Study. uk . com
  1. Home
  2. All questions
  3. Question 173

CISM study material · question 173 of 1000

An auditor asks the security manager to describe the organisation's risk assessment methodology. Which two components does SP 800-30 say it should contain? Choose two.

  1. An explicit risk model defining the assessable risk factors and their relationships
  2. An analysis approach describing how combinations of factors are examined
  3. A schedule of the external audits planned for the coming year, against which the assessment results will be checked
  4. A list of every asset in the organisation
Show the answer

Answer: A. An explicit risk model defining the assessable risk factors and their relationships
B. An analysis approach describing how combinations of factors are examined

SP 800-30 says a methodology typically includes the assessment process, an explicit risk model, an assessment approach such as qualitative or quantitative, and an analysis approach such as threat- or asset-oriented.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3 Key Risk Concepts

Challenge yourself on this topic → Study as cards