Study. uk . com
  1. Home
  2. All questions
  3. Question 199

CISM study material · question 199 of 1000

An organisation has never formally stated which impacts matter most. Which two sources does SP 800-30 say priorities can usually be derived from? Choose two.

  1. Security categorisation levels
  2. Strategic plans and policies
  3. The vendor's risk documentation
  4. The most recent penetration test report
Show the answer

Answer: B. Strategic plans and policies
A. Security categorisation levels

SP 800-30 says where priorities and values are not explicitly defined, they can typically be derived from strategic planning and policies, and notes security categorisation levels indicate the organisational impact of compromise.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Impact

Challenge yourself on this topic → Study as cards