hiexam
isc · CISSP · Q428 · multiple_choice · topic_1

What is the MAIN purpose of a security assessment plan?

What is the MAIN purpose of a security assessment plan?
  • A.Provide education to employees on security and privacy, to ensure their awareness on policies and procedures.
  • B.Provide the objectives for the security and privacy control assessments and a detailed roadmap of how to conduct such assessments.
  • C.Provide guidance on security requirements, to ensure the identified security risks are properly addressed based on the recommendation.
  • D.Provide technical information to executives to help them understand information security postures and secure funding.
Explanation
Def B: https://csrc.nist.gov/glossary/term/assessment_plan

Reference: examtopics_top_comment

Practice with progress tracking

Sign in to track wrong answers, get spaced-repetition reminders, and run timed exam mode.