Study. uk . com
  1. Home
  2. All questions
  3. Question 201

CISM study material · question 201 of 1000

At which tiers does SP 800-30 say risk aggregation is mainly performed?

  1. Only at the organisation tier, by the risk executive function, since no lower tier sees enough to aggregate
  2. Only at the system tier, where the data originates and where each of the individual risks is first recorded and rated
  3. Equally at all three tiers, each of them rolling its own results into a single organisation-wide figure
  4. Mainly at the organisation and business process tiers, only occasionally at the system tier
Show the answer

Answer: D. Mainly at the organisation and business process tiers, only occasionally at the system tier

SP 800-30 puts aggregation — rolling lower risks up into higher ones — chiefly at the organisation and mission tiers, with only occasional use at system level.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Aggregation

Challenge yourself on this topic → Study as cards