Study. uk . com
  1. Home
  2. All questions
  3. Question 218

CISM study material · question 218 of 1000

An organisation assesses risk system by system and is surprised by an exposure created by interconnections between systems. Which weakness does SP 800-30 identify in this practice?

  1. Interconnection risk can only be found by penetration testing across the boundary, which a system-level assessment does not commission
  2. Traditional assessment focuses at the system level and overlooks risks better assessed at the organisation or process level
  3. System-level assessment always overstates risk, because each system is assessed as though it carried the whole business function alone
  4. Interconnection risk sits outside the scope of an ordinary risk assessment and is handled instead through the interconnection security agreement in force
Show the answer

Answer: B. Traditional assessment focuses at the system level and overlooks risks better assessed at the organisation or process level

SP 800-30 notes traditional risk assessments generally focus at Tier 3 and tend to overlook significant risk factors better assessed at Tier 1 or 2, giving exposure of a core business function through system interconnections as its example.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.4 Application of Risk Assessments

Challenge yourself on this topic → Study as cards