312-50V11 · Question #558
What information should an IT system analysis provide to the risk assessor?
The correct answer is C. Security architecture. IT system analysis feeds the risk assessor information about the current security architecture, including controls and configurations already in place.
Question
What information should an IT system analysis provide to the risk assessor?
Options
- AManagement buy-in
- BThreat statement
- CSecurity architecture
- DImpact analysis
How the community answered
(37 responses)- A5% (2)
- B3% (1)
- C89% (33)
- D3% (1)
Why each option
IT system analysis feeds the risk assessor information about the current security architecture, including controls and configurations already in place.
Management buy-in is an organizational prerequisite for conducting a risk assessment, not an output of IT system analysis.
A threat statement is produced during the threat identification phase of the risk assessment itself, not derived from system analysis.
An IT system analysis documents the security architecture of the target system, including its components, existing security controls, data flows, and configurations. This information is essential for the risk assessor to understand the current security posture and identify gaps. Without this architectural baseline, a meaningful risk assessment cannot be performed.
Impact analysis is a separate step in the risk assessment process that evaluates consequences of threats, not an output of system analysis.
Concept tested: IT system analysis output in risk assessment
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.