Study. uk . com
  1. Home
  2. All questions
  3. Question 187

CISM study material · question 187 of 1000

Which two of the following does SP 800-30 recognise as vulnerabilities in governance structures themselves? Choose two.

  1. An unpatched operating system running on a file server in the branch office estate
  2. Absence of an effective risk management strategy and adequate risk framing
  3. A weak password policy on an internal application that the finance team uses every day
  4. Inconsistent decisions about the relative priorities of business functions
Show the answer

Answer: B. Absence of an effective risk management strategy and adequate risk framing
D. Inconsistent decisions about the relative priorities of business functions

SP 800-30 states vulnerabilities can be found in organisational governance structures, giving examples such as lack of effective risk strategies and risk framing, poor intra-agency communication, and inconsistent decisions about mission priorities.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Vulnerabilities

Challenge yourself on this topic → Study as cards