Study. uk . com
  1. Home
  2. All questions
  3. Question 352

CISM study material · question 352 of 1000

What is the stated objective of the conduct step of a risk assessment under SP 800-30?

  1. To produce a list of risks that can be prioritised by risk level and used to inform response decisions
  2. To determine whether the organisation's risk tolerance has been set correctly for the conditions it now operates in
  3. To verify the effectiveness of controls already deployed
  4. To select the controls that will treat each identified risk
Show the answer

Answer: A. To produce a list of risks that can be prioritised by risk level and used to inform response decisions

SP 800-30 makes the conduct step's output a ranked list of information security risks, ordered by risk level, from which response decisions are then taken.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 3.2 Conducting the Risk Assessment

Challenge yourself on this topic → Study as cards