Study. uk . com
  1. Home
  2. All questions
  3. Question 110

CISM study material · question 110 of 1000

At the organisation tier, what kind of monitoring activity does SP 800-39 describe as appropriate?

  1. Vulnerability scanning of individual servers, with the results rolled up into an organisation-wide exposure figure
  2. Ongoing threat assessments and how changes in the threat space affect architecture and systems below
  3. Automated checking of the configuration settings on every endpoint against the hardening baseline the organisation has published for them
  4. Verification that backups completed for each system, reported to the organisation tier as a monthly assurance figure
Show the answer

Answer: B. Ongoing threat assessments and how changes in the threat space affect architecture and systems below

SP 800-39 places continuing threat assessment at Tier 1, together with tracing what a shifting threat picture means for the enterprise and security architectures and the systems beneath them.

Source: NIST SP 800-39 (NIST) — Sec. 3.4 Monitoring Risk

Challenge yourself on this topic → Study as cards