- Home
- All questions
- Question 173
CISM study material · question 173 of 1000
An auditor asks the security manager to describe the organisation's risk assessment methodology. Which two components does SP 800-30 say it should contain? Choose two.
Show the answer
Answer: A. An explicit risk model defining the assessable risk factors and their relationships
B. An analysis approach describing how combinations of factors are examined
SP 800-30 says a methodology typically includes the assessment process, an explicit risk model, an assessment approach such as qualitative or quantitative, and an analysis approach such as threat- or asset-oriented.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3 Key Risk Concepts