Study. uk . com
  1. Home
  2. All questions
  3. Question 349

CISM study material · question 349 of 1000

A risk model defines its factors and scales but leaves how they combine to the assessor's judgement each time. What does SP 800-30 say a model requires, and what do those rules reflect?

  1. An external validation of the model, which reflects the independence expected of whoever is asked to carry out the assessment
  2. A published methodology, which reflects industry practice
  3. Algorithms such as formulas, tables or rules for combining factors, which reflect the organisation's risk tolerance
  4. A quantitative scale for every factor in the model, which reflects the expectations the regulator has published for the sector
Show the answer

Answer: C. Algorithms such as formulas, tables or rules for combining factors, which reflect the organisation's risk tolerance

SP 800-30 states organisation-specific risk models include algorithms — formulas, tables or rules — for combining risk factors, and that algorithms for combining risk factors reflect organisational risk tolerance.

Source: NIST SP 800-30 Rev. 1 (NIST) — Task 1-5 Identify Risk Model and Analytic Approach

Challenge yourself on this topic → Study as cards