2.1k views
4 votes
To be compliant with the risk management standards and processes outlined in NIST publications (think FISMA), policies must include key security control requirements. One of the following is not one of the key requirements. Which one?

a) Access Control
b) Risk Assessment
c) Business Continuity Planning
d) Change Management

User Semptra
by
8.1k points

1 Answer

4 votes

Final answer:

The correct answer is D) Change Management.

Step-by-step explanation:

The correct answer is D) Change Management. While Access Control, Risk Assessment, and Business Continuity Planning are all key requirements for compliance with risk management standards and processes outlined in NIST publications (such as FISMA), Change Management is not listed as one of the key requirements in this context.

User Spencer R
by
8.4k points