Study. uk . com
  1. Home
  2. All questions
  3. Question 251

CISM study material · question 251 of 1000

What is the stated purpose of the monitoring step in the IR 8286 risk life cycle?

  1. To confirm that the register has been updated within the period the policy requires, and to record who last updated each entry
  2. To ensure enterprise risk conditions remain within the defined risk appetite as cybersecurity risks change
  3. To recalculate residual risk for reporting to the regulator
  4. To verify that each control has been implemented as designed
Show the answer

Answer: B. To ensure enterprise risk conditions remain within the defined risk appetite as cybersecurity risks change

IR 8286 gives monitoring the job of keeping enterprise risk conditions inside the appetite that was set, as the cybersecurity risks underneath keep shifting.

Source: NIST IR 8286 (NIST) — Sec. 2.1 Notional Risk Management Life Cycle

Challenge yourself on this topic → Study as cards