nerdexam
Cisco

300-745 · Question #44

Considering recent cybersecurity threats, a company wants to improve the process for identifying, assessing, and managing risks with a comprehensive and holistic approach. Which framework must be…

The correct answer is C. NIST SP 800-37. NIST SP 800-37 provides the Risk Management Framework (RMF), which establishes a structured process for identifying, assessing, and managing cybersecurity risks. It offers a comprehensive and holistic approach, integrating security and risk management activities into the system…

Risk, Events, and Requirements

Question

Considering recent cybersecurity threats, a company wants to improve the process for identifying, assessing, and managing risks with a comprehensive and holistic approach. Which framework must be used to meet these requirements?

Options

  • AHIPPA
  • BMITRE CAPEC
  • CNIST SP 800-37
  • DGDPR

How the community answered

(41 responses)
  • A
    15% (6)
  • B
    5% (2)
  • C
    78% (32)
  • D
    2% (1)

Explanation

NIST SP 800-37 provides the Risk Management Framework (RMF), which establishes a structured process for identifying, assessing, and managing cybersecurity risks. It offers a comprehensive and holistic approach, integrating security and risk management activities into the system development life cycle, making it the appropriate framework for this requirement.

Topics

#risk management framework#NIST SP 800-37#risk assessment#security governance

Community Discussion

No community discussion yet for this question.

Full 300-745 Practice