Study. uk . com
  1. Home
  2. All questions
  3. Question 172

CISM study material · question 172 of 1000

A manager plans to complete a risk assessment and then hold a separate exercise to rank the results. How does SP 800-30 define the scope of assessment?

  1. Risk assessment is identifying, estimating and prioritising risk, so prioritisation is part of it
  2. Risk assessment is identifying and responding to risk, with prioritisation carried out inside the response step
  3. Risk assessment ends at estimation; prioritisation is a separate management step performed once the estimates are in
  4. Risk assessment covers identification only; estimation and prioritisation both belong to the response process that follows it
Show the answer

Answer: A. Risk assessment is identifying, estimating and prioritising risk, so prioritisation is part of it

SP 800-30 defines risk assessment as the process of identifying, estimating and prioritising information security risks, so prioritisation belongs inside the assessment rather than after it.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3 Key Risk Concepts

Challenge yourself on this topic → Study as cards