Study. uk . com
  1. Home
  2. All questions
  3. Question 92

CISM study material · question 92 of 1000

A requirements document lists the security functions a system must provide but says nothing about how much assurance is needed in them. What has been omitted under SP 800-39?

  1. The common controls the system will inherit from the enterprise, and the residual responsibility left with the system owner
  2. The level of trustworthiness expected of that security functionality
  3. The authorisation boundary for the system, which fixes which elements the authorisation covers
  4. The categorisation of the information processed, which drives the control baseline the system starts from
Show the answer

Answer: B. The level of trustworthiness expected of that security functionality

SP 800-39 states security requirements define both the needed security functionality for systems and the level of trustworthiness for that functionality, so specifying function without assurance leaves the requirement incomplete.

Source: NIST SP 800-39 (NIST) — Sec. 2.5 Tier Three — Information Systems View

Challenge yourself on this topic → Study as cards