- Home
- All questions
- Question 19
CISM study material · question 19 of 1000
A newly appointed security manager wants to structure risk management across the organisation using SP 800-39. Which description of the three tiers is correct?
Show the answer
Answer: C. Tier 1 the organisation, Tier 2 mission and business processes, Tier 3 information systems
SP 800-39 addresses risk at three tiers: the organisation, mission and business processes, and information systems, running from strategic risk at the top to tactical risk at the bottom.
Source: NIST SP 800-39 (NIST) — Sec. 2.2 Multitiered Risk Management