Study. uk . com
  1. Home
  2. All questions
  3. Question 272

CISM study material · question 272 of 1000

An organisation cannot say with confidence which devices it operates or where its data resides. What consequence does IR 8286 draw?

  1. Risk assessment must be outsourced to a third party
  2. The organisation cannot maintain a risk register
  3. Every asset must be treated as high impact by default until the inventory has been completed and verified
  4. Neither the assets themselves nor the effect of cyber risk on them can be fully quantified
Show the answer

Answer: D. Neither the assets themselves nor the effect of cyber risk on them can be fully quantified

IR 8286 makes asset knowledge the precondition for quantification: where the inventory is patchy or wrong, no reliable figure can be put on the assets or on what cyber risk does to them.

Source: NIST IR 8286 (NIST) — Sec. 2.3.1 Insufficient Asset Information

Challenge yourself on this topic → Study as cards