Study. uk . com
  1. Home
  2. All questions
  3. Question 265

CISM study material · question 265 of 1000

Which two activities does IR 8286 say a cybersecurity risk register should support to condition its data for the enterprise view? Choose two.

  1. Normalising information across organisational units
  2. Aggregating risks from adversary threats and system failures
  3. Publishing the register to external stakeholders on a fixed quarterly schedule
  4. Assigning a control identifier to each entry in the register
Show the answer

Answer: A. Normalising information across organisational units
B. Aggregating risks from adversary threats and system failures

IR 8286 lists aggregating risks from adversary threats and system failures, normalising information across organisational units, and prioritising operational responses against mission and budget guidance.

Source: NIST IR 8286 (NIST) — Sec. 2.3 The Gap Between CSRM Output and ERM Input

Challenge yourself on this topic → Study as cards