- Home
- All questions
- Question 309
CISM study material · question 309 of 1000
An organisation decides very low exposure risks need not be entered on the register. What condition does IR 8286 attach to such a threshold?
Show the answer
Answer: D. The guidance for the threshold must be applied consistently throughout the enterprise
IR 8286 notes cybersecurity risks should not arbitrarily be omitted, but that many may represent such low exposure they need not be included, and that guidance for this threshold should be applied consistently throughout the enterprise.
Source: NIST IR 8286 (NIST) — Sec. 3.4 Prioritize Risks