Study. uk . com
  1. Home
  2. All questions
  3. Question 253

CISM study material · question 253 of 1000

An enterprise risk register holds legal and financial risks but no cybersecurity entries, and the board cannot see cyber risk alongside the rest. What does IR 8286 prescribe?

  1. Cyber risks should be reported separately to the technology committee, which is the body best equipped to interpret them
  2. Cyber risks must be documented and tracked in cybersecurity risk registers so they reach the enterprise view
  3. Cyber risks should be converted into financial risks before any entry is made, so that the enterprise register holds one kind of measure
  4. Cyber risks belong only in the system security plan, where they sit beside the controls that were chosen to treat them
Show the answer

Answer: B. Cyber risks must be documented and tracked in cybersecurity risk registers so they reach the enterprise view

IR 8286 treats the enterprise register as a composite of discipline-specific ones, so cyber risks must be captured and tracked in cybersecurity registers if they are to be managed at enterprise level.

Source: NIST IR 8286 (NIST) — Sec. 2.1 Risk Register

Challenge yourself on this topic → Study as cards