Study. uk . com
  1. Home
  2. All questions
  3. Question 672

CISM study material · question 672 of 1000

How does NIST characterise the relationship between programme assessments, control assessments and risk assessment?

  1. Programme and control assessments replace the need for a separate risk assessment, since between the two of them they already cover the same ground
  2. Risk assessment is a subset of control assessment
  3. Programme and control assessments are themselves forms of risk assessment, each offering a different lens on the same security risk
  4. They are unrelated activities serving different audiences
Show the answer

Answer: C. Programme and control assessments are themselves forms of risk assessment, each offering a different lens on the same security risk

SP 800-55v1 treats programme and control assessments as risk assessments in their own right, each viewing the same information security risk from a different angle.

Source: NIST SP 800-55 Vol. 1 (NIST) — Ch. 2 Assessment and Measurement

Challenge yourself on this topic → Study as cards