Study. uk . com
  1. Home
  2. All questions
  3. Question 321

CISM study material · question 321 of 1000

Controls have been deployed to mitigate a risk and the register is updated to show the risk as treated. What further step does IR 8286 require before that treatment can be relied upon?

  1. Approval by the enterprise risk steering committee, which records the treatment as closed once it has seen the supporting evidence
  2. A twelve-month waiting period before reassessment
  3. Evaluation of the applied controls by a competent assessor to confirm the mitigation is effective and cost-effective
  4. Sign-off by the vendor confirming that the controls were installed correctly and configured to the vendor's supported baseline
Show the answer

Answer: C. Evaluation of the applied controls by a competent assessor to confirm the mitigation is effective and cost-effective

IR 8286 asks a competent assessor to examine the controls actually applied, confirming the mitigation both works and is worth what it cost, before the treatment is trusted.

Source: NIST IR 8286 (NIST) — Sec. 3.5.1 Applying Security Controls

Challenge yourself on this topic → Study as cards