Study. uk . com
  1. Home
  2. All questions
  3. Question 308

CISM study material · question 308 of 1000

Business units estimate likelihood over different periods — one over a year, another over five. What problem does IR 8286 identify?

  1. Longer periods always produce higher likelihood values, so a five-year estimate overstates the risk against a one-year estimate
  2. Estimates made over five years are invalid, because no threat picture holds steady long enough for such a figure to mean anything
  3. Only quantitative estimates require a stated time frame, since a qualitative rating is read as covering the coming twelve months by convention
  4. Registers cannot be normalised and aggregated, because a consistent time frame is what makes estimates comparable
Show the answer

Answer: D. Registers cannot be normalised and aggregated, because a consistent time frame is what makes estimates comparable

IR 8286 asks that likelihood everywhere be estimated over the same period, because normalising cybersecurity registers into one enterprise register depends on the estimates being comparable.

Source: NIST IR 8286 (NIST) — Sec. 3.3.2 Techniques for Estimating Likelihood and Impact

Challenge yourself on this topic → Study as cards