Study. uk . com
  1. Home
  2. All questions
  3. Question 671

CISM study material · question 671 of 1000

Which two kinds of assessment does NIST name alongside risk assessment when evaluating security risk? Choose two.

  1. Programme-level assessments judging strategy, policy, procedure and operations
  2. Financial assessments judging the security budget
  3. Vendor assessments judging supplier viability
  4. Control assessments judging whether specific controls perform as intended
Show the answer

Answer: A. Programme-level assessments judging strategy, policy, procedure and operations
D. Control assessments judging whether specific controls perform as intended

SP 800-55v1 names risk assessments identifying risks, programme-level assessments supporting decisions about strategy, policies, procedures and operations, and control assessments evaluating whether specific controls perform as intended.

Source: NIST SP 800-55 Vol. 1 (NIST) — Ch. 2 Assessment and Measurement

Challenge yourself on this topic → Study as cards