Study. uk . com
  1. Home
  2. All questions
  3. Question 234

CISM study material · question 234 of 1000

Two organisations scope their threat analysis differently: one considers only threats its peers have actually suffered, the other adds threats that are merely plausible. What best explains the difference?

  1. One is regulated and the other is not
  2. One uses quantitative methods and the other qualitative, which changes what can be counted
  3. Their differing risk tolerance, which shapes how assessments are scoped
  4. One organisation has a larger security budget and can afford to look much further
Show the answer

Answer: C. Their differing risk tolerance, which shapes how assessments are scoped

SP 800-39 notes more risk-tolerant organisations may be concerned only with threats peer organisations have experienced, while less risk-tolerant ones expand the list to threats that are theoretically possible but not yet observed.

Source: NIST SP 800-39 (NIST) — Sec. 2.3.3 Risk Management Strategy

Challenge yourself on this topic → Study as cards