- Home
- All questions
- Question 132
CISM study material · question 132 of 1000
A decentralised organisation performs most risk assessment at the business process tier. What does SP 800-39 say this creates a greater need for?
Show the answer
Answer: B. More communication within that tier to identify cross-cutting threats and vulnerabilities
SP 800-39 expects a decentralised organisation to do more of its assessing at Tier 2, and therefore to talk more across Tier 2 so that threats and weaknesses spanning several processes are spotted.
Source: NIST SP 800-39 (NIST) — Sec. 3.2 Assessing Risk