Study. uk . com
  1. Home
  2. All questions
  3. Question 139

CISM study material · question 139 of 1000

An assessment examines only those threats for which the organisation already has safeguards deployed. What does SP 800-39 say is missing?

  1. The residual risk calculation for each deployed control
  2. The cost-benefit analysis for each safeguard
  3. Verification that each deployed safeguard was correctly installed and is operating the way its design intended
  4. Examination of business vulnerabilities and threats where no safeguards or countermeasures exist
Show the answer

Answer: D. Examination of business vulnerabilities and threats where no safeguards or countermeasures exist

SP 800-39 states that risk determinations require organisations to examine mission and business vulnerabilities and threats where safeguards or countermeasures do not exist, not only those the current controls address.

Source: NIST SP 800-39 (NIST) — Task 2-2 Risk Determination and Uncertainty

Challenge yourself on this topic → Study as cards