Study. uk . com
  1. Home
  2. All questions
  3. Question 356

CISM study material · question 356 of 1000

An organisation begins its risk assessment with a business impact analysis at the upper tiers rather than with threat identification. Is this consistent with SP 800-30?

  1. No — the task order is fixed and must begin with threat sources
  2. No — business impact analysis belongs to continuity planning alone
  3. Yes — starting from impact analysis lets detailed threat analysis focus on the systems and links that matter most
  4. Yes, but only for non-adversarial threats
Show the answer

Answer: C. Yes — starting from impact analysis lets detailed threat analysis focus on the systems and links that matter most

SP 800-30 notes organisations may find reordering the tasks advantageous, giving the example of starting with business impact analysis at Tiers 1 and 2 so assessors can focus detailed analysis on critical systems, databases and links.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 3.2 footnote 46

Challenge yourself on this topic → Study as cards