Study. uk . com
  1. Home
  2. All questions
  3. Question 92

CISSP study material · question 92 of 500

A conglomerate lets each subsidiary run its own risk governance while the parent sets only the strategy. An auditor argues this decentralised model breaches NIST SP 800-39. What does the publication actually require?

  1. Any model is acceptable provided accountability for accepting risk is assigned unambiguously.
  2. Governance must be centralised so that one authority accepts all organisational risk.
  3. Governance must be hybrid, with strategy central and acceptance delegated.
  4. Governance must mirror the organisation's legal structure exactly.
Show the answer

Answer: A. Any model is acceptable provided accountability for accepting risk is assigned unambiguously.

SP 800-39 permits centralised, decentralised or hybrid governance. What it insists on regardless of model is clear, unambiguous accountability for accepting risk.

Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.3.1 Governance

Challenge yourself on this topic → Study as cards