security to be woven through the enterprise's other management activities — strategic planning, capital planning, enterprise architecture — rather than run as a parallel track that reports its conclusions afterwards.
Source: NIST SP 800-100 (NIST) — Sec. 2.3 Challenges and Keys to Success