Study. uk . com
  1. Home
  2. All questions
  3. Question 738

CISM study material · question 738 of 1000

What does the Community Profile recommend be taken into account when the organisation adjusts its cybersecurity risk management strategy?

  1. Past cybersecurity incidents and the risks they revealed
  2. The strategies published by comparable peer organisations in the sector
  3. The enforcement history of the applicable regulator in that sector
  4. The product roadmap published by the incumbent tooling vendor for it
Show the answer

Answer: A. Past cybersecurity incidents and the risks they revealed

SP 800-61r3 recommends taking past cybersecurity incidents into account when adjusting the organisation's risk management strategy and direction, and taking risks from past incidents into account when reviewing that strategy.

Source: NIST SP 800-61 Rev. 3 (NIST) — Table 2 GV.OV-01

Challenge yourself on this topic → Study as cards