350-201 · Question #108
What is needed to assess risk mitigation effectiveness in an organization?
The correct answer is C. cost-effectiveness of control measures. Assessing risk mitigation effectiveness centers on the cost-effectiveness of control measures, which quantifies whether security controls reduce risk sufficiently relative to their implementation cost.
Question
What is needed to assess risk mitigation effectiveness in an organization?
Options
- Aanalysis of key performance indicators
- Bcompliance with security standards
- Ccost-effectiveness of control measures
- Dupdated list of vulnerable systems
How the community answered
(14 responses)- A14% (2)
- B7% (1)
- C71% (10)
- D7% (1)
Why each option
Assessing risk mitigation effectiveness centers on the cost-effectiveness of control measures, which quantifies whether security controls reduce risk sufficiently relative to their implementation cost.
Key performance indicators measure broad operational or business outcomes and do not specifically quantify whether individual risk mitigation controls are reducing targeted risks.
Compliance with security standards confirms conformance to regulatory or policy requirements but does not measure the actual degree of risk reduction achieved by specific mitigations.
Cost-effectiveness analysis of control measures directly evaluates risk mitigation effectiveness by comparing the cost of a security control against the magnitude of risk reduction it delivers. If a control's cost exceeds the expected loss it prevents, the mitigation is not effective, making this cost-benefit comparison the essential tool for determining whether risk management actions are working as intended.
An updated list of vulnerable systems characterizes the current risk exposure rather than evaluating the effectiveness of mitigations that have already been applied.
Concept tested: Assessing risk mitigation via control cost-benefit effectiveness
Source: https://csrc.nist.gov/publications/detail/sp/800-39/final
Topics
Community Discussion
No community discussion yet for this question.