Study. uk . com
  1. Home
  2. All questions
  3. Question 355

CISM study material · question 355 of 1000

An assessment cannot cover the whole threat space in the detail the methodology describes within the resources available. What compromise does SP 800-30 permit?

  1. Substituting a compliance review for the assessment
  2. Deferring the assessment until enough resources are available to cover the whole threat space at the level of detail the methodology sets out
  3. Reducing the scope to the highest-impact system only, so that the detail the methodology requires can be applied in full to that single system
  4. Generalising threat sources, events and vulnerabilities to ensure coverage, going into specifics only where the objectives require
Show the answer

Answer: D. Generalising threat sources, events and vulnerabilities to ensure coverage, going into specifics only where the objectives require

SP 800-30 states that in practice, adequate coverage within available resources may dictate generalising threat sources, events and vulnerabilities to ensure full coverage, assessing specific detailed ones only as necessary to accomplish the objectives.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 3.2 Conducting the Risk Assessment

Challenge yourself on this topic → Study as cards