Study. uk . com
  1. Home
  2. All questions
  3. Question 65

CISM study material · question 65 of 1000

Security planning happens in the security office and is presented to the business only once complete, separately from strategic and capital planning. Which NIST governance practice does this violate?

  1. Security planning must be approved by the audit committee
  2. Security planning must precede all other enterprise planning
  3. Security plans must be published to all staff
  4. Security activities must be integrated into other enterprise management activities
Show the answer

Answer: D. Security activities must be integrated into other enterprise management activities

SP 800-100 requires security to be woven through the enterprise's other management activities — strategic planning, capital planning, enterprise architecture — rather than run as a parallel track that reports its conclusions afterwards.

Source: NIST SP 800-100 (NIST) — Sec. 2.3 Challenges and Keys to Success

Challenge yourself on this topic → Study as cards