312-50V9 · Question #436
What information should an IT system analysis provide to the risk assessor?
The correct answer is C. Security architecture. An IT system analysis documents the technical security architecture of a system, giving the risk assessor the structural context needed to identify and evaluate risks.
Question
What information should an IT system analysis provide to the risk assessor?
Options
- AManagement buy-in
- BThreat statement
- CSecurity architecture
- DImpact analysis
How the community answered
(37 responses)- A3% (1)
- C95% (35)
- D3% (1)
Why each option
An IT system analysis documents the technical security architecture of a system, giving the risk assessor the structural context needed to identify and evaluate risks.
Management buy-in is a prerequisite for conducting a risk assessment program, not an output that system analysis provides to the risk assessor.
A threat statement is produced during the threat identification phase of the risk assessment itself, not derived from the IT system analysis.
Security architecture describes the system's components, data flows, trust boundaries, and existing controls - precisely the technical picture a risk assessor needs to evaluate exposure. Without understanding how the system is designed and what protections are already in place, the assessor cannot accurately identify threats or determine risk levels. System analysis feeds architecture details into the risk assessment process as defined in NIST SP 800-30.
Impact analysis is performed by the risk assessor after receiving system information, not an input that system analysis supplies.
Concept tested: IT system analysis inputs to risk assessment
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.