- Home
- All questions
- Question 265
CISM study material · question 265 of 1000
Which two activities does IR 8286 say a cybersecurity risk register should support to condition its data for the enterprise view? Choose two.
Show the answer
Answer: A. Normalising information across organisational units
B. Aggregating risks from adversary threats and system failures
IR 8286 lists aggregating risks from adversary threats and system failures, normalising information across organisational units, and prioritising operational responses against mission and budget guidance.
Source: NIST IR 8286 (NIST) — Sec. 2.3 The Gap Between CSRM Output and ERM Input