- Home
- All questions
- Question 8
CISM study material · question 8 of 1000
An auditor notes the organisation's information security policy was approved six years ago and has not been touched since, although the organisation has since adopted cloud hosting and entered a regulated market. What is the governance failing?
Show the answer
Answer: B. Policy has not been reviewed and reissued to reflect changed requirements, threats and technology
CSF 2.0 requires policy to be revisited and reissued when requirements, threats, technology or the mission change. A policy untouched through material change is a governance gap regardless of its original quality.
Source: NIST CSWP 29 (NIST) — Appendix A GV.PO-02