Study. uk . com
  1. Home
  2. All questions
  3. Question 19

CISM study material · question 19 of 1000

A newly appointed security manager wants to structure risk management across the organisation using SP 800-39. Which description of the three tiers is correct?

  1. Tier 1 individual information systems, Tier 2 the networks that join them, Tier 3 the organisation itself
  2. Tier 1 technical controls, Tier 2 administrative controls, Tier 3 physical and environmental safeguards
  3. Tier 1 the organisation, Tier 2 mission and business processes, Tier 3 information systems
  4. Tier 1 strategy setting, Tier 2 internal audit assurance, Tier 3 regulatory compliance reporting and attestation
Show the answer

Answer: C. Tier 1 the organisation, Tier 2 mission and business processes, Tier 3 information systems

SP 800-39 addresses risk at three tiers: the organisation, mission and business processes, and information systems, running from strategic risk at the top to tactical risk at the bottom.

Source: NIST SP 800-39 (NIST) — Sec. 2.2 Multitiered Risk Management

Challenge yourself on this topic → Study as cards