- Home
- All questions
- Question 671
CISM study material · question 671 of 1000
Which two kinds of assessment does NIST name alongside risk assessment when evaluating security risk? Choose two.
Show the answer
Answer: A. Programme-level assessments judging strategy, policy, procedure and operations
D. Control assessments judging whether specific controls perform as intended
SP 800-55v1 names risk assessments identifying risks, programme-level assessments supporting decisions about strategy, policies, procedures and operations, and control assessments evaluating whether specific controls perform as intended.
Source: NIST SP 800-55 Vol. 1 (NIST) — Ch. 2 Assessment and Measurement