- Home
- All questions
- Question 356
CISM study material · question 356 of 1000
An organisation begins its risk assessment with a business impact analysis at the upper tiers rather than with threat identification. Is this consistent with SP 800-30?
Show the answer
Answer: C. Yes — starting from impact analysis lets detailed threat analysis focus on the systems and links that matter most
SP 800-30 notes organisations may find reordering the tasks advantageous, giving the example of starting with business impact analysis at Tiers 1 and 2 so assessors can focus detailed analysis on critical systems, databases and links.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 3.2 footnote 46