Study. uk . com
  1. Home
  2. All questions
  3. Question 392

CISSP study material · question 392 of 500

A team asks which single assessment methodology NIST requires them to adopt. What does SP 800-115 say?

  1. NIST requires its own SP 800-53A procedures for all organisations.
  2. NIST requires the methodology named in the organisation's authorisation package.
  3. NIST requires the Open Source Security Testing Methodology Manual for technical testing.
  4. NIST endorses none over another and expects organisations to adopt or combine methodologies to suit themselves.
Show the answer

Answer: D. NIST endorses none over another and expects organisations to adopt or combine methodologies to suit themselves.

SP 800-115 states NIST does not endorse one methodology over another, intending to give organisations options to adopt an existing methodology or combine several into their own.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.1 Information Security Assessment Methodology

Challenge yourself on this topic → Study as cards