- Home
- All questions
- Question 775
CISM study material · question 775 of 1000
Which two risk evaluation factors does NIST name for prioritising an incident? Choose two.
Show the answer
Answer: B. The stage of the observed activity
D. Recoverability
SP 800-61r3's factor list runs across how critical the asset is, what the incident does to function and to data, how far the observed activity has progressed, who the actor appears to be, and how recoverable things are.
Source: NIST SP 800-61 Rev. 3 (NIST) — Table 3 RS.MA.N2