Study. uk . com
  1. Home
  2. All questions
  3. Question 30

CISM study material · question 30 of 1000

A security manager is drafting the organisation-wide risk management strategy. Which two elements does SP 800-39 expect it to contain? Choose two.

  1. The acceptable risk assessment methodologies
  2. An inventory of every information asset the organisation holds
  3. An unambiguous expression of the organisation's risk tolerance
  4. The disciplinary sanctions applied when a member of staff violates the policy
Show the answer

Answer: C. An unambiguous expression of the organisation's risk tolerance
A. The acceptable risk assessment methodologies

SP 800-39 states the strategy includes an unambiguous expression of risk tolerance, acceptable assessment methodologies, risk response strategies, a consistent evaluation process, and approaches for monitoring risk over time.

Source: NIST SP 800-39 (NIST) — Sec. 2.3.3 Risk Management Strategy

Challenge yourself on this topic → Study as cards