- Home
- All questions
- Question 92
CISSP study material · question 92 of 500
A conglomerate lets each subsidiary run its own risk governance while the parent sets only the strategy. An auditor argues this decentralised model breaches NIST SP 800-39. What does the publication actually require?
Show the answer
Answer: A. Any model is acceptable provided accountability for accepting risk is assigned unambiguously.
SP 800-39 permits centralised, decentralised or hybrid governance. What it insists on regardless of model is clear, unambiguous accountability for accepting risk.
Source: NIST SP 800-39 (NIST) — SP 800-39 > 2.3.1 Governance