Study. uk . com
  1. Home
  2. All questions
  3. Question 326

CISM study material · question 326 of 1000

Which four risk factors does SP 800-37 identify as considered during risk assessment?

  1. Confidentiality, integrity, availability and privacy of the information being held
  2. Asset value, control cost, residual risk and the owner accountable for treating it
  3. Impact of loss, threats, vulnerabilities and likelihood of occurrence
  4. Impact, exposure, tolerance and appetite
Show the answer

Answer: C. Impact of loss, threats, vulnerabilities and likelihood of occurrence

SP 800-37 counts four factors in assessment: what would be lost, what threatens, what is weak, and how likely occurrence is.

Source: NIST SP 800-37 Rev. 2 (NIST) — Sec. 2.2 footnote 26

Challenge yourself on this topic → Study as cards