Study. uk . com
  1. Home
  2. All questions
  3. Question 132

CISM study material · question 132 of 1000

A decentralised organisation performs most risk assessment at the business process tier. What does SP 800-39 say this creates a greater need for?

  1. External validation of every assessment
  2. More communication within that tier to identify cross-cutting threats and vulnerabilities
  3. A single mandated assessment methodology
  4. Fewer assessments at the organisation tier
Show the answer

Answer: B. More communication within that tier to identify cross-cutting threats and vulnerabilities

SP 800-39 expects a decentralised organisation to do more of its assessing at Tier 2, and therefore to talk more across Tier 2 so that threats and weaknesses spanning several processes are spotted.

Source: NIST SP 800-39 (NIST) — Sec. 3.2 Assessing Risk

Challenge yourself on this topic → Study as cards