Study. uk . com
  1. Home
  2. All questions
  3. Question 8

CISM study material · question 8 of 1000

An auditor notes the organisation's information security policy was approved six years ago and has not been touched since, although the organisation has since adopted cloud hosting and entered a regulated market. What is the governance failing?

  1. Policy was approved by the security function rather than at the executive level that owns the risk the policy commits the organisation to
  2. Policy has not been reviewed and reissued to reflect changed requirements, threats and technology
  3. Policy does not cite a recognised control framework
  4. Policy has not been distributed to every employee
Show the answer

Answer: B. Policy has not been reviewed and reissued to reflect changed requirements, threats and technology

CSF 2.0 requires policy to be revisited and reissued when requirements, threats, technology or the mission change. A policy untouched through material change is a governance gap regardless of its original quality.

Source: NIST CSWP 29 (NIST) — Appendix A GV.PO-02

Challenge yourself on this topic → Study as cards