Study. uk . com
  1. Home
  2. All questions
  3. Question 309

CISM study material · question 309 of 1000

An organisation decides very low exposure risks need not be entered on the register. What condition does IR 8286 attach to such a threshold?

  1. The threshold must be approved by the external auditor
  2. The threshold must be expressed in monetary terms
  3. The threshold may not exclude any adversarial risk
  4. The guidance for the threshold must be applied consistently throughout the enterprise
Show the answer

Answer: D. The guidance for the threshold must be applied consistently throughout the enterprise

IR 8286 notes cybersecurity risks should not arbitrarily be omitted, but that many may represent such low exposure they need not be included, and that guidance for this threshold should be applied consistently throughout the enterprise.

Source: NIST IR 8286 (NIST) — Sec. 3.4 Prioritize Risks

Challenge yourself on this topic → Study as cards