nerdexam
CSA

CCSK · Question #115

The level of attention and scrutiny paid to enterprise risk assessments should be directly related to what?

The correct answer is B. The value of the information at risk. Enterprise risk assessments should be calibrated to the value of the information being protected, not to technical or environmental factors.

Legal, Risk, and Compliance

Question

The level of attention and scrutiny paid to enterprise risk assessments should be directly related to what?

Options

  • AThe size of the cloud computing environment
  • BThe value of the information at risk
  • CThe operating system and firewall type
  • DWhether the cloud is IaaS, PaaS, or SaaS
  • EBoth A and C

How the community answered

(39 responses)
  • A
    13% (5)
  • B
    74% (29)
  • C
    3% (1)
  • D
    8% (3)
  • E
    3% (1)

Why each option

Enterprise risk assessments should be calibrated to the value of the information being protected, not to technical or environmental factors.

AThe size of the cloud computing environment

The size of the cloud environment does not determine risk severity; a small environment can hold extremely sensitive, high-value data that warrants intensive scrutiny.

BThe value of the information at riskCorrect

The core principle of risk management is that the depth and rigor of a risk assessment must be proportional to the potential impact if that risk materializes. The value of the information at risk determines the potential business, financial, and reputational harm from a breach or loss. Allocating assessment effort based on information value ensures that high-stakes data receives the scrutiny it deserves while avoiding wasted resources on low-value assets.

CThe operating system and firewall type

Operating system and firewall type are technical control details, not drivers for calibrating the level of risk assessment attention.

DWhether the cloud is IaaS, PaaS, or SaaS

The cloud service model affects the distribution of security responsibilities but is not the primary factor in determining how much scrutiny a risk assessment requires.

EBoth A and C

Incorrect because neither A nor C represents the correct basis for scaling risk assessment effort.

Concept tested: Risk assessment effort proportional to information value

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#enterprise risk assessment#information value#risk prioritization#risk management

Community Discussion

No community discussion yet for this question.

Full CCSK Practice