Study. uk . com
  1. Home
  2. All questions
  3. Question 137

CISM study material · question 137 of 1000

An organisation prioritises remediating system-level flaws over addressing a weakness in its business process design. What does SP 800-39 warn about that ordering?

  1. Business process weaknesses cannot be remediated by security controls
  2. Process weaknesses fall outside the scope of risk assessment
  3. Architectural and business process weaknesses can have greater impact because their effect spans many systems and environments
  4. System flaws are always lower severity than process weaknesses
Show the answer

Answer: C. Architectural and business process weaknesses can have greater impact because their effect spans many systems and environments

SP 800-39 states vulnerabilities associated with architectural design and mission or business processes can have a greater impact on the organisation's ability to carry out its missions because of their potential impact across multiple systems and environments.

Source: NIST SP 800-39 (NIST) — Task 2-1 Threat and Vulnerability Identification

Challenge yourself on this topic → Study as cards