- Home
- All questions
- Question 172
CISM study material · question 172 of 1000
A manager plans to complete a risk assessment and then hold a separate exercise to rank the results. How does SP 800-30 define the scope of assessment?
Show the answer
Answer: A. Risk assessment is identifying, estimating and prioritising risk, so prioritisation is part of it
SP 800-30 defines risk assessment as the process of identifying, estimating and prioritising information security risks, so prioritisation belongs inside the assessment rather than after it.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3 Key Risk Concepts