Study. uk . com
  1. Home
  2. All questions
  3. Question 5

CISM study material · question 5 of 1000

A manager is drafting the agenda for the quarterly cybersecurity risk discussion under CSF 2.0. Which item belongs on that agenda that a purely threat-focused agenda would omit?

  1. Strategic opportunities, characterised as positive risks
  2. Open findings from the last internal audit, ranked by the severity the auditors assigned to them
  3. The count of phishing simulation failures
  4. A ranked list of unpatched vulnerabilities weighted by asset criticality
Show the answer

Answer: A. Strategic opportunities, characterised as positive risks

CSF 2.0 treats positive risk as in scope and asks that strategic opportunities be characterised and included in the same cybersecurity risk discussions as negative risks.

Source: NIST CSWP 29 (NIST) — Appendix A GV.RM-07

Challenge yourself on this topic → Study as cards