Study. uk . com
  1. Home
  2. All questions
  3. Question 353

CISM study material · question 353 of 1000

Which sequence correctly orders the tasks of conducting a risk assessment under SP 800-30?

  1. Identify threat sources, identify threat events, identify vulnerabilities and predisposing conditions, determine likelihood, determine impact, determine risk
  2. Identify vulnerabilities, determine the impact, identify the threat sources and the events they drive, determine likelihood, and then determine the overall level of risk
  3. Identify the assets, identify each of the threats acting on every one of them, select the controls that will treat each of those threats, and then determine the residual risk that is left behind
  4. Determine risk, identify the threat sources, identify the vulnerabilities and predisposing conditions, determine impact, and then determine the likelihood of occurrence
Show the answer

Answer: A. Identify threat sources, identify threat events, identify vulnerabilities and predisposing conditions, determine likelihood, determine impact, determine risk

SP 800-30 sets out the conduct tasks in this order: identify threat sources, identify threat events, identify vulnerabilities and predisposing conditions, determine likelihood, determine adverse impacts, and determine risk.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 3.2 Conducting the Risk Assessment

Challenge yourself on this topic → Study as cards